Uptime Hamster: 21d 9h 1mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza UNC4841

UNC4841

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: SLIME57, GhostEmperor, UNC4841 o Salt Typhoon, Salt Typhoon, US Government wiretap system, este grupo ha sido vinculado a operaciones de espionaje, violación de redes de organizaciones gubernamentales, empresas
Ver en IntelTracker → APTTrail →
UNC4841 is a cyber espionage threat actor assessed with high confidence to be a China-nexus group operating in support of the People's Republic of China, which emerged in at least October 2022. The group's primary motivation is to gather intelligence of political or strategic interest to China through targeted information collection. What sets UNC4841 apart is its rapid and sophisticated adaptation to defensive efforts, including quickly modifying its malware and deploying new persistence mechanisms in response to patches. While it shares infrastructure overlaps with other China-nexus actors like UNC2286 (also known as GhostEmperor, FamousSparrow, Earth Estries, and Salt Typhoon), Mandiant has not formally attributed UNC4841's activity to a previously known group. This actor is also known by the synonym SLIME57.

Aliases del actor

SLIME57GhostEmperorUNC4841 o Salt TyphoonSalt TyphoonUS Government wiretap systemeste grupo ha sido vinculado a operaciones de espionajeviolación de redes de organizaciones gubernamentalesempresas

Actores similares

Salt Typhoonthreat-actor · 1volt-typhoonactor · 1salty-spideractor · 1apt-flaxtyphoonactor · 1Volt Typhoonthreat-actor · 1SALTY SPIDERapt · 0Flax Typhoonapt · 0Raspberry Typhoonapt · 0Lilac Typhoonapt · 0System Owner/User Discoveryactor · 1
Motivacion