UNC3886
Also reported as Fire Ant. Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1027 3 reports reports only
- T1059.004 3 reports in ATT&CK
- T1140 3 reports reports only
- T1003 2 reports reports only
- T1016 2 reports reports only
- T1021.004 2 reports in ATT&CK
- T1059 2 reports reports only
- T1059.001 2 reports in ATT&CK
- T1059.003 2 reports in ATT&CK
- T1059.006 2 reports in ATT&CK
Show all 57 techniques Show fewer
- T1070 2 reports reports only
- T1070.003 2 reports reports only
- T1070.004 2 reports in ATT&CK
- T1078 2 reports in ATT&CK
- T1083 2 reports in ATT&CK
- T1105 2 reports reports only
- T1129 2 reports reports only
- T1202 2 reports reports only
- T1218.011 2 reports in ATT&CK
- T1497 2 reports reports only
- T1497.001 2 reports reports only
- T1547 2 reports reports only
- T1560 2 reports reports only
- T1560.001 2 reports in ATT&CK
- T1573.001 2 reports reports only
- T1620 2 reports reports only
- T1003.001 1 report in ATT&CK
- T1014 1 report in ATT&CK
- T1021 1 report reports only
- T1033 1 report reports only
- T1036.005 1 report reports only
- T1041 1 report reports only
- T1055.009 1 report reports only
- T1056 1 report reports only
- T1057 1 report in ATT&CK
- T1059.008 1 report reports only
- T1071 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report in ATT&CK
- T1082 1 report reports only
- T1087 1 report reports only
- T1090 1 report reports only
- T1095 1 report in ATT&CK
- T1102.001 1 report reports only
- T1190 1 report in ATT&CK
- T1203 1 report in ATT&CK
- T1205.002 1 report reports only
- T1219 1 report reports only
- T1222 1 report reports only
- T1518 1 report reports only
- T1552 1 report reports only
- T1555.005 1 report in ATT&CK
- T1563.001 1 report reports only
- T1565.001 1 report reports only
- T1571 1 report reports only
- T1573 1 report reports only
- T1601 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-2463
- CVE-2017-0144 KEV ransomware
- CVE-2018-0171 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2021-20021 KEV ransomware
- CVE-2021-20022 KEV ransomware
- CVE-2021-20023 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-35247 KEV
- CVE-2022-0609 KEV
- CVE-2022-1040 KEV
Show all 53 CVEs Show fewer
- CVE-2022-1388 KEV ransomware
- CVE-2022-20821 KEV
- CVE-2022-21587 KEV ransomware
- CVE-2022-22948 KEV
- CVE-2022-26871 KEV
- CVE-2022-27518 KEV
- CVE-2022-28810 KEV
- CVE-2022-29499 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-40139 KEV
- CVE-2022-41040 KEV ransomware
- CVE-2022-41128 KEV
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-44698 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-20867 KEV
- CVE-2023-23397 KEV
- CVE-2023-2868 KEV
- CVE-2023-34048 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3519 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21888
- CVE-2024-21893 KEV ransomware
- CVE-2024-22024
- CVE-2025-21590 KEV
- CVE-2025-29824 KEV ransomware
- CVE-2025-32433 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 28 reports Show fewer
-
Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
-
Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation
-
Bad VIB(E)s Part One- Investigating Novel Malware Persistence Within ESXi Hypervisors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bad VIB(E)s Part One- Investigating Novel Malware Persistence Within ESXi Hypervisors
Newest first. Details opens the report in Explore.