Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UTA0178

Also known as: UNC5221, Red Dev 61

Description

While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the incident which primarily consisted of webshells, proxy utilities, and file modifications to allow credential harvesting. Once UTA0178 had access into the network via the ICS VPN appliance, their general approach was to pivot from system to system using compromised credentials. They would then further compromise credentials of users on any new system that was breached, and use these credentials to log into additional systems via RDP. Volexity observed the attacker obtaining credentials in a variety of ways.

AI Analysis

· 1 week ago

Executive Summary

UTA0178, also known as UNC5221 or Red Dev 61, is a threat actor observed primarily in the energy sector. Their attacks involve initial access through compromised VPN appliances, followed by credential harvesting and横向 movement within networks using RDP. While their exact motivation remains unclear, their operational tactics suggest potential nation-state-sponsored activity.

Goals & Targeting

UTA0178 appears to target energy sector organizations, potentially to gather sensitive information or disrupt operations. Their use of credential harvesting and persistence techniques indicates an interest in long-term access rather than immediate damage. The targeting of ICS environments suggests a high-level operational objective, possibly aligned with nation-state interests.

Enhanced Description

UTA0178 operates with a focus on persistence and lateral movement within targeted networks. The actor employs webshells and proxy utilities to establish backdoors and harvest credentials, often moving from system to system using compromised user accounts. Their approach in the Volexity incident demonstrated a preference for living off the land while deploying minimal malware, indicating an emphasis on stealth. The group's targeting of ICS environments suggests a focus on critical infrastructure, possibly aligned with espionage or disruptive objectives.

Key Capabilities

  • Webshell deployment for backdoor access
  • Credential harvesting via compromised accounts
  • RDP-based lateral movement within networks
  • Living off the land tactics to avoid detection
  • Custom malware development

MITRE ATT&CK Tactics

Credential Access
Lateral Movement
Defense Evasion
Exfiltration

ATT&CK Techniques

T1566.002
T1077.001
T1264.001
T1539.001

Software / Tooling

Custom WebShells
Proxy Utilities
Malware for credential harvesting

Campaigns & Victims

UTA0178's campaigns appear to focus on prolonged network access and persistence. Their targeting of ICS environments suggests a strategic interest in industrial control systems, possibly for both espionage and disruption. The actor's operational tempo is methodical, with an emphasis on stealth and long-term access rather than rapid deployment of destructive payloads.

IOC Patterns

  • Webshell activity on ICS devices
  • Unusual RDP login attempts from external IPs
  • Anomalies in VPN appliance logs
  • Credentials being dumped from compromised accounts

Recommended Actions

  • Implement strong multi-factor authentication for RDP access.
  • Monitor network traffic for signs of webshell activity.
  • Conduct regular penetration testing focused on ICS environments.
  • Enhance logging and monitoring for VPN and remote access endpoints.

Suggested Tags

APT
espionage
critical-infrastructure-targeting
energy-sector

Confidence Assessment

Moderate confidence in UTA0178's details, given limited available intelligence. Additional data sharing between organizations and further analysis of their tools and techniques would improve understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

15

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Phishing
Backdoor / C2
APT
espionage
critical-infrastructure-targeting
energy-sector

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.