Uptime Hamster: 10d 19h 55mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza UNC215

UNC215

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: APT UNC215
Ver en IntelTracker → APTTrail →
UNC215 is a Chinese cyber espionage group that Mandiant began tracking in early 2019, although its operations are believed to stem from a broader Chinese espionage campaign dating back to 2014. The group's primary motivation is information theft and espionage, focusing on obtaining sensitive information and intellectual property aligned with Beijing's financial, diplomatic, and strategic interests. What distinguishes UNC215 is its sophisticated use of false flag operations, meticulously crafting deceptions to masquerade as Iranian actors by employing Farsi strings, utilizing Iranian web shells like SEASHARPEE, and incorporating '/Iran/' filepaths in their operations to mislead attribution. The group has also demonstrated an adaptive approach to its tradecraft, continuously evolving its tactics, techniques, and procedures to hinder detection and attribution, including leveraging trusted relationships for lateral movement. While UNC215 is distinct, it has been linked with low confidence

Aliases del actor

APT UNC215

Actores similares

apt-unc215actor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknownotx.alienvault.comAPT UNC215 indicators and references
Webunknownwww.mandiant.comAPT UNC215 indicators and references
Repositoriounknowngithub.comAPT UNC215 indicators and references
Webunknownraw.githubusercontent.comAPT UNC215 indicators and references
Webunknown103.59.144.183APTTrailURLhttpAPT UNC215 indicators and references
Motivacion