Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-02

UNC2814

Also known as:Alloy TaurusGranite TyphoonPHANTOM PANDARed Dev 4

As of 2026-05-30, UNC2814 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning apt. Also known as Alloy Taurus, Granite Typhoon, PHANTOM PANDA, Red Dev 4. ATT&CK coverage spans 56 techniques across 14 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1105 (Ingress Tool Transfer).

Tracked threats
43 critical · 1 high
First seen
2026-02-25
Last seen
2026-05-11
ATT&CK techniques
56across 4 of 4 threats
Related CVEs
0None referenced
Attribution
ChinaNation or origin
Nation: China · 4 tracked threat(s) · Categories: APT

Activity timeline

UNC2814 appears in 4 tracked threats between and ; the busiest month was 2026-03 with 2 reports.

ATT&CK techniques observed

56 techniques observed across 4 of 4 tracked threats · Command and Control (12), Stealth (formerly Defense Evasion) (7), Credential Access (6), Discovery (5), Collection (4), Exfiltration (4)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 4 of 4 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 4 of 4 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 4 of 4 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 4 tracked threats
  • T1078 Valid Accounts — Persistenceobserved in 3 of 4 tracked threats
  • T1572 Protocol Tunneling — Command and Controlobserved in 3 of 4 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 4 tracked threats
  • T1021.004 SSH — Lateral Movementobserved in 2 of 4 tracked threats
  • T1033 System Owner/User Discovery — Discoveryobserved in 2 of 4 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 4 tracked threats
  • T1059.004 Unix Shell — Executionobserved in 2 of 4 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 4 tracked threats

Tracked threats