DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // UNC3886-CHINA-TELECOM-ESPIONAGEFIRST SEEN: 2022

UNC3886

ALSO KNOWN AS: Fire Ant (Sygnia tracking)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:China (China-nexus, assessed by Mandiant/Google as working on behalf of PRC; no formal government attribution by Singapore)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:2022
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL95/100
RESOURCES100/100
PERSISTENCE100/100
STEALTH100/100
IMPACT95/100

UNC3886 is a highly disciplined China-nexus APT group that confirmed its status as one of the most capable telecom-targeting actors globally after Singapore's CSA disclosed on February 9, 2026 that the group had breached all four of Singapore's major telcos (M1, SIMBA Telecom, Singtel, StarHub) in a campaign persisting undetected for nearly a year. The group used a zero-day exploit to bypass perimeter firewalls, deployed the REPTILE and MEDUSA Linux kernel rootkits for stealth persistence, and exfiltrated technical network data. Singapore mounted Operation CYBER GUARDIAN — its largest-ever coordinated cyber incident response — involving 100+ defenders across 11 months to evict the group. Campaign TTPs overlap with broader Salt Typhoon telecom targeting patterns observed in the U.S., Canada, and Norway.

Strategic cyber espionage focused on telecommunications infrastructure — persistent covert access for intelligence collection, network reconnaissance, and pre-positioning for potential supply-chain compromise or wiretapping

Zero-day exploitation of Fortinet FortiOS, VMware vCenter/ESXi, and Juniper Networks devices (T1190), REPTILE kernel-mode Linux rootkit deployment (T1014), MEDUSA LD_PRELOAD rootkit for credential logging (T1014), TINYSHELL-based custom backdoors on Juniper routers (T1505.001), credential harvesting (T1003), living-off-the-land techniques, anti-forensic rootkit evasion, network architecture reconnaissance

TELECOMMUNICATIONS
GOVERNMENT
DEFENSE
CRITICAL INFRASTRUCTURE
TECHNOLOGY

REPTILE rootkit (kernel-mode, process/file/network hiding + reverse shell), MEDUSA rootkit (LD_PRELOAD credential logger), TINYSHELL-based backdoors on Juniper Junos OS routers, custom malware for VMware ESXi persistence; targets Fortinet FortiOS, VMware vCenter, Juniper Junos OS

FILE DATE: MID 2025
Operation CYBER GUARDIAN (Singapore Telecom Campaign)
UNC3886 breaches all four major Singapore telcos (M1, SIMBA, Singtel, StarHub) using zero-day firewall bypass and rootkits; Singapore launches largest-ever national cyber incident response spanning 11 months.
FILE DATE: FEB 2026
Singapore CSA Public Attribution
Singapore publicly attributes the 11-month telecom campaign to UNC3886 on February ██████████████ the first national-level public naming of the group by a sovereign government; Operation CYBER GUARDIAN formally concluded.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn