UNC6201, also written UNC_6201, is a China-linked cyber-espionage threat cluster active since at least mid-2024. It targets network edge appliances, including VPN concentrators, and virtualization infrastructure, favoring systems that lack conventional endpoint detection and response coverage. Its operations emphasize credential capture, lateral movement, and long-term persistence; investigated intrusions in 2025 had an average dwell time of 393 days. Known victims include organizations in North America. UNC6201 has operational overlaps with UNC5221, associated with Silk Typhoon, but the two remain distinct tracked clusters. UNC6201 exploited CVE-2026-22769, a hard-coded credential vulnerability in Dell RecoverPoint for Virtual Machines, as a zero-day beginning in mid-2024. The actor authenticated to Apache Tomcat Manager using embedded administrator credentials and deployed the SLAYSTYLE web shell, enabling root-level command execution. Its malware arsenal includes BRICKSTORM and GRIMBOLT, also tracked as PLENET. In September 2025, it replaced older BRICKSTORM implants with GRIMBOLT, a C# remote-shell backdoor compiled using native ahead-of-time compilation and packed with UPX to complicate static analysis. Persistence mechanisms include modification of legitimate startup scripts to execute malware at boot. The cluster steals valid credentials from compromised appliances and uses them to access VMware environments. It creates temporary virtual network interfaces, termed Ghost NICs, on virtual machines hosted by ESXi servers to pivot into internal and SaaS environments, subsequently deleting the interfaces to reduce forensic visibility. On compromised VMware vCenter appliances, it uses firewall-based Single Packet Authorization and selective traffic redirection to conceal access. UNC6201 has also used AI models for vulnerability research and exploit development, alongside publicly available Python automation to provision and rapidly cancel premium LLM accounts to cycle free credits.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A suspected Chinese cyber-espionage cluster associated with exploitation of a hardcoded-credentials vulnerability in Dell RecoverPoint. Researchers reported overlaps with Silk Typhoon, but the content does not establish that the two names identify the same actor.
Cluster lié à la Chine maintenant des accès persistants de très longue durée sur des couches d’infrastructure peu visibles, notamment serveurs de virtualisation et équipements de bordure, à des fins d’espionnage.
Referenced as a PRC-linked threat cluster that exploited Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769 and delivered BRICKSTORM, GRIMBOLT, and the SLAYSTYLE webshell.
Suspected China-nexus threat cluster linked to attacks using PLENET and exploitation of Dell RecoverPoint for Virtual Machines as a zero-day.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.