Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1048
MITRE ATT&CK Group

UNC3886 (G1048)

ShareXLinkedInRedditHN

[UNC3886](https://attack.mitre.org/groups/G1048) is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. [UNC3886](https://attack.mitre.org/groups/G1048) has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.(Citation: Mandiant Fortinet Zero Day)(Citation: Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023)

▪Techniques used (49)

T1027.005Indicator Removal from ToolsT1681Search Threat Vendor DataT1059.012Hypervisor CLIT1083File and Directory DiscoveryT1078.001Default AccountsT1554Compromise Host Software BinaryT1068Exploitation for Privilege EscalationT1673Virtual Machine DiscoveryT1564.011Ignore Process InterruptsT1587.001MalwareT1212Exploitation for Credential AccessT1675ESXi Administration CommandT1218.011Rundll32T1074.001Local Data StagingT1070.007Clear Network Connection History and ConfigurationsT1059.006PythonT1548Abuse Elevation Control MechanismT1070.006TimestompT1690Prevent Command History LoggingT1560.003Archive via Custom MethodT1203Exploitation for Client ExecutionT1037.004RC ScriptsT1685Disable or Modify ToolsT1070.004File DeletionT1588.004Digital CertificatesT1555.005Password ManagersT1587.004ExploitsT1505.006vSphere Installation BundlesT1560.001Archive via UtilityT1003.001LSASS MemoryT1057Process DiscoveryT1570Lateral Tool TransferT1588.001MalwareT1059.003Windows Command ShellT1036.004Masquerade Task or ServiceT1037Boot or Logon Initialization ScriptsT1014RootkitT1059.001PowerShellT1040Network SniffingT1124System Time DiscoveryT1078Valid AccountsT1205.001Port KnockingT1190Exploit Public-Facing ApplicationT1095Non-Application Layer ProtocolT1686Disable or Modify System FirewallT1059.004Unix ShellT1205Traffic SignalingT1021.004SSHT1008Fallback Channels

▪Software used (8)

S1221MOPSLEDmalwareS1218VIRTUALPIEmalwareS1224CASTLETAPmalwareS1223THINCRUSTmalwareS1217VIRTUALPITAmalwareS1219REPTILEmalwareS1220MEDUSAmalwareS1222RIFLESPINEmalware
G1048on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.