Skip to content

Hide Navigation Hide TOC

UNC5266 (083a637b-c58c-4ccb-ab59-81d783873e80)

Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA. At this time, based on observed infrastructure usage similarities, Mandiant suspects with moderate confidence that UNC5266 overlaps in part with UNC3569, a China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator, among others, to gain initial access to target environments.

Cluster A Galaxy A Cluster B Galaxy B Level
UNC5266 (083a637b-c58c-4ccb-ab59-81d783873e80) Threat Actor TERRIBLETEA (4838b37b-2d1f-4cb8-945d-7185580f0bff) Backdoor 1
UNC5266 (083a637b-c58c-4ccb-ab59-81d783873e80) Threat Actor SLIVER (84c2d789-64be-429b-aeee-253a4e0e2aff) Tool 1