UNC4990 is a financially motivated threat actor that has been active since at least 2020. They primarily target users in Italy and rely on USB devices for initial infection. The group has evolved their tactics over time, using encoded text files on popular websites like GitHub and Vimeo to host payloads. They have been observed using sophisticated backdoors like QUIETBOARD and EMPTYSPACE, and have targeted organizations in various industries, particularly in Italy.
Executive Summary
UNC4990 is a financially motivated threat actor targeting users primarily in Italy since 2020. They use USB devices for initial infections and have evolved their tactics, leveraging encoded text files on public websites like GitHub and Vimeo to host payloads. The group employs sophisticated backdoors such as QUIETBOARD and EMPTYSPACE, indicating a high level of technical proficiency.
Goals & Targeting
UNC4990's strategic objectives appear to be primarily financial in nature, with a focus on accessing sensitive data or systems that could be monetized. Their targeting of Italy suggests either a specific interest in Italian organizations or an operational preference for regions where their tactics can be more effectively executed. The group’s use of sophisticated backdoors like QUIETBOARD and EMPTYSPACE indicates a long-term vision to maintain persistent access to targeted networks, enabling continuous data extraction or other malicious activities.
Enhanced Description
UNC4990 is identified as a financially motivated cyber threat actor who has been active since at least 2020. Their primary targets are individuals and organizations located in Italy, with initial infections often facilitated through the use of USB devices. Over time, this group has demonstrated an ability to evolve their tactics, transitioning from basic methods to more sophisticated approaches. Notably, UNC4990 has been observed utilizing encoded text files on popular websites such as GitHub and Vimeo to host malicious payloads. This tactic allows them to hide their attack infrastructure under the guise of legitimate online platforms. The group is notable for deploying advanced backdoors like QUIETBOARD and EMPTYSPACE, indicating a high level of technical expertise. Despite their focus on意大利, there have been observations suggesting their activities may extend to other regions as well.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC4990's campaigns have demonstrated a patient and methodical approach to compromising targets. Their use of USB devices as an infection vector suggests a deliberate targeting process, possibly exploiting environments with less stringent security measures. The reliance on public websites for payload delivery indicates a strategic choice to avoid immediate detection while maintaining a persistent presence. Notable past operations include multiple waves of attacks in Italy and potential lateral movement activities within targeted networks once access is achieved.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the data about UNC4990 is moderate due to limited publicly available information. While their operational methods and targets are well-documented, specific technical details about their full attack chain remain unclear. Potential gaps include a deeper understanding of their long-term infrastructure and additional indicators beyond those already observed.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics