UNC215UNC215

Also known as: UNC215

Known aliases
1

Profile

UNC215 is a Chinese nation-state threat actor that has been active since at least 2014. They have targeted organizations in various sectors, including government, technology, telecommunications, defense, finance, entertainment, and healthcare. UNC215 has been observed using tools such as Mimikatz, FOCUSFJORD, and HYPERBRO for initial access and post-compromise activities. They have demonstrated a focus on evading detection and have employed tactics such as using trusted third parties, minimizing forensic evidence, and incorporating false flags. UNC215's targets are located globally, with a particular focus on the Middle East, Europe, Asia, and North America.

Aliases· 1

UNC215

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC2717
Actor
UNC2630
Actor
UNC2814
Actor
UNC6691
Actor
UNC3569
Actor
UNC4191
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.