UNC6201 is a suspected PRC-nexus cyber espionage threat cluster focused on long-term access operations against infrastructure layers that often lack conventional endpoint visibility, including edge appliances, virtualization platforms, and related management systems. The cluster has been linked to exploitation of Dell RecoverPoint for Virtual Machines through CVE-2026-22769 as a zero-day since at least mid-2024, using that access to deploy the SLAYSTYLE web shell, the BRICKSTORM backdoor, and the newer GRIMBOLT backdoor. Investigations have also tied the actor to compromises of edge devices that do not support endpoint security products, where it captured valid credentials, maintained persistence, and pivoted into VMware environments. Reported dwell times have averaged roughly 393 days, with some reporting noting persistence beyond 390 days. UNC6201’s tradecraft emphasizes stealth, persistence, and post-compromise maneuvering. Observed behaviors include lateral movement, credential capture, boot persistence through modification of legitimate startup scripts, and use of covert access mechanisms on compromised virtualization infrastructure. In VMware environments, the actor has been observed creating temporary “Ghost NICs” on ESXi-hosted virtual machines to pivot into internal and SaaS-connected environments while reducing forensic visibility. On compromised vCenter appliances, it has used iptables-based Single Packet Authorization to conceal command-and-control access. GRIMBOLT, a C# backdoor compiled with native ahead-of-time techniques and packed to hinder analysis, appears to have replaced older BRICKSTORM binaries in some operations beginning in September 2025. The cluster is associated with targeting of edge appliances such as VPN concentrators and other core network devices, as well as backup, recovery, and virtualization management infrastructure. UNC6201 has also been reported using automation to provision and cycle premium LLM accounts for AI-enabled workflows, and has been named among PRC-linked groups using AI systems for vulnerability research and exploit development. Mandiant and Google have reported notable overlaps between UNC6201 and UNC5221, the cluster publicly associated with Silk Typhoon, but do not currently assess them to be the same actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cluster lié à la Chine maintenant des accès persistants de très longue durée sur des couches d’infrastructure peu visibles, notamment serveurs de virtualisation et équipements de bordure, à des fins d’espionnage.
Referenced as a PRC-linked threat cluster that exploited Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769 and delivered BRICKSTORM, GRIMBOLT, and the SLAYSTYLE webshell.
Suspected China-nexus threat cluster linked to attacks using PLENET and exploitation of Dell RecoverPoint for Virtual Machines as a zero-day.
Reported by Google as deploying Brickstorm against Dell RecoverPoint for Virtual Machines.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.