UNC2717
UNC2717 is a Mandiant/FireEye-tracked threat cluster that targeted global government agencies in Europe and the U.S. between October 2020 and March 2021. The activity involved exploitation of Pulse Secure (Pulse Connect Secure) VPN vulnerabilities, including CVE-2021-22893 as well as previously disclosed 2019 and 2020 flaws, to gain access to victim environments. FireEye reported that UNC2717 repurposed the same Pulse Secure flaws used in related intrusion activity to install custom malware on government agency networks. UNC2717 was observed using Pulse Secure-focused malware including HARDPULSE, QUIETPULSE, and PULSEJUMP; in a March 2021 incident at a European organization, Mandiant observed UNC2717 using RADIALPULSE, PULSEJUMP, and HARDPULSE. The group was described as displaying advanced tradecraft and going to impressive lengths to avoid detection. Reported evasion and persistence behaviors associated with the broader UNC2630/UNC2717 activity included deleting or editing logs and artifacts, modifying timestamps, and using persistence mechanisms on Pulse Secure appliances that could survive software upgrades and factory resets. Mandiant also reported the actors harvested Active Directory credentials, bypassed multifactor authentication on Pulse Secure devices, and used stolen credentials and Windows-native tooling for reconnaissance, lateral movement, and access to resources such as Microsoft 365. Mandiant assessed that espionage activity by UNC2630 and UNC2717 supports key Chinese government priorities aligned with China’s 14th Five Year Plan. However, Mandiant also stated it lacked sufficient evidence to determine UNC2717 government sponsorship or affiliation with a known APT group. No aliases or sub-groups for UNC2717 were provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- defense
- government
- technology
- transportation
- finance
- telecommunications
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-aligned cyber espionage cluster involved in Pulse Secure VPN appliance compromises, emphasizing stealth and anti-forensics to maintain access and support strategic intelligence collection.
Cluster repurposing Pulse Secure VPN vulnerabilities to compromise targets (including government agencies) and deploy custom malware; activity observed from at least Oct 2020 through Mar 2021.
Suspected state-sponsored actor exploiting Pulse Connect Secure vulnerabilities (including CVE-2021-22893) to compromise global government agencies; deployed multiple custom malware families (Oct 2020–Mar 2021).
Cluster tracked by Mandiant for exploitation of Pulse Secure VPN appliances, leveraging webshells and utility scripts for credential/system information collection and persistence mechanisms; targeted government entities globally (observed at a European organization).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.