Fire Ant

☆ pin
Also known as UNC3886
Reports
3
First seen
Aug 31, 2026
Last seen
Aug 31, 2026
Motivation
Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Top ATT&CK techniques

T1003 OS Credential Dumping ×2T1041 Exfiltration Over C2 Channel ×2T1562.001 Impair Defenses: Disable or Modify Tools ×2T1543 Create or Modify System Process ×2T1070.001 Indicator Removal: Clear Windows Event Logs ×2T1547.004 Boot or Logon Autostart Execution: Systemd ×1T1204 User Execution ×1T1021.004 Remote Services: SSH ×1T1078 Valid Accounts ×1T1555 Credentials from Password Stores ×1T1021 Remote Services ×1T1021.001 Remote Services: Remote Desktop Protocol ×1

Indicators

cve ×68hash_sha1 ×6filename ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.