Singapore warns China-linked group UNC3886 targets its critical infrastructure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-41328 | Path Traversal in Fortinet FortiOS Exploited in Targeted Attacks CVE-2022-41328 is a path traversal flaw (CWE-22) in Fortinet FortiOS in which the system fails to properly limit file paths, allowing crafted CLI commands to escape the restricted directory. A privileged attacker — one who already has CLI access to the device — can issue these crafted commands to read and write arbitrary files on the underlying Linux system, effectively breaking out of the FortiOS CLI sandbox. That post-compromise capability is valuable for stealth and persistence, since changes to system files on the underlying OS may not be visible through normal FortiOS administration. Organizations running FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.9, or any release before 6.4.11 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-14, carries a high EPSS score (10.7% probability of exploitation within 30 days, 96th percentile), and public reporting describes its use in targeted cyberattacks on government entities attributed to the espionage group tracked as UNC3886, though no public proof-of-concept code is known. Do: Upgrade all affected FortiGate/FortiOS devices to a fixed release beyond the affected ranges — 7.2.4 or later, 7.0.10 or later, or 6.4.11 or later — per Fortinet's advisory, as required by the CISA KEV entry. Restrict privileged CLI access (admin accounts, trusted-host/local-in policies) and review CLI logs plus the underlying Linux filesystem for unexpected file changes as signs of compromise, particularly on government or otherwise high-value networks given UNC3886 targeting. | 7.1 | 11% | KEV |
| masshundreds of thousands of FortiGate deployments (well over 100,000 internet-facing FortiGates appear in public scans) |
Full article365 words · extracted from securityaffairs.com · click to collapse

Singapore says China-linked group UNC3886 targeted its critical infrastructure by hacking routers and security devices.
Singapore accused China-linked APT group UNC3886 of targeting its critical infrastructure. UNC3886 is a sophisticated China-linked cyber espionage group that targets network devices and virtualization technologies using zero-day exploits. Its primary focus is on defense, technology, and telecommunications sectors in the US and Asia.
In 2023, the APT group targeted multiple government organizations using the Fortinet zero-day CVE-2022-41328 to deploy custom backdoors.
In March 2025, the group carried out a campaign targeting Juniper Networks’ Junos OS routers, demonstrating a deep knowledge of system internals. UNC3886 prioritizes stealth by using passive backdoors and tampering with logs and forensic artifacts to ensure long-term persistence while evading detection.
Singapore’s Coordinating National Security Minister K. Shanmugam confirmed that the China-nexus group has targeted routers and security devices to infiltrate critical infrastructure in the country.
“UNC3886 poses a serious threat to us and has the potential to undermine our national security.” On July 18, Coordinating Minister for National Security K. Shanmugam said. “Even as we speak, UNC3886 is attacking our critical infrastructure right now.”
“The intent of this threat actor in attacking Singapore is quite clear. They are going after high-value, strategic targets – vital infrastructure that delivers our essential services.” he added.
“If it succeeds, it can conduct espionage, and it can cause major disruption to Singapore and Singaporeans.”
According to Shanmugan, the UNC3886’s activity is still ongoing and could potentially undermine the national security. He also added that the government will disclose more details later.
“Attacks on our systems and infrastructure will then impact on how we do business, who will be our vendors, and what’s in our supply chains,” he concluded. “All of that will have to be re-looked at, and if we decide that we cannot trust them then we may choose not to use them.”
China-linked APT groups often target Asian countries, such as Singapore, Japan, South Korea, Hong Kong, and Taiwan.
China-linked APT group Volt Typhoon is believed to have hacked Singapore’s mobile carrier Singapore Telecommunications in 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Singapore)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/180179/uncategorized/singapore-warns-china-linked-group-unc3886-targets-its-critical-infrastructure.html