Skip to main content
Mallory
7 malware familiesExploits CVEs in the wild

UNC2717

Also known asUNC2717

UNC2717 is a Mandiant/FireEye-tracked threat cluster that targeted global government agencies in Europe and the U.S. between October 2020 and March 2021. The activity involved exploitation of Pulse Secure (Pulse Connect Secure) VPN vulnerabilities, including CVE-2021-22893 as well as previously disclosed 2019 and 2020 flaws, to gain access to victim environments. FireEye reported that UNC2717 repurposed the same Pulse Secure flaws used in related intrusion activity to install custom malware on government agency networks. UNC2717 was observed using Pulse Secure-focused malware including HARDPULSE, QUIETPULSE, and PULSEJUMP; in a March 2021 incident at a European organization, Mandiant observed UNC2717 using RADIALPULSE, PULSEJUMP, and HARDPULSE. The group was described as displaying advanced tradecraft and going to impressive lengths to avoid detection. Reported evasion and persistence behaviors associated with the broader UNC2630/UNC2717 activity included deleting or editing logs and artifacts, modifying timestamps, and using persistence mechanisms on Pulse Secure appliances that could survive software upgrades and factory resets. Mandiant also reported the actors harvested Active Directory credentials, bypassed multifactor authentication on Pulse Secure devices, and used stolen credentials and Windows-native tooling for reconnaissance, lateral movement, and access to resources such as Microsoft 365. Mandiant assessed that espionage activity by UNC2630 and UNC2717 supports key Chinese government priorities aligned with China’s 14th Five Year Plan. However, Mandiant also stated it lacked sufficient evidence to determine UNC2717 government sponsorship or affiliation with a known APT group. No aliases or sub-groups for UNC2717 were provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • defense
  • government
  • technology
  • transportation
  • finance
  • telecommunications
MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics9 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1190×2
Exploit Public-Facing Application
TA0003
Persistence
3 techniques
T1505
Server Software Component
T1505.003
Web Shell
T1546
Event Triggered Execution
T1556
Modify Authentication Process
TA0004
Privilege Escalation
1 technique
T1546
Event Triggered Execution
TA0112
Defense Impairment
1 technique
T1556
Modify Authentication Process
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1556
Modify Authentication Process
IOCS

Observables

7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal7

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables7

Domains, IPs, and hashes tied to this actor, refreshed continuously.