SUBJECT PROFILE
UNC3886 is a highly disciplined China-nexus APT group that confirmed its status as one of the most capable telecom-targeting actors globally after Singapore's CSA disclosed on February 9, 2026 that the group had breached all four of Singapore's major telcos (M1, SIMBA Telecom, Singtel, StarHub) in a campaign persisting undetected for nearly a year. The group used a zero-day exploit to bypass perimeter firewalls, deployed the REPTILE and MEDUSA Linux kernel rootkits for stealth persistence, and exfiltrated technical network data. Singapore mounted Operation CYBER GUARDIAN — its largest-ever coordinated cyber incident response — involving 100+ defenders across 11 months to evict the group. Campaign TTPs overlap with broader Salt Typhoon telecom targeting patterns observed in the U.S., Canada, and Norway.
Strategic cyber espionage focused on telecommunications infrastructure — persistent covert access for intelligence collection, network reconnaissance, and pre-positioning for potential supply-chain compromise or wiretapping
OPERATIONAL HISTORY
Zero-day exploitation of Fortinet FortiOS, VMware vCenter/ESXi, and Juniper Networks devices (T1190), REPTILE kernel-mode Linux rootkit deployment (T1014), MEDUSA LD_PRELOAD rootkit for credential logging (T1014), TINYSHELL-based custom backdoors on Juniper routers (T1505.001), credential harvesting (T1003), living-off-the-land techniques, anti-forensic rootkit evasion, network architecture reconnaissance
KNOWN INFRASTRUCTURE
REPTILE rootkit (kernel-mode, process/file/network hiding + reverse shell), MEDUSA rootkit (LD_PRELOAD credential logger), TINYSHELL-based backdoors on Juniper Junos OS routers, custom malware for VMware ESXi persistence; targets Fortinet FortiOS, VMware vCenter, Juniper Junos OS