UNC6586 is a suspected China-nexus cyber-espionage cluster observed exploiting the React Server Components remote code execution vulnerability CVE-2025-55182, also known as React2Shell, for initial access. The group has been documented using the SNOWLIGHT downloader, a VShell stager and backdoor component, to retrieve and execute additional payloads disguised as legitimate files. Reporting places UNC6586 among multiple Chinese espionage-oriented clusters that rapidly operationalized React2Shell shortly after disclosure. Observed tradecraft indicates exploitation of internet-facing web applications for initial compromise, followed by downloader-based payload staging and post-compromise access enablement. UNC6586 has been specifically associated with use of command-line retrieval methods to fetch and launch SNOWLIGHT, and with subsequent HTTP-based retrieval of follow-on payloads. Tooling overlap links UNC6586 operationally with other China-aligned clusters that have also used SNOWLIGHT, including UNC5174 and UAT-6382, although shared tooling alone does not establish organizational identity. Available reporting supports assessment of UNC6586 as part of the broader ecosystem of PRC-linked intrusion activity focused on espionage rather than financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster associated with use of the SNOWLIGHT VShell stager.
China-nexus APT cluster referenced as associated with SNOWLIGHT-linked intrusions.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity (UNC-style naming suggests an uncategorized cluster).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.