logo

UNC3886__2023__Mandiant_Fortinet-Zero-Day-Suspected-Chinese-Operation_03-16-2023.pdf

ID: c6c3e07d-7e00-48a6-8232-2b64dc2a485d

STIX ID: report--c6c3e07d-7e00-48a6-8232-2b64dc2a485d

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2023-03-17

Last Modified Date: 2023-03-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Executive summary: Mandiant details a suspected China-nexus cyber espionage operation (UNC3886) that exploited the Fortinet FortiOS zero-day CVE-2022-41328 and related VMware ESXi components to deploy multiple custom backdoors across Fortinet appliances (FortiGate, FortiManager, FortiAnalyzer) and ESXi hypervisors, enabling persistent access, credential theft, and lateral movement; the operation employs backdoors such as THINCRUST, CASTLETAP, REPTILE, TABLEFLIP, and VIRTUALPITA, includes anti-forensics, and demonstrates capability to bypass ACLs and stealthily maintain access across environments.