Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, Memory Integrity, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, MiniDionis, Hammertoss, Chinastrats, Patchwork, UNC53, TEMP.Hex, hastalamuerte, buildx641
UNC3973 emerges from the broader BASTA ransomware ecosystem but showcases distinct operational traits that differentiate it as an autonomous or closely affiliated threat actor. The group targets a wide spectrum of industries—including finance, government, utilities, media, healthcare, and manufacturing—across more than thirty countries, with a pronounced focus on leveraging managed service providers (MSPs) to acquire shared domain‑administrator credentials. Initial access is frequently achieved through malvertising campaigns or phishing emails containing malicious attachments that deliver QAKBot and other dropper payloads. Once inside, UNC3973’s adversaries immediately pivot to privilege escalation and lateral movement using native Windows utilities. They employ WMI execution via Cobalt Strike beams, PsExec, and SMB (Windows Admin Shares) for rapid spread, while simultaneously attempting to disable endpoint protections. The adversary then deploys BASTA ransomware in mass‑mode and supplements it with custom malware families such as KNOTROCK (a utility used for data collection/exfiltration) and KNOTWRAP (a dropper/loader). Exfiltration is conducted through publicly accessible cloud storage solutions using the RCLONE command‑line tool, often accompanied by DNS‑based beaconing and system tunneling via SYSTEMBC. UNC3973’s methodology reflects a blend of opportunistic monetization—rapidly extracting value from compromised accounts—and strategic intelligence gathering. The group's documented “leave‑later‑attacking” behavior suggests the ability to preserve footholds for future exploitation, indicating sophisticated post‑exploitation survivability tactics.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC3973 is a financially‑motivated threat actor that exploits supply‑chain vectors—most notably compromised managed service providers—to gain privileged domain access and deploy ransomware. The group mixes classic malware (BASTA ransomware, KNOTROCK/KNOTWRAP) with living‑off‑the‑land techniques such as WMI, Windows Admin Shares and malvertising to move laterally and exfiltrate data via cloud tools like RCLONE. Organizations that rely on third‑party providers, especially in banking and insurance sectors, face a high risk of rapid compromise and monetary loss.
Goals & Targeting
Strategically, UNC3973 seeks both espionage and financial gain. By compromising privileged accounts in MSP environments, it gains broad reach across high‑value sectors globally, enabling data exfiltration and ransomware deployment. The actor’s emphasis on non‑sector specific coverage—yet pronounced focus on finance, government, defense, and telecommunications—reflects an intent to harvest sensitive intelligence while also monetizing compromised infrastructures quickly.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC3973’s hallmark campaigns exploit supply‑chain relationships with MSPs, exemplified by the June Canadian credit‑union breach that leveraged shared domain admin accounts. The group rapidly monetizes gained access—often within days—by deploying BASTA ransomware and custom utilities to exfiltrate data via RCLONE before encrypting targets or negotiating dual‑purpose extortion (ransom + intelligence). Their operational tempo is fast, focusing on high‑value but often poorly defended third‑party relationships. The actor has also demonstrated the ability to abandon failed ransom attempts yet persist in the environment for future attacks, indicating a sophisticated persistence strategy. Victim types span public sector, finance, healthcare, and telecommunications, with a geographic reach that includes North America, Europe, Asia, and the Middle East. Observed patterns reveal repeated use of malvertising, phishing attachments, and RDP/Windows Admin Shares for lateral movement. Notably, attempts to install both SYSTEMBC and BASTA were blocked in documented incidents by endpoint solutions, pointing to a need for layered defense against these vectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data regarding UNC3973’s tactics, techniques, and tools is corroborated by multiple incident reports and threat‑intel feeds, giving a high level of confidence in the presented operational profile. However, uncertainties remain concerning the exact lineage of the actor (its relationship to BASTA/UNC4393), precise dates for first and last sightings, and the full breadth of its financial motivations versus espionage objectives. Further correlation with additional case studies would strengthen attribution and help refine detection signatures.
No campaigns linked yet.
No observed data linked yet.
15
Techniques
62
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics