Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC3973

Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, Memory Integrity, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, MiniDionis, Hammertoss, Chinastrats, Patchwork, UNC53, TEMP.Hex, hastalamuerte, buildx641

Description

UNC3973 emerges from the broader BASTA ransomware ecosystem but showcases distinct operational traits that differentiate it as an autonomous or closely affiliated threat actor. The group targets a wide spectrum of industries—including finance, government, utilities, media, healthcare, and manufacturing—across more than thirty countries, with a pronounced focus on leveraging managed service providers (MSPs) to acquire shared domain‑administrator credentials. Initial access is frequently achieved through malvertising campaigns or phishing emails containing malicious attachments that deliver QAKBot and other dropper payloads. Once inside, UNC3973’s adversaries immediately pivot to privilege escalation and lateral movement using native Windows utilities. They employ WMI execution via Cobalt Strike beams, PsExec, and SMB (Windows Admin Shares) for rapid spread, while simultaneously attempting to disable endpoint protections. The adversary then deploys BASTA ransomware in mass‑mode and supplements it with custom malware families such as KNOTROCK (a utility used for data collection/exfiltration) and KNOTWRAP (a dropper/loader). Exfiltration is conducted through publicly accessible cloud storage solutions using the RCLONE command‑line tool, often accompanied by DNS‑based beaconing and system tunneling via SYSTEMBC. UNC3973’s methodology reflects a blend of opportunistic monetization—rapidly extracting value from compromised accounts—and strategic intelligence gathering. The group's documented “leave‑later‑attacking” behavior suggests the ability to preserve footholds for future exploitation, indicating sophisticated post‑exploitation survivability tactics.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Aerospace
Energy
Media
Education
Healthcare
Information technology
Manufacturing
Pharmaceutical
Maritime
Think tank
Chemical
Entertainment
Hospitality
Mining
Nuclear
Gaming
Legal services
Retail
Transportation
Construction
Food agriculture

Targeted Countries / Regions

US
CN
GB
IN
JP
KR
DE
RU
IR
SA
FR
CA
IL
TW
TR
PK
AU
KZ
UA
ES
PL
SG
VN
NL
BR
IT
BY
AE
IQ
MX
RO
SY
AZ
EG
LB

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

UNC3973 is a financially‑motivated threat actor that exploits supply‑chain vectors—most notably compromised managed service providers—to gain privileged domain access and deploy ransomware. The group mixes classic malware (BASTA ransomware, KNOTROCK/KNOTWRAP) with living‑off‑the‑land techniques such as WMI, Windows Admin Shares and malvertising to move laterally and exfiltrate data via cloud tools like RCLONE. Organizations that rely on third‑party providers, especially in banking and insurance sectors, face a high risk of rapid compromise and monetary loss.

Goals & Targeting

Strategically, UNC3973 seeks both espionage and financial gain. By compromising privileged accounts in MSP environments, it gains broad reach across high‑value sectors globally, enabling data exfiltration and ransomware deployment. The actor’s emphasis on non‑sector specific coverage—yet pronounced focus on finance, government, defense, and telecommunications—reflects an intent to harvest sensitive intelligence while also monetizing compromised infrastructures quickly.

Enhanced Description

Key Capabilities

  • malvertising initial access
  • living‑off‑the‑land lateral movement via native Windows utilities
  • open‑source reconnaissance (Bloodhound, ADFIND, PSNMAP, COGSCAN) for network mapping and privilege escalation
  • WMI execution via Cobalt Strike to deploy ransomware en‑mass
  • bypassing AV with certutil payload downloads
  • data exfiltration to cloud (RCLONE)
  • deployment of BASTA ransomware and custom malware KNOTROCK/KNOTWRAP
  • abandoning failed ransom attempts for later re‑attack
  • phishing via malicious email attachments
  • commercial RAT (Cobalt Strike BEACON) deployment
  • PsExec and Windows Admin Shares lateral movement
  • tunneling via SYSTEMBC

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Lateral Movement
Exfiltration
Impact
Persistence
Credential Access
Collection
Command and Control

ATT&CK Techniques

T1189
T1047
T1076
T1105
T1530
T1486
T1018
T1566.001
T1078.002
T1110.004
T1063
T1021.004
T1090
T1041
T1059.003

Software / Tooling

Bloodhound
ADFIND
PSNMAP
COGSCAN
SMB Beacon
RDP
WMI (Cobalt Strike)
certutil
RCLONE
BASTA ransomware
KNOTROCK
malvertising ad delivery
QAKBOT
Cobalt Strike BEACON
SYSTEMBC tunneler
PsExec
KNOTWRAP
PORTYARD
POWERSPLOIT
POWERVIEW
DARKGATE
UNC2500

Campaigns & Victims

UNC3973’s hallmark campaigns exploit supply‑chain relationships with MSPs, exemplified by the June Canadian credit‑union breach that leveraged shared domain admin accounts. The group rapidly monetizes gained access—often within days—by deploying BASTA ransomware and custom utilities to exfiltrate data via RCLONE before encrypting targets or negotiating dual‑purpose extortion (ransom + intelligence). Their operational tempo is fast, focusing on high‑value but often poorly defended third‑party relationships. The actor has also demonstrated the ability to abandon failed ransom attempts yet persist in the environment for future attacks, indicating a sophisticated persistence strategy. Victim types span public sector, finance, healthcare, and telecommunications, with a geographic reach that includes North America, Europe, Asia, and the Middle East. Observed patterns reveal repeated use of malvertising, phishing attachments, and RDP/Windows Admin Shares for lateral movement. Notably, attempts to install both SYSTEMBC and BASTA were blocked in documented incidents by endpoint solutions, pointing to a need for layered defense against these vectors.

IOC Patterns

  • malicious email attachments delivering QAKBOT
  • DNS beacon domains used for C2
  • PsExec usage for lateral movement
  • Windows Admin Shares exploitation
  • RCLONE exfiltration tool activity
  • KNOTWRAP dropper signatures
  • KNOTROCK utility markers
  • malvertising ad delivery

Recommended Actions

  • Implement web filtering and malvertising detection to block malicious advertisements.
  • Restrict or monitor RDP usage and SMB Windows Admin Shares to prevent lateral movement via Beacon/WMI.
  • Block WMI execution from unverified binaries such as Cobalt Strike.
  • Configure endpoint protection to detect certutil‑based payload downloads.
  • Monitor for unfamiliar RCLONE processes; restrict outbound cloud storage traffic unless explicitly required. Deploy signature/behavioral detection for BASTA ransomware, KNOTROCK/KNOTWRAP utilities.
  • Maintain up‑to‑date patching of Windows systems to close known vulnerabilities exploitable via WMI or SMB. Block phishing emails with malicious attachments; enable attachment sandboxing and content filtering. Enforce MFA on privileged accounts and enforce least privilege for domain admins. Deploy DNS monitoring for tunneling activity, especially domains associated with SYSTEMBC. Restrict use of PsExec and Windows Admin Shares through group policy and monitor usage logs.],

Suggested Tags

UNC3973
ransomware
malvertising
cloud exfiltration
WMI
RDP
SMB Beacon
living-off-the-land
custom malware
BASTA
KNOTROCK
phishing
credential theft
lateral movement
exfiltration
dns tunneling
Cobalt Strike
Qakbot
APT28
supply chain compromise

Confidence Assessment

The data regarding UNC3973’s tactics, techniques, and tools is corroborated by multiple incident reports and threat‑intel feeds, giving a high level of confidence in the presented operational profile. However, uncertainties remain concerning the exact lineage of the actor (its relationship to BASTA/UNC4393), precise dates for first and last sightings, and the full breadth of its financial motivations versus espionage objectives. Further correlation with additional case studies would strengthen attribution and help refine detection signatures.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. www.f5.com — Cited by web research for: hastalamuerte
  3. cloud.google.com — Cited by web research for: Global
  4. chintangurjar.com — Cited by web research for: Gaming
  5. https://www.mandiant.com — Cited by AI analysis.
  6. https://www.cybereason.com — Cited by AI analysis.

Intel Summary

15

Techniques

62

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

Ransomware
Critical Infrastructure
Supply Chain Attack
Backdoor / C2
APT
ransomware
finance-sector
supply-chain-attack
UNC3973
malvertising
cloud exfiltration
WMI
RDP
SMB Beacon
living-off-the-land
custom malware
BASTA
KNOTROCK
phishing
credential theft
lateral movement
exfiltration
dns tunneling
Cobalt Strike
Qakbot
APT28
supply chain compromise

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.