Also known as: UNC5221, Red Dev 61
While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the incident which primarily consisted of webshells, proxy utilities, and file modifications to allow credential harvesting. Once UTA0178 had access into the network via the ICS VPN appliance, their general approach was to pivot from system to system using compromised credentials. They would then further compromise credentials of users on any new system that was breached, and use these credentials to log into additional systems via RDP. Volexity observed the attacker obtaining credentials in a variety of ways.
Executive Summary
UTA0178, also known as UNC5221 or Red Dev 61, is a threat actor observed primarily in the energy sector. Their attacks involve initial access through compromised VPN appliances, followed by credential harvesting and横向 movement within networks using RDP. While their exact motivation remains unclear, their operational tactics suggest potential nation-state-sponsored activity.
Goals & Targeting
UTA0178 appears to target energy sector organizations, potentially to gather sensitive information or disrupt operations. Their use of credential harvesting and persistence techniques indicates an interest in long-term access rather than immediate damage. The targeting of ICS environments suggests a high-level operational objective, possibly aligned with nation-state interests.
Enhanced Description
UTA0178 operates with a focus on persistence and lateral movement within targeted networks. The actor employs webshells and proxy utilities to establish backdoors and harvest credentials, often moving from system to system using compromised user accounts. Their approach in the Volexity incident demonstrated a preference for living off the land while deploying minimal malware, indicating an emphasis on stealth. The group's targeting of ICS environments suggests a focus on critical infrastructure, possibly aligned with espionage or disruptive objectives.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UTA0178's campaigns appear to focus on prolonged network access and persistence. Their targeting of ICS environments suggests a strategic interest in industrial control systems, possibly for both espionage and disruption. The actor's operational tempo is methodical, with an emphasis on stealth and long-term access rather than rapid deployment of destructive payloads.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in UTA0178's details, given limited available intelligence. Additional data sharing between organizations and further analysis of their tools and techniques would improve understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
15
IOCs
0
Observed Data
0
Tactics