Also known as: REvil, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, Mandiant researchers discovered
UNC2465 is a financially motivated threat actor known for orchestrating multi‑layered ransomware campaigns that combine the SMOKEDHAM .NET backdoor with the DARKSIDE ransomware engine. First identified by Mandiant through its activity in a supply‑chain compromise, the group has evolved from traditional drive‑by attacks to sophisticated Trojanized installer delivery and software supply‑chain exploitation aimed at high‑profile organizations. The actor routinely harvests credentials by dumping LSASS memory and uses remote‑access tools—UltraVNC, Cobalt Strike Beacon—to expand coverage after initial lateral movement. The use of NGROK for internal service exposure indicates a preference for fast, flexible tunnelling to maintain persistent footholds. UNC2465 also maintains an online leak site on the TOR network; when data exfiltrated during or after ransom operations is released, victims face heightened reputational damage and potential regulatory penalties. In addition to ransomware delivery, the actors engage in exfiltration over both standard web protocols and encrypted tunnels, frequently leveraging PowerShell, MSHTA, and Visual Basic scripts for command execution. Their techniques include keylogging, screen capture and obfuscated payloads that hide under legitimate processes, reinforcing their ability to remain covert within compromised networks. The group's operational pattern shows an emphasis on high‑value victims: financial services, healthcare, government, utilities, defense, media, manufacturing, and IT sectors. They adapt quickly to new detection capabilities by switching between supply‑chain compromise and phishing campaigns, making them a persistent threat in both infrastructure‑centric and end‑user environments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC2465 is a financially driven threat actor that primarily deploys the SMOKEDHAM .NET backdoor in conjunction with DARKSIDE ransomware to extort victims across a wide range of sectors, including finance, healthcare, and defense. The group exploits phishing, software supply‑chain attacks, and remote tunnelling (NGROK) to establish persistence, move laterally, and exfiltrate data via TOR leak sites. They target Russian entities but have also been observed affecting global organizations through both direct compromises and supply‑chain vectors, often leveraging popular remote‑access tools such as UltraVNC and Cobalt Strike BEACON.
Goals & Targeting
UNC2465 seeks monetary gain primarily through ransomware payment, but also leverages exfiltrated data for extortion, thereby increasing pressure on victims to pay. Their targeting breadth reflects an opportunistic strategy focused on organizations whose operations rely heavily on secure communications—finance, healthcare, defense—and that can afford the disruption caused by a ransomware or data‑leak incident. Geographically they have a Russian base of operation but actively target global entities, particularly those with exposed software supply chains. The group’s typical victim is an organization with complex internal environments where lateral movement tools (VNC, SSH) can be leveraged after gaining initial foothold via phishing or compromised installer delivery.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC2465’s campaigns typically begin with a spear‑phishing or supply‑chain delivery vector that installs the SMOKEDHAM backdoor, followed by the deployment of a ransomware engine (commonly DARKSIDE). The group maintains an online leak site on TOR to post exfiltrated data as a pressure tactic. Their operational tempo is adaptive; they pivot between direct compromises and software supply‑chain attacks depending on threat model changes. Victims are mainly large enterprises with interconnectivity to cloud or vendor services, making the actors’ use of cloud credentials exploitation and remote‑access tools decisive. Previous operations demonstrate a willingness to exploit Windows service weaknesses (e.g., overwriting binaries) to gain SYSTEM privileges, and they frequently use code signing for evasion. The persistence of known tooling like BEACON or UltraVNC in the attacker’s arsenal highlights their continued reliance on commercial RATs to sustain post‑exploitation activity.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information is largely derived from publicly available reports, including a Mandiant summary and Cyber Defense Magazine coverage. The alias list provided ("REvil") appears incongruent with known names for UNC2465; therefore that entry is treated as uncertain. While the core TTPs, toolset, and operational patterns are well supported, details such as first/last seen dates and some specific campaign identifiers remain unspecified or dated. The confidence in overall threat profile attributes (motivation, sector focus, and capabilities) is moderate to high based on corroborating sources. Further up‑to‑date IOC feeds would improve detail on active infrastructure.
No campaigns linked yet.
No observed data linked yet.
45
Techniques
46
Tools
0
Campaigns
45
IOCs
0
Observed Data
13
Tactics