Campaign · all campaigns
RedPenguinC0056 state
🇨🇳 CN
aka RedPenguin
Run by UNC3886
Last updated: 2026-08-20
1attributed CVEs
32ATT&CK techniques
4.3IDF score (tooling uniqueness)
1exclusive CVEs
2025years active
About this actor
The [RedPenguin](https://attack.mitre.org/campaigns/C0056) project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. [RedPenguin](https://attack.mitre.org/campaigns/C0056) activity was separately attributed to [UNC3886](https://attack.mitre.org/groups/G1048) and included the deployment of multiple custom versions of the publicly-available TINYSHELL backdoor on Juniper routers.(Citation: Juniper RedPenguin MAR 2025)(Citation: Mandiant UNC3886 Juniper Routers MAR 2025)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 32 ATT&CK techniques on file.
- Named victims
- 1 extracted from reporting.
Thin data: Only one named victim is on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2025 — 1 CVE published, 1 KEV added
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2025-21590 KEV | 7.5 | 4.4 | 0.0274 | 2025-03-12 | see CVE |
T1014Rootkit ↗T1016System Network Configuration Discovery ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1040Network Sniffing ↗T1041Exfiltration Over C2 Channel ↗T1055Process Injection ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.004Unix Shell ↗T1059.008Network Device CLI ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1070.007Clear Network Connection History and Configurations ↗T1078Valid Accounts ↗T1090Proxy ↗T1090.003Multi-hop Proxy ↗T1095Non-Application Layer Protocol ↗T1104Multi-Stage Channels ↗T1105Ingress Tool Transfer ↗T1140Deobfuscate/Decode Files or Information ↗T1203Exploitation for Client Execution ↗T1205Traffic Signaling ↗T1554Compromise Host Software Binary ↗T1571Non-Standard Port ↗T1573Encrypted Channel ↗T1573.001Symmetric Cryptography ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1690Prevent Command History Logging ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 22 / 32 | 69% |
CM-6 | 21 / 32 | 66% |
SI-3 | 20 / 32 | 62% |
CM-2 | 18 / 32 | 56% |
CA-7 | 17 / 32 | 53% |
CM-7 | 16 / 32 | 50% |
AC-3 | 15 / 32 | 47% |
SC-7 | 13 / 32 | 41% |
AC-4 | 11 / 32 | 34% |
AC-6 | 11 / 32 | 34% |
SI-7 | 11 / 32 | 34% |
AC-2 | 10 / 32 | 31% |
SI-10 | 8 / 32 | 25% |
AC-5 | 6 / 32 | 19% |
AC-17 | 5 / 32 | 16% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- KV Botnet Activity 0.25
- ArcaneDoor 0.24
- UNC3886 0.23
- Darkhotel 0.22
- Tropic Trooper 0.21
Active in same years
- ArcaneDoor 1.00
- SharePoint ToolShell Exploitation 1.00
- Kimsuky 1.00
- Volt Typhoon 1.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00