Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC4540

Also known as: BokBot, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down

Description

UNC4540 has been active since at least 2021, according to Mandiant intelligence, focusing on maintaining persistence on network appliances such as SonicWall Secure Mobile Access devices. The actor deploys a custom TinyShell backdoor variant that survives firmware upgrades, enabling credential theft—including hashed passwords and keystroke logging via Ghost RAT—and remote shell provision for further lateral movement. The malware also demonstrates the use of RClone for exfiltrating collected data over alternative protocols while maintaining cover by encrypting sensitive files when necessary. Zero‑day exploitation of FortiOS CVE-2022-42475 indicates that UNC4540 is prepared to pivot to other internet-facing appliances should SonicWall devices be patched or unavailable. Phishing campaigns featuring malicious macros remain a staple for initial access, while brute‑force attacks against remote desktop sessions complement the actor’s toolset. The confluence of credential theft, persistent backdoor capabilities and exfiltration tools suggests a strategy aimed at long‑term espionage with an overt financial payoff via double‑extortion tactics.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Healthcare
Education
Telecommunications
Critical infrastructure
Manufacturing
Media
Retail
Non profit
Information technology
Hospitality
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation
Pharmaceutical
Chemical

Targeted Countries / Regions

CN
RU
IN
UA
GB
DE
KP
IR
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

UNC4540 is a suspected Chinese threat actor that primarily targets unpatched SonicWall Secure Mobile Access appliances, employing custom firmware‑upgrade resilient malware to steal credentials and provide long‑term remote shell access. The group additionally leverages phishing with malicious macros, zero‑day exploits against FortiOS CVE-2022-42475, and exfiltrates data via RClone, following a double‑extortion strategy that combines ransomware encryption with theft of insider data.

Goals & Targeting

UNC4540 seeks to secure enduring footholds in high-value sectors—including government, defense, finance, healthcare, and critical infrastructure—by exploiting network device vulnerabilities for prolonged espionage. The group’s focus on credential harvesting, persistent shell access and data exfiltration reflects a dual motive: covert intelligence gathering and financial gain through extortion or direct theft of monetizable information.

Enhanced Description

Key Capabilities

  • Persistence via firmware upgrade exploitation
  • Credential theft (hashed passwords and keystrokes) using TinyShell/backdoor
  • Remote shell access provision on compromised devices
  • Exfiltration with RClone over alternative protocols
  • Keystroke logging via Ghost RAT
  • Initial access through external-facing services exploitation (VPN, RDP)
  • Phishing campaigns with malicious macros
  • Zero‑day exploitation of FortiOS CVE-2022-42475

MITRE ATT&CK Tactics

Initial Access
Persistence
Credential Access
Exfiltration
Impact
Privilege Escalation

ATT&CK Techniques

T1190
T1133
T1048
T1567
T1657
T1037
T1003
T1543
T1059

Software / Tooling

TinyShell backdoor
Ghost RAT
Nitrogen Loader
RClone
FortiOS CVE-2022-42475 exploit scripts
Credential‑stealing malware variant of UNC4540

Campaigns & Victims

UNC4540 operates on an opportunistic, high‑impact cadence: it rapidly exploits unpatched network appliances across a broad geographic footprint that spans China, Russia, Ukraine, India, the UK, Germany, North Korea and others. Victims are typically mid to large enterprises with external-facing VPN or RDP access. The actor’s campaigns feature rapid exploitation of public-facing services followed by stealthy persistence mechanisms that survive firmware updates—an approach that enables long‑term operational security. Recent operations have revealed a trend toward simultaneous ransomware activity and data theft, indicating the use of double‑extortion tactics to monetize compromised environments.

IOC Patterns

  • Persistence through firmware upgrade exploitation
  • Credential harvesting (hashed or keystroke)
  • Provision of remote shell access via compromise
  • Data exfiltration via RClone over alternative protocols
  • Exploitation of FortiOS CVE-2022-42475 zero‑day
  • Targeting unpatched SonicWall Secure Mobile Access gateways
  • Malicious macro delivery through phishing emails

Recommended Actions

  • Apply timely firmware updates to all SonicWall and other network appliances.
  • Disable unused remote services (RDP, VPN) on security devices.
  • Implement multi‑factor authentication for Remote Desktop and VPN access.
  • Educate users on spotting phishing with malicious macros.
  • Monitor logs for signs of keystroke logging or abnormal credential requests.
  • Patch FortiOS and SonicWall devices immediately upon release.
  • Segment critical infrastructure from public‑facing interfaces via network segmentation.
  • Deploy endpoint detection that flags known credential‑stealing malware on SonicWall gateways.
  • Maintain up‑to‑date vulnerability databases and ingest latest threat intelligence feeds.

Suggested Tags

UNC4540
Chinese threat actor
SonicWall SMA persistence
Firmware upgrade exploitation
Keystroke logging
Double-extortion tactics
Ghost RAT
Nitrogen Loader
RClone
Zero-day Exploit
Network Device Exploitation
Credential Theft

Confidence Assessment

The information on UNC4540’s focus on SonicWall Secure Mobile Access appliances, firmware‑upgrade resilient malware and credential theft is supported by multiple reputable sources (Mandiant, Malpedia, Ars Technica). Confidence in the use of RClone for exfiltration and the exploitation of FortiOS CVE-2022-42475 is moderate, based on indirect attribution. Details about additional tools such as Black Basta or broader double‑extortion operations are less certain and rely on context from related Chinese threat actor patterns.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 8 Email Address 2 Filename 8 MD5 Hash 2

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Royal Ransomware
  2. mallory.ai — Cited by web research for: T1037
  3. cloud.google.com — Cited by web research for: TinyShell
  4. pmc.ncbi.nlm.nih.gov — Cited by web research for: Interception
  5. andreafortuna.org — Cited by web research for: andrea@andreafortuna.org
  6. https://malpedia.caad.fkie.fraunhofer.de/actor/unc4540 — Cited by AI analysis.
  7. https://malpedia.caad.fkie.fraunhofer.de/details/win.ghost_rat — Cited by AI analysis.
  8. https://arstechnica.com/information-technology/2023/03/malware-infecting-widely-used-security-appliance-survive — Cited by AI analysis.
  9. https://malpedia.caad.fkie.fraunhofer.de/details/win.nitrogen — Cited by AI analysis.
  10. https://www.mandiant.com/blog/suspected-chinese-threat-actors-exploiting-fortios-vulnerability-cve-2022-42475 — Cited by AI analysis.

Intel Summary

17

Techniques

45

Tools

0

Campaigns

33

IOCs

0

Observed Data

7

Tactics

Tags

APT
Critical Infrastructure
Zero-Day Exploitation
Backdoor / C2
UNC4540
Chinese threat actor
SonicWall SMA persistence
Firmware upgrade exploitation
Keystroke logging
Double-extortion tactics
Ghost RAT
Nitrogen Loader
RClone
Zero-day Exploit
Network Device Exploitation
Credential Theft

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.