Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC2465

Also known as: REvil, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, Mandiant researchers discovered

Description

UNC2465 is a financially motivated threat actor known for orchestrating multi‑layered ransomware campaigns that combine the SMOKEDHAM .NET backdoor with the DARKSIDE ransomware engine. First identified by Mandiant through its activity in a supply‑chain compromise, the group has evolved from traditional drive‑by attacks to sophisticated Trojanized installer delivery and software supply‑chain exploitation aimed at high‑profile organizations. The actor routinely harvests credentials by dumping LSASS memory and uses remote‑access tools—UltraVNC, Cobalt Strike Beacon—to expand coverage after initial lateral movement. The use of NGROK for internal service exposure indicates a preference for fast, flexible tunnelling to maintain persistent footholds. UNC2465 also maintains an online leak site on the TOR network; when data exfiltrated during or after ransom operations is released, victims face heightened reputational damage and potential regulatory penalties. In addition to ransomware delivery, the actors engage in exfiltration over both standard web protocols and encrypted tunnels, frequently leveraging PowerShell, MSHTA, and Visual Basic scripts for command execution. Their techniques include keylogging, screen capture and obfuscated payloads that hide under legitimate processes, reinforcing their ability to remain covert within compromised networks. The group's operational pattern shows an emphasis on high‑value victims: financial services, healthcare, government, utilities, defense, media, manufacturing, and IT sectors. They adapt quickly to new detection capabilities by switching between supply‑chain compromise and phishing campaigns, making them a persistent threat in both infrastructure‑centric and end‑user environments.

Goals & Targeting

Targeted Sectors

Financial services
Media
Defense
Utilities
Healthcare
Government
Manufacturing
Information technology

Targeted Countries / Regions

RU

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

UNC2465 is a financially driven threat actor that primarily deploys the SMOKEDHAM .NET backdoor in conjunction with DARKSIDE ransomware to extort victims across a wide range of sectors, including finance, healthcare, and defense. The group exploits phishing, software supply‑chain attacks, and remote tunnelling (NGROK) to establish persistence, move laterally, and exfiltrate data via TOR leak sites. They target Russian entities but have also been observed affecting global organizations through both direct compromises and supply‑chain vectors, often leveraging popular remote‑access tools such as UltraVNC and Cobalt Strike BEACON.

Goals & Targeting

UNC2465 seeks monetary gain primarily through ransomware payment, but also leverages exfiltrated data for extortion, thereby increasing pressure on victims to pay. Their targeting breadth reflects an opportunistic strategy focused on organizations whose operations rely heavily on secure communications—finance, healthcare, defense—and that can afford the disruption caused by a ransomware or data‑leak incident. Geographically they have a Russian base of operation but actively target global entities, particularly those with exposed software supply chains. The group’s typical victim is an organization with complex internal environments where lateral movement tools (VNC, SSH) can be leveraged after gaining initial foothold via phishing or compromised installer delivery.

Enhanced Description

Key Capabilities

  • Advanced phishing campaigns
  • Trojanized and supply‑chain attack delivery

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command And Control
Impact

ATT&CK Techniques

T1566.001
T1190
T1053.005
T1059.009
T1204
T1071.001
T1553.002
T1572
T1525
T1547.009
T1105
T1082
T1033
T1049
T1112

Software / Tooling

SMOKEDHAM backdoor
DARKSIDE ransomware
Qilin ransomware
NGROK tunnelling
UltraVNC
Cobalt Strike BEACON
MSHTA
PowerShell scripts
PsExec
RClone
LockBit

Campaigns & Victims

UNC2465’s campaigns typically begin with a spear‑phishing or supply‑chain delivery vector that installs the SMOKEDHAM backdoor, followed by the deployment of a ransomware engine (commonly DARKSIDE). The group maintains an online leak site on TOR to post exfiltrated data as a pressure tactic. Their operational tempo is adaptive; they pivot between direct compromises and software supply‑chain attacks depending on threat model changes. Victims are mainly large enterprises with interconnectivity to cloud or vendor services, making the actors’ use of cloud credentials exploitation and remote‑access tools decisive. Previous operations demonstrate a willingness to exploit Windows service weaknesses (e.g., overwriting binaries) to gain SYSTEM privileges, and they frequently use code signing for evasion. The persistence of known tooling like BEACON or UltraVNC in the attacker’s arsenal highlights their continued reliance on commercial RATs to sustain post‑exploitation activity.

IOC Patterns

  • Spear‑phishing with macro‑laced Office documents
  • Trojanized software installer delivery via supply chain compromise
  • Use of NGROK for C2 tunnelling
  • LSASS memory dump for credential harvesting
  • TOR-based leak site exfiltration and extortion

Recommended Actions

  • Implement multi‑factor authentication across all accounts, especially for service and cloud provider access. Deploy endpoint detection & response solutions that specifically flag PowerShell, MSHTA, UltraVNC and other RATs, including malicious process injection tactics. Enforce strict software whitelisting or code signing verification; block unapproved installers and detect tampered binaries. Monitor for anomalous use of VPN, SSH, VNC, and ngrok tunnelling on corporate networks and apply stricter controls or blocking. Educate users about spear‑phishing indicators and conduct regular simulated phishing exercises. Implement network segmentation to restrict lateral movement and employ host‑based firewalls with mandatory access control. Maintain updated signatures for SMOKEDHAM backdoor binaries and DARKSIDE ransomware variants in AV feeds. Set up incident response plans that include immediate isolation of infected hosts and containment of data exfiltration via TOR networks.

Suggested Tags

APT
Cybercrime
Ransomware
Supply‑Chain Attack
Exfiltration
Extortion
Financial Gain
Finance sector
Healthcare sector
Defense sector

Confidence Assessment

The information is largely derived from publicly available reports, including a Mandiant summary and Cyber Defense Magazine coverage. The alias list provided ("REvil") appears incongruent with known names for UNC2465; therefore that entry is treated as uncertain. While the core TTPs, toolset, and operational patterns are well supported, details such as first/last seen dates and some specific campaign identifiers remain unspecified or dated. The confidence in overall threat profile attributes (motivation, sector focus, and capabilities) is moderate to high based on corroborating sources. Further up‑to‑date IOC feeds would improve detail on active infrastructure.

ATT&CK Techniques

Credential Access
1 technique
Lateral Movement
2 techniques
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 MD5 Hash 3 Filename 6 URL 1

References

  1. cloud.google.com — Cited by web research for: REvil
  2. attack.mitre.org — Cited by web research for: services
  3. www.cyberdefensemagazine.com — Cited by web research for: Mandiant researchers discovered
  4. attack.mitre.org — Cited by web research for: Interception
  5. cloud.google.com — Cited by web research for: Ransomware payload
  6. https://support.mandiant.com/hc/en-us/articles/360048722073 — Cited by AI analysis.

Intel Summary

45

Techniques

46

Tools

0

Campaigns

45

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Critical Infrastructure
Supply Chain Attack
Phishing
Backdoor / C2
Data Exfiltration
APT group
Cyber extortion
Financial sector targeted
Energy sector targeted
Cobalt Strike
APT
Cybercrime
Supply‑Chain Attack
Exfiltration
Extortion
Financial Gain
Finance sector
Healthcare sector
Defense sector

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.