Activity timeline
UNC6201 appears in 3 tracked threats between and ; the busiest month was 2026-02 with 1 report.
ATT&CK techniques observed
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 2 of 3 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 2 of 3 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 2 of 3 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 2 of 3 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 2 of 3 tracked threats
- T1587 Develop Capabilities — Resource Developmentobserved in 2 of 3 tracked threats
- T1588 Obtain Capabilities — Resource Developmentobserved in 2 of 3 tracked threats
- T1003.003 NTDS — Credential Accessobserved in 1 of 3 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 1 of 3 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 3 tracked threats
- T1021.004 SSH — Lateral Movementobserved in 1 of 3 tracked threats
Tracked threats
- GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day Exploit (2FA Bypass), PROMPTFLUX/HONESTCUE/CANFAIL/LONGSTREAM/PROMPTSPY AI-Enabled Malware, and APT27/APT45/UNC2814/UNC5673/UNC6201/TeamPCP AI-Augmented OperationsHIGH
- Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769)CRITICAL
- Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon, BRICKSTORM/GRIMBOLT/SLAYSTYLE, VMware Ghost NIC Pivoting, iptables SPACRITICAL