DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // UNC3886-CHINA-TELECOM-ESPIONAGEFIRST SEEN: 2022

UNC3886

ALSO KNOWN AS: Fire Ant (Sygnia tracking)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:China (China-nexus, assessed by Mandiant/Google as working on behalf of PRC; no formal government attribution by Singapore)
ATTRIBUTION:STATE-SPONSORED
STATUS:● ACTIVE
FIRST OBSERVED:2022
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL95/100
RESOURCES100/100
PERSISTENCE100/100
STEALTH100/100
IMPACT95/100

UNC3886 is a highly disciplined China-nexus APT group that confirmed its status as one of the most capable telecom-targeting actors globally after Singapore's CSA disclosed on February 9, 2026 that the group had breached all four of Singapore's major telcos (M1, SIMBA Telecom, Singtel, StarHub) in a campaign persisting undetected for nearly a year. The group used a zero-day exploit to bypass perimeter firewalls, deployed the REPTILE and MEDUSA Linux kernel rootkits for stealth persistence, and exfiltrated technical network data. Singapore mounted Operation CYBER GUARDIAN — its largest-ever coordinated cyber incident response — involving 100+ defenders across 11 months to evict the group. Campaign TTPs overlap with broader Salt Typhoon telecom targeting patterns observed in the U.S., Canada, and Norway.

Strategic cyber espionage focused on telecommunications infrastructure — persistent covert access for intelligence collection, network reconnaissance, and pre-positioning for potential supply-chain compromise or wiretapping

Zero-day exploitation of Fortinet FortiOS, VMware vCenter/ESXi, and Juniper Networks devices (T1190), REPTILE kernel-mode Linux rootkit deployment (T1014), MEDUSA LD_PRELOAD rootkit for credential logging (T1014), TINYSHELL-based custom backdoors on Juniper routers (T1505.001), credential harvesting (T1003), living-off-the-land techniques, anti-forensic rootkit evasion, network architecture reconnaissance

TELECOMMUNICATIONS
GOVERNMENT
DEFENSE
CRITICAL INFRASTRUCTURE
TECHNOLOGY

REPTILE rootkit (kernel-mode, process/file/network hiding + reverse shell), MEDUSA rootkit (LD_PRELOAD credential logger), TINYSHELL-based backdoors on Juniper Junos OS routers, custom malware for VMware ESXi persistence; targets Fortinet FortiOS, VMware vCenter, Juniper Junos OS

FILE DATE: MID 2025
Operation CYBER GUARDIAN (Singapore Telecom Campaign)
UNC3886 breaches all four major Singapore telcos (M1, SIMBA, Singtel, StarHub) using zero-day firewall bypass and rootkits; Singapore launches largest-ever national cyber incident response spanning 11 months.
FILE DATE: FEB 2026
Singapore CSA Public Attribution
Singapore publicly attributes the 11-month telecom campaign to UNC3886 on February ██████████████ the first national-level public naming of the group by a sovereign government; Operation CYBER GUARDIAN formally concluded.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn