Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇨🇳 CN3 malware families

UNC2814

Also known asUNC2814

UNC2814 is a suspected People’s Republic of China (PRC)-nexus cyber espionage group that Google Threat Intelligence Group (GTIG) has tracked since 2017. The group has historically targeted international governments and global telecommunications organizations across Africa, Asia, and the Americas. GTIG disclosed and disrupted a global UNC2814 espionage campaign that impacted 53 victims in 42 countries across four continents, with suspected infections in at least 20 additional countries. Reporting states the group has no observed overlap with activity publicly reported as Salt Typhoon. UNC2814 is associated with a novel C-based backdoor named GRIDTIDE. GRIDTIDE abused legitimate Google Sheets API functionality for command-and-control, allowing malicious traffic to blend in with normal cloud API activity rather than exploiting a vulnerability in Google products. The malware is capable of executing arbitrary shell commands and uploading and downloading files. Reported tradecraft in victim environments included use of a service account for SSH-based lateral movement, living-off-the-land binaries for reconnaissance, privilege escalation, and persistence, creation of a malicious systemd service for persistence, and deployment of SoftEther VPN Bridge to establish outbound encrypted connectivity. UNC2814 was also reported to target systems containing personally identifiable information, which GTIG assessed as consistent with telecommunications espionage used to identify, track, and monitor persons of interest. Separate reporting states UNC2814 used persona-driven jailbreaking against AI systems for vulnerability research, including prompts such as “senior security auditor,” “network security expert specializing in embedded devices,” and “senior C/C++ binary security expert.” These prompts were used to push past model safety guardrails while researching TP-Link firmware, remote code execution flaws, and Odette File Transfer Protocol (OFTP) implementations. One source cited in the content states UNC2814 is also known as Gallium.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Telecommunication Services
  • Government & Administration

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics47 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1595
Active Scanning
T1598
Phishing for Information
TA0042
Resource Development
1 technique
T1587
Develop Capabilities
T1587.001
Malware
T1587.004
Exploits
TA0001
Initial Access
3 techniques
T1078
Valid Accounts
T1078.004
Cloud Accounts
T1133
External Remote Services
T1190×4
Exploit Public-Facing Application
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.004×4
Unix Shell
TA0003
Persistence
3 techniques
T1078
Valid Accounts
T1078.004
Cloud Accounts
T1133
External Remote Services
T1543
Create or Modify System Process
T1543.002×4
Systemd Service
TA0004
Privilege Escalation
3 techniques
T1068
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1078.004
Cloud Accounts
T1543
Create or Modify System Process
T1543.002×4
Systemd Service
TA0005
Stealth
3 techniques
T1027×4
Obfuscated Files or Information
T1036×3
Masquerading
T1078
Valid Accounts
T1078.004
Cloud Accounts
TA0007
Discovery
4 techniques
T1033×2
System Owner/User Discovery
T1082×4
System Information Discovery
T1083×2
File and Directory Discovery
T1124
System Time Discovery
TA0008
Lateral Movement
2 techniques
T1021
Remote Services
T1021.004×3
SSH
T1570
Lateral Tool Transfer
TA0009
Collection
3 techniques
T1005
Data from Local System
T1119
Automated Collection
T1530
Data from Cloud Storage
TA0011
Command and Control
6 techniques
T1071×3
Application Layer Protocol
T1071.001×3
Web Protocols
T1071.004
DNS
T1090
Proxy
T1090.002×2
External Proxy
T1102×5
Web Service
T1102.002×2
Bidirectional Communication
T1105×5
Ingress Tool Transfer
T1132
Data Encoding
T1573×3
Encrypted Channel
TA0010
Exfiltration
2 techniques
T1041×5
Exfiltration Over C2 Channel
T1567
Exfiltration Over Web Service
IOCS

Observables

227 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping33

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables227

Domains, IPs, and hashes tied to this actor, refreshed continuously.