UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware Exploitation, Covert Infrastructure Persistence — Threadlinqs Intelligence
As of 2026-05-30, UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware Exploitation, Covert Infrastructure Persistence is a critical-severity apt threat attributed to UNC3886 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-0221 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: APT
Attribution: UNC3886 · China · ESPIONAGE
China-nexus APT group UNC3886 exploited zero-day vulnerabilities in Fortinet FortiOS and VMware vCenter/ESXi to deploy REPTILE and MEDUSA rootkits against all four major Singaporean telecom operators
UNC3886 is a highly sophisticated China-nexus cyber espionage group active since at least 2022, known for exploiting zero-day vulnerabilities in edge devices and virtualization platforms to establish stealthy, long-term persistent access to high-value targets. In this campaign, UNC3886 targeted Singapore's critical telecommunications infrastructure, compromising all four major operators — M1, SIMBA Telecom, Singtel, and StarHub.
The initial intrusion vector involved exploitation of a zero-day vulnerability to bypass perimeter firewalls, consistent with UNC3886's documented use of CVE-2022-42475 (FortiOS SSL VPN heap buffer overflow enabling unauthenticated remote code execution) and CVE-2022-41328 (FortiOS path traversal via CLI commands). Once inside the network perimeter, the threat actor exploited VMware vCenter vulnerabilities including CVE-2023-34048 (DCERPC out-of-bounds write for unauthenticated RCE) and CVE-2023-20867 (VMware Tools authentication bypass) to pivot through virtualization infrastructure.
For persistence and defense evasion, UNC3886 deployed the REPTILE kernel-mode Linux rootkit, which provides stealthy process, file, and network connection hiding capabilities through flag manipulation, as well as reverse shell access via port knocking. The MEDUSA rootkit, utilizing LD_PRELOAD dynamic linker hijacking, was deployed for credential logging from PAM authentication hooks and covert command execution. Both rootkits were installed on guest virtual machines to maintain access and evade endpoint detection.
The campaign's command-and-control infrastructure leveraged Operational Relay Box (ORB) networks — a sophisticated proxy mesh that routes attacker traffic through compromised devices and rented infrastructure across multiple autonomous systems. Team Cymru identified up to 12 unique ORB-tagged IPs communicating with the four victim ISPs within a 90-day window, with 44 total ORB nodes located within Singapore. In a 30-day observation period, 42 unique ORB IPs communicated with victim ISPs, while 62 unique victim IPs communicated back with ORBs, indicating deep network penetration.
Additional malware deployed includes TinyShell (a Python-based RAT providing HTTP/HTTPS command execution), CASTLETAP (a passive FortiGate firewall backdoor disguised as /bin/fgfm that activates on specially crafted ICMP magic packets), MOPSLED (a modular shellcode backdoor using ChaCha20 encryption with HTTP/TCP C2), RIFLESPINE (a cross-platform backdoor leveraging Google Drive for file transfers with AES encryption), and VIRTUALPITA/VIRTUALPIE (vSphere Installation Bundle backdoors for ESXi hypervisor persistence). LOOKOVER, a C-based sniffer, was used to intercept TACACS+ authentication credentials.
The Singapore Cyber Security Agency (CSA) first detected the intrusion on July 18, 2025, leading to Operation CYBER GUARDIAN — described as Singapore's largest-ever multi-agency cyber operation. The CSA confirmed that while the threat actor gained unauthorized access to parts of the telecom networks including critical systems, there was no evidence of personal data exfiltration or internet availability disruption. The campaign's primary objective was theft of communication infrastructure technical data, consistent with UNC3886's espionage mandate.
This campaign shares tooling and targeting overlaps with the Fire Ant cluster disclosed by Sygnia in July 2025, which similarly targeted VMware ESXi, vCenter environments, and network appliances. UNC3886 was also linked to Campaign RedPenguin (C0056, July 2024 - March 2025) targeting Juniper Networks routers with custom TINYSHELL-based backdoors, exploiting CVE-2025-21590 (Junos OS kernel privilege escalation).
Weaknesses (CWE)
CWE-122, CWE-22, CWE-787, CWE-287, CWE-732, CWE-269
Target sectors: telecommunications, critical-infrastructure, government, defense, technology
Target regions: Singapore, Southeast Asia, Asia-Pacific
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2022-41328, CVE-2022-42475, CVE-2023-34048, CVE-2023-20867, CVE-2022-22948, CVE-2025-21590, T1190, T1059, T1059, T1059, T1059, T1203, T1098, T1037, T1543, T1505