Full Report
2025-03-12 • Mandiant • Frank Tse, Jakub Jozwiak, Logeswaran Nadarajan, Lukasz Lamparski, Mathew Potaczek, Mustafa Nasser, Nick Harbour, Punsaen Boonyakarn, Shawn Chew • elf.tinyshell Open article on Malpedia
Analysis Summary
# Threat Actor: UNC3886
## Attribution & Identity
China-Nexus Espionage Actor.
## Activity Summary
The actor is described as targeting Juniper routers in ongoing espionage operations.
## Tactics, Techniques & Procedures
- Exploitation of Juniper router vulnerabilities. (Specific TTP details extracted from the larger article would follow here, but are not present in the provided context snippet.)
- Use of malware family `elf.tinyshell`. (Specific ATT&CK IDs need to be referenced from the full article.)
## Targeting
- Sectors: Not explicitly detailed in the provided context.
- Geography: Not explicitly detailed in the provided context.
- Victims: Not explicitly detailed in the provided context.
## Tools & Infrastructure
- Malware families used: `elf.tinyshell`.
- Infrastructure (C2, domains, IPs): Not detailed in the provided context.
## Implications
The actor is engaged in espionage, leveraging access to critical network infrastructure (Juniper routers) to maintain persistence and potentially exfiltrate sensitive information.
## Mitigations
- Patching and securing Juniper router deployments against known vulnerabilities targeted by the actor. (Specific mitigation details would rely on the content of the full report.)