Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC4990

Description

UNC4990 is a financially motivated threat actor that has been active since at least 2020. They primarily target users in Italy and rely on USB devices for initial infection. The group has evolved their tactics over time, using encoded text files on popular websites like GitHub and Vimeo to host payloads. They have been observed using sophisticated backdoors like QUIETBOARD and EMPTYSPACE, and have targeted organizations in various industries, particularly in Italy.

AI Analysis

· 1 week ago

Executive Summary

UNC4990 is a financially motivated threat actor targeting users primarily in Italy since 2020. They use USB devices for initial infections and have evolved their tactics, leveraging encoded text files on public websites like GitHub and Vimeo to host payloads. The group employs sophisticated backdoors such as QUIETBOARD and EMPTYSPACE, indicating a high level of technical proficiency.

Goals & Targeting

UNC4990's strategic objectives appear to be primarily financial in nature, with a focus on accessing sensitive data or systems that could be monetized. Their targeting of Italy suggests either a specific interest in Italian organizations or an operational preference for regions where their tactics can be more effectively executed. The group’s use of sophisticated backdoors like QUIETBOARD and EMPTYSPACE indicates a long-term vision to maintain persistent access to targeted networks, enabling continuous data extraction or other malicious activities.

Enhanced Description

UNC4990 is identified as a financially motivated cyber threat actor who has been active since at least 2020. Their primary targets are individuals and organizations located in Italy, with initial infections often facilitated through the use of USB devices. Over time, this group has demonstrated an ability to evolve their tactics, transitioning from basic methods to more sophisticated approaches. Notably, UNC4990 has been observed utilizing encoded text files on popular websites such as GitHub and Vimeo to host malicious payloads. This tactic allows them to hide their attack infrastructure under the guise of legitimate online platforms. The group is notable for deploying advanced backdoors like QUIETBOARD and EMPTYSPACE, indicating a high level of technical expertise. Despite their focus on意大利, there have been observations suggesting their activities may extend to other regions as well.

Key Capabilities

  • Sophisticated backdoor development (QUIETBOARD, EMPTYSPACE)
  • Evolved tactics using encoded text files on public websites
  • USB-based initial infection methods
  • Persistence mechanisms for long-term access

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1059
T1064
T1003.002

Software / Tooling

QUIETBOARD
EMPTYSPACE
Encoded Text Files (malicious payloads)

Campaigns & Victims

UNC4990's campaigns have demonstrated a patient and methodical approach to compromising targets. Their use of USB devices as an infection vector suggests a deliberate targeting process, possibly exploiting environments with less stringent security measures. The reliance on public websites for payload delivery indicates a strategic choice to avoid immediate detection while maintaining a persistent presence. Notable past operations include multiple waves of attacks in Italy and potential lateral movement activities within targeted networks once access is achieved.

IOC Patterns

  • USB devices used as infection vectors
  • Encoded text files hosted on public websites like GitHub or Vimeo
  • Sophisticated backdoor payloads (e.g., QUIETBOARD)

Recommended Actions

  • Implement strict USB device policies and monitoring
  • Monitor public hosting platforms for suspicious activity
  • Deploy endpoint detection solutions to identify encoded threats
  • Conduct regular audits of network access points

Suggested Tags

Financially motivated
APT
Persistence
Italy-focused

Confidence Assessment

The confidence level in the data about UNC4990 is moderate due to limited publicly available information. While their operational methods and targets are well-documented, specific technical details about their full attack chain remain unclear. Potential gaps include a deeper understanding of their long-term infrastructure and additional indicators beyond those already observed.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
Financially motivated
APT
Persistence
Italy-focused

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.