Also known as: BokBot, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down
UNC4540 has been active since at least 2021, according to Mandiant intelligence, focusing on maintaining persistence on network appliances such as SonicWall Secure Mobile Access devices. The actor deploys a custom TinyShell backdoor variant that survives firmware upgrades, enabling credential theft—including hashed passwords and keystroke logging via Ghost RAT—and remote shell provision for further lateral movement. The malware also demonstrates the use of RClone for exfiltrating collected data over alternative protocols while maintaining cover by encrypting sensitive files when necessary. Zero‑day exploitation of FortiOS CVE-2022-42475 indicates that UNC4540 is prepared to pivot to other internet-facing appliances should SonicWall devices be patched or unavailable. Phishing campaigns featuring malicious macros remain a staple for initial access, while brute‑force attacks against remote desktop sessions complement the actor’s toolset. The confluence of credential theft, persistent backdoor capabilities and exfiltration tools suggests a strategy aimed at long‑term espionage with an overt financial payoff via double‑extortion tactics.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC4540 is a suspected Chinese threat actor that primarily targets unpatched SonicWall Secure Mobile Access appliances, employing custom firmware‑upgrade resilient malware to steal credentials and provide long‑term remote shell access. The group additionally leverages phishing with malicious macros, zero‑day exploits against FortiOS CVE-2022-42475, and exfiltrates data via RClone, following a double‑extortion strategy that combines ransomware encryption with theft of insider data.
Goals & Targeting
UNC4540 seeks to secure enduring footholds in high-value sectors—including government, defense, finance, healthcare, and critical infrastructure—by exploiting network device vulnerabilities for prolonged espionage. The group’s focus on credential harvesting, persistent shell access and data exfiltration reflects a dual motive: covert intelligence gathering and financial gain through extortion or direct theft of monetizable information.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC4540 operates on an opportunistic, high‑impact cadence: it rapidly exploits unpatched network appliances across a broad geographic footprint that spans China, Russia, Ukraine, India, the UK, Germany, North Korea and others. Victims are typically mid to large enterprises with external-facing VPN or RDP access. The actor’s campaigns feature rapid exploitation of public-facing services followed by stealthy persistence mechanisms that survive firmware updates—an approach that enables long‑term operational security. Recent operations have revealed a trend toward simultaneous ransomware activity and data theft, indicating the use of double‑extortion tactics to monetize compromised environments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information on UNC4540’s focus on SonicWall Secure Mobile Access appliances, firmware‑upgrade resilient malware and credential theft is supported by multiple reputable sources (Mandiant, Malpedia, Ars Technica). Confidence in the use of RClone for exfiltration and the exploitation of FortiOS CVE-2022-42475 is moderate, based on indirect attribution. Details about additional tools such as Black Basta or broader double‑extortion operations are less certain and rely on context from related Chinese threat actor patterns.
No campaigns linked yet.
No observed data linked yet.
17
Techniques
45
Tools
0
Campaigns
33
IOCs
0
Observed Data
7
Tactics