UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware Exploitation, Covert Infrastructure Persistence
UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean (TL-2026-0221), also tracked as Operation CYBER GUARDIAN, is a critical-severity advanced persistent threat campaign scored CVSS 9.8, first published 2026-03-13 and last reviewed 2026-08-30. It is attributed to UNC3886 (China) with high confidence, affects Fortinet FortiOS, references 7 CVEs (CVE-2022-41328, CVE-2022-42475, CVE-2023-34048), maps to 50 MITRE ATT&CK techniques (T1003, T1003.001, T1005), and is covered by 9 detection rules and 40 indicators of compromise.
Key facts for TL-2026-0221
- Threat ID
- TL-2026-0221
- Also known as
- Operation CYBER GUARDIAN, Campaign RedPenguin
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- APT
- First published
- 2026-03-13
- Last reviewed
- 2026-08-30
- Attribution
- UNC3886
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- telecommunications, critical-infrastructure, government, defense, technology
- Target regions
- Singapore, Southeast Asia, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 40
- Updates
- 2026-08-30 · revalidated 1× · latest source
Malware and tooling in UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean
Malware and tooling: CASTLETAP - S1224, GobRAT, LOOKOVER, MEDUSA - S1220, MOPSLED - S1221, REPTILE - S1219, RIFLESPINE - S1222, VIRTUALPIE - S1218, VIRTUALPITA - S1217, tsh, ORB Network
China-nexus APT group UNC3886 exploited zero-day vulnerabilities in Fortinet FortiOS and VMware vCenter/ESXi to deploy REPTILE and MEDUSA rootkits against all four major Singaporean telecom operators (M1, SIMBA Telecom, Singtel, StarHub), leveraging Operational Relay Box (ORB) network infrastructure for covert C2 communications and stealing communication infrastructure technical data in a multi-year espionage campaign that triggered Singapore's largest-ever multi-agency cyber response, Operation CYBER GUARDIAN.
How UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean works
UNC3886 is a highly sophisticated China-nexus cyber espionage group active since at least 2022, known for exploiting zero-day vulnerabilities in edge devices and virtualization platforms to establish stealthy, long-term persistent access to high-value targets. In this campaign, UNC3886 targeted Singapore's critical telecommunications infrastructure, compromising all four major operators — M1, SIMBA Telecom, Singtel, and StarHub.
The initial intrusion vector involved exploitation of a zero-day vulnerability to bypass perimeter firewalls, consistent with UNC3886's documented use of CVE-2022-42475 (FortiOS SSL VPN heap buffer overflow enabling unauthenticated remote code execution) and CVE-2022-41328 (FortiOS path traversal via CLI commands). Once inside the network perimeter, the threat actor exploited VMware vCenter vulnerabilities including CVE-2023-34048 (DCERPC out-of-bounds write for unauthenticated RCE) and CVE-2023-20867 (VMware Tools authentication bypass) to pivot through virtualization infrastructure.
For persistence and defense evasion, UNC3886 deployed the REPTILE kernel-mode Linux rootkit, which provides stealthy process, file, and network connection hiding capabilities through flag manipulation, as well as reverse shell access via port knocking. The MEDUSA rootkit, utilizing LD_PRELOAD dynamic linker hijacking, was deployed for credential logging from PAM authentication hooks and covert command execution. Both rootkits were installed on guest virtual machines to maintain access and evade endpoint detection.
The campaign's command-and-control infrastructure leveraged Operational Relay Box (ORB) networks — a sophisticated proxy mesh that routes attacker traffic through compromised devices and rented infrastructure across multiple autonomous systems. Team Cymru identified up to 12 unique ORB-tagged IPs communicating with the four victim ISPs within a 90-day window, with 44 total ORB nodes located within Singapore. In a 30-day observation period, 42 unique ORB IPs communicated with victim ISPs, while 62 unique victim IPs communicated back with ORBs, indicating deep network penetration.
Additional malware deployed includes TinyShell (a Python-based RAT providing HTTP/HTTPS command execution), CASTLETAP (a passive FortiGate firewall backdoor disguised as /bin/fgfm that activates on specially crafted ICMP magic packets), MOPSLED (a modular shellcode backdoor using ChaCha20 encryption with HTTP/TCP C2), RIFLESPINE (a cross-platform backdoor leveraging Google Drive for file transfers with AES encryption), and VIRTUALPITA/VIRTUALPIE (vSphere Installation Bundle backdoors for ESXi hypervisor persistence). LOOKOVER, a C-based sniffer, was used to intercept TACACS+ authentication credentials.
The Singapore Cyber Security Agency (CSA) first detected the intrusion on July 18, 2025, leading to Operation CYBER GUARDIAN — described as Singapore's largest-ever multi-agency cyber operation. The CSA confirmed that while the threat actor gained unauthorized access to parts of the telecom networks including critical systems, there was no evidence of personal data exfiltration or internet availability disruption. The campaign's primary objective was theft of communication infrastructure technical data, consistent with UNC3886's espionage mandate.
This campaign shares tooling and targeting overlaps with the Fire Ant cluster disclosed by Sygnia in July 2025, which similarly targeted VMware ESXi, vCenter environments, and network appliances. UNC3886 was also linked to Campaign RedPenguin (C0056, July 2024 - March 2025) targeting Juniper Networks routers with custom TINYSHELL-based backdoors, exploiting CVE-2025-21590 (Junos OS kernel privilege escalation).
MITRE ATT&CK techniques used in TL-2026-0221
credential-access
T1003 OS Credential Dumping; T1040 Network Sniffing; T1212 Exploitation for Credential Access; T1557 Adversary-in-the-Middle
Credential Access
T1003.001 OS Credential Dumping; T1649 Steal or Forge Authentication Certificates
Collection
defense-evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1078 Valid Accounts; T1205 Traffic Signaling; T1564 Hide Artifacts
discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1083 File and Directory Discovery; T1673 Virtual Machine Discovery
lateral-movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027.005 Obfuscated Files or Information; T1036.005 Masquerading; T1562.001 Impair Defenses; T1564.006 Hide Artifacts
persistence
T1037 Boot or Logon Initialization Scripts; T1098 Account Manipulation; T1505 Server Software Component; T1543 Create or Modify System Process; T1554 Compromise Host Software Binary
Persistence
T1037.004 Boot or Logon Initialization Scripts; T1505.003 Server Software Component
exfiltration
T1041 Exfiltration Over C2 Channel
collection
T1056 Input Capture; T1074 Data Staged
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Execution
T1059.001 Command and Scripting Interpreter; T1675 ESXi Administration Command
privilege-escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
command-and-control
T1090 Proxy; T1095 Non-Application Layer Protocol; T1104 Multi-Stage Channels; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel
Command and Control
T1090.001 Proxy; T1572 Protocol Tunneling
initial-access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
defense-impairment
Affected products and versions in UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean
- Fortinet — FortiOS
Vulnerable versions: 7.2.0-7.2.3; 7.0.0-7.0.9; before 6.4.11
Fixed in: 7.2.4+; 7.0.10+; 6.4.11+ - VMware — vCenter Server
Vulnerable versions: All versions before October 2023 patch
Fixed in: Patched October 2023 - VMware — VMware Tools
Vulnerable versions: Versions affected by CVE-2023-20867
Fixed in: Patched versions - VMware — ESXi
Vulnerable versions: Multiple versions
Fixed in: Latest patched versions - Juniper — Junos OS
Vulnerable versions: Versions affected by CVE-2025-21590
Fixed in: Patched versions - M1 Limited — Telecommunications Infrastructure
Vulnerable versions: Targeted
Fixed in: Under remediation - SIMBA Telecom — Telecommunications Infrastructure
Vulnerable versions: Targeted
Fixed in: Under remediation - Singtel — Telecommunications Infrastructure
Vulnerable versions: Targeted
Fixed in: Under remediation - StarHub — Telecommunications Infrastructure
Vulnerable versions: Targeted
Fixed in: Under remediation
Remediation for UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean
Patches
- Apply Fortinet FortiOS patches for CVE-2022-41328 (upgrade to 7.2.4+, 7.0.10+, or 6.4.11+)
- Apply Fortinet FortiOS patches for CVE-2022-42475 (upgrade to 7.2.3+, 7.0.9+, or 6.4.11+)
- Apply VMware vCenter patch for CVE-2023-34048 (patched October 2023)
- Apply VMware Tools patch for CVE-2023-20867
- Apply VMware vCenter patch for CVE-2022-22948
- Apply Juniper Junos OS patch for CVE-2025-21590
Immediate actions
- Block all identified TinyShell and GOBRAT C2 IP addresses at network perimeter
- Hunt for REPTILE kernel module artifacts on Linux hosts and ESXi VMs (check for anomalous LKMs with lsmod, hidden processes, hidden network connections)
- Hunt for MEDUSA LD_PRELOAD rootkit by inspecting /etc/ld.so.preload and LD_PRELOAD environment variables across all Linux systems
- Audit all FortiGate firewall binaries for unauthorized modifications, especially /bin/fgfm (CASTLETAP indicator)
- Block ORB-tagged IP ranges communicating with telecom infrastructure at perimeter firewalls
- Rotate all TACACS+ credentials and SSH keys across network infrastructure
- Isolate and forensically image any VMware ESXi hosts showing anomalous vSphere Installation Bundles
Workarounds
- Restrict management access to FortiGate devices from trusted IPs only
- Disable unnecessary VMware guest operations if CVE-2023-20867 patch cannot be applied immediately
- Monitor for anomalous ICMP packets with non-standard payloads (CASTLETAP activation signature)
- Enable enhanced logging on all FortiGate, VMware, and Juniper devices to detect log tampering
Longer-term hardening
- Deploy EDR with kernel-level rootkit detection on all Linux hosts and VMs
- Implement network segmentation between management planes and production telecom infrastructure
- Deploy behavioral detection for ORB network proxy patterns and anomalous ICMP traffic
- Establish continuous monitoring of FortiGate, VMware vCenter, and Juniper device integrity
- Implement hardware-based integrity verification for edge devices and hypervisors
- Deploy TACACS+ encryption and mutual authentication to prevent credential interception
CVEs associated with UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean
CVE-2022-41328, CVE-2022-42475, CVE-2023-34048, CVE-2023-20867, CVE-2022-22948, CVE-2025-21590, CVE-2022-1388
Weaknesses (CWE) in UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean
CWE-122, CWE-22, CWE-787, CWE-287, CWE-732, CWE-269, CWE-306
Timeline of UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean
Showing the 20 most recent tracked events.
- UNC3886 begins exploiting CVE-2023-34048 in VMware vCenter Server, later identified by Mandiant as active since late 2021
- UNC3886 first observed active in cyber espionage operations targeting defense, technology, and telecom sectors
- F5 discloses CVE-2022-1388, a missing-authentication flaw in BIG-IP's iControl REST interface, and publishes patches in K23605346.
- CISA adds CVE-2022-1388 to the Known Exploited Vulnerabilities catalog and issues advisory AA22-138A amid active exploitation in the wild.
- Fortinet discloses CVE-2022-41328 (path traversal) and CVE-2022-42475 (heap buffer overflow) exploited by UNC3886 in FortiOS
- Mandiant publishes initial research on UNC3886 exploitation of Fortinet zero-days and custom malware ecosystem including CASTLETAP and THINCRUST
- VMware discloses CVE-2023-20867 (VMSA-2023-0013), a VMware Tools flaw allowing unauthenticated host-to-guest operations from a compromised ESXi host.
- VMware releases patch for CVE-2023-34048 (vCenter DCERPC out-of-bounds write) after UNC3886 exploitation confirmed since 2021
- Mandiant confirms UNC3886 exploited CVE-2023-34048 since late 2021, maintaining access for up to 18 months before discovery
- CISA adds CVE-2023-34048 to the Known Exploited Vulnerabilities catalog.
- Mandiant publishes 'Cloaked and Covert' report detailing REPTILE and MEDUSA rootkit deployments on VMware ESXi guest VMs
- Mandiant reports Campaign RedPenguin (C0056): UNC3886 targeting Juniper Networks routers with custom TINYSHELL backdoors, exploiting CVE-2025-21590
- Sygnia discloses Fire Ant cluster with tooling and targeting overlaps with UNC3886, targeting VMware ESXi/vCenter and network appliances
- Cyber Security Agency of Singapore (CSA) detects UNC3886 actively attacking Singapore critical telecommunications infrastructure
- Sygnia publishes its Fire Ant research documenting the actor's evolution from hypervisor compromise (ESXi/vCenter) to abuse of trusted network infrastructure (F5 BIG-IP) to bypass network segmentation.
- CSA confirms M1, SIMBA Telecom, Singtel, and StarHub all targeted; no personal data exfiltration or service disruption confirmed
- CSA announces Operation CYBER GUARDIAN — Singapore's largest-ever multi-agency cyber operation targeting UNC3886 across all four major telecom operators
- Team Cymru publishes ORB network tracking analysis identifying 12 unique ORB IPs on victim ISPs and 44 total Singapore-based ORB nodes
- ASEC (AhnLab) publishes February 2026 APT Group Trends Report documenting UNC3886 zero-day rootkit campaign against Singaporean telecom
- As of 2026-05-29, Singapore's 11-month Operation CYBER GUARDIAN evicted UNC3886 from all four telcos by Feb 2026 (access closed, CVEs patched), but the China-nexus actor remains undisrupted and active with vendors/OT-ISAC warning of ongoing persistent risk. The specific intrusion is remediated, yet the actor and edge/hypervisor rootkit tradecraft persist, so the threat warrants continued monitoring.
Update history for TL-2026-0221
- 2026-08-30 — Fire Ant Evolves: China-Nexus Espionage Group Extends Hypervisor Compromise to Trusted Network Infrastructure: What changed No field escalations. The record gains a genuinely new attack vector: exploitation of F5 BIG-IP (CVE-2022-1388) to plant webshells/tunnels that bridge network segments previously assumed isolated from the compromised hypervisor
Sources cited for UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean
- February 2026 APT Group Trends Report — ASEC (AhnLab)
- CSA Singapore — Largest Multi-Agency Cyber Operation Against UNC3886
- China-Linked UNC3886 Targets Singapore Telecom Sector — The Hacker News
- Singapore: Rootkits, Zero-Day Used in Chinese Attack on Major Telecom Firms — SecurityWeek
- Tracking ORBs on Singapore Telecommunications Networks — Team Cymru
- UNC3886 (G1048) — MITRE ATT&CK
- Cloaked and Covert: Uncovering UNC3886 Espionage Operations — Google Cloud / Mandiant
- Fortinet Zero-Day and Custom Malware in Espionage Operation — Google Cloud / Mandiant
- Chinese VMware Exploitation Since 2021 (CVE-2023-34048) — Google Cloud / Mandiant
- Revisiting UNC3886 Tactics to Defend Against Present Risk — Trend Micro
- Singapore Mounts Largest Ever Cyber Operation to Oust APT Actor — Computer Weekly
- Unmasking UNC3886: A Sophisticated Cyber Espionage Group — TXOne Networks
- UNC3886 Threat Actor Profile — FortiGuard
- Singapore Says China-Backed Hackers Targeted Largest Phone Companies — TechCrunch
- OT-ISAC Warns Singapore Critical Infrastructure of UNC3886 — Industrial Cyber
Threats related to UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean
Detection coverage for TL-2026-0221
As of 2026-08-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0221 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.