Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC4536

Also known as: EugenLoader, PaykLoader, APT32, APT28, Pawn Storm, Fancy Bear, Sednit, landing pages, are often, Akira, Sandworm, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, Royal Ransomware, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, PUNK SPIDER, GOLD SAHARA

Description

UNC4536, also operating under the monikers FakeBat, EugenLoader, and PaykLoader, specializes in distributing malicious payloads via fake software searches and malvertising campaigns. Utilizing trojanized MSIX installers that masquerade as legitimate applications, the group lures victims onto compromised download portals through SEO poisoning and Google Ads promotion, leading to rapid installation of backdoors such as CARBANAK. Beyond initial infection vectors, UNC4536 demonstrates sophisticated lateral movement tactics by hijacking Windows service binaries through permission flaws and exploiting remote services or zero‑day software vulnerabilities. The actor augments persistence through malicious code injected into cloud or container images and maintains stealthy command-and-control channels over public web services, frequently leveraging legitimate platforms such as Azure, AWS, or third‑party SaaS for data exfiltration. Financial gain remains the core motivation; however, the actor’s opportunistic nature allows it to target a broad spectrum of industries—including finance, defense, healthcare, and critical infrastructure—through targeted phishing with believable personas. By combining credential dumping, clipboard capture, audio logging, and cloud‑based data staging pipelines (e.g., BITS jobs), UNC4536 orchestrates high-impact ransomware or exfiltration campaigns that can culminate in data encryption for impact or monetary theft. Operationally, the group acquires infrastructure through purchased or compromised cloud servers, botnets, and container registries. Its approach to service disruption includes Endpoint DoS attacks to stall critical services while maintaining a foothold and exploiting compromised accounts for automated exfiltration via public-facing endpoints.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Media
Education
Telecommunications
Healthcare
Critical infrastructure
Information technology
Manufacturing
Retail
Transportation
Non profit
Hospitality
Energy
Mining
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction

Targeted Countries / Regions

CN
RU
KP
IN
UA
GB
DE
IR
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

UNC4536 (aliases FakeBat, EugenLoader/PaykLoader) is a financially motivated threat actor that distributes malware through elaborate malvertising and trojanized MSIX installers, targeting a wide range of sectors across the globe. The group leverages compromised email, cloud, and third‑party web service accounts for initial access, C2 communication, and exfiltration while implanting persistence mechanisms in cloud or container images. The actor exhibits a blend of stealthy supply‑chain manipulation and opportunistic infrastructure acquisition, exploiting remote services, software vulnerabilities, and Windows service permissions to embed malware and degrade availability with Endpoint DoS tactics.

Goals & Targeting

UNC4536’s strategic objectives focus on maximizing financial return through both ransomware deployments and data‑theft operations. The diverse sector coverage—from defense to retail—indicates an opportunistic targeting model that prioritizes compromise of high-value systems or supply chains rather than a narrow ideological mandate. Their infrastructure acquisition strategy, including botnet formation and cloud image manipulation, suggests a goal of achieving long‑term persistence while maintaining anonymity and mitigating attribution.

Enhanced Description

Key Capabilities

  • Distribute malware through fake software searches and malvertising campaigns (including trojanized MSIX installers)
  • Exploit compromised email, cloud, or third‑party web service accounts for initial access, C2, and exfiltration
  • Acquire infrastructure via purchase or compromise of cloud servers, container images, botnets
  • Conduct phishing with legitimate personas to gain credentials
  • Implant malicious code into cloud/container images for persistence
  • Hijack Windows service binaries using permission flaws
  • Exploit remote services and software vulnerabilities (including zero‑day) for internal access
  • Execute Endpoint DoS attacks to degrade critical services
  • Harvest sensitive data including credential dumping, clipboard capture, audio capture

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. unit42.paloaltonetworks.com — Cited by web research for: Royal Ransomware
  3. security.googlecloudcommunity.com — Cited by web research for: T1204.002
  4. attack.mitre.org — Cited by web research for: MSBuild

Intel Summary

40

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

13

Tactics

Tags

Critical Infrastructure
Backdoor / C2

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.