Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6293

Also known as: tracked as, Synaptics worm, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

UNC6293 is identified by Google Threat Intelligence Group (GTIG) as a Russian government‑linked adversary with low-confidence linkage to APT29. Their primary motivation is financial gain, and they have conducted multiple campaigns using social engineering—particularly ASP‑based phishing—to target academics, critics, and organizations in defense, media, education, financial services, government, and IT realms. The actor exploits application‑specific passwords to bypass multi‑factor authentication, and abuses cloud permission configurations (just‑in‑time role requests) to achieve temporary elevated privileges. In addition to credential theft and privilege escalation, UNC6293 acquires or shares access through initial‑access broker networks and uses rented or compromised infrastructure in services such as Dropbox, AWS, Microsoft OneDrive, Google Workspace, and GitHub for hosting malicious payloads. They also embed malicious code into cloud or container images for persistence and leverage common web platforms (e.g., Google, Twitter) for command‑and‑control channels. Their malware is highly polymorphic, employing code obfuscation, encryption, packing, and runtime mutation to avoid signature‑based detection. The actor demonstrates capabilities across the attack lifecycle: initial access via phishing and app‑specific passwords; credential theft through password store extraction and MFA bypass; privilege escalation using cloud configuration abuse; persistence by creating local/domain accounts and hijacking service binaries; lateral movement via compromised remote access tools; impact through DoS attacks on DNS and web services; and exfiltration over encrypted tunnels or popular cloud storage. UNC6293 has operated in at least two distinct campaigns—one heavily themed around Ukrainian events—underscoring their opportunistic approach.

Goals & Targeting

Targeted Sectors

Defense
Media
Education
Financial services
Government
Information technology

Targeted Countries / Regions

RU
US
AU

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 16 hours ago

Executive Summary

UNC6293 is a Russian state‑linked threat actor focused on financial gain, employing sophisticated phishing and cloud privilege abuse tactics against defense, media, education, financial services, government, and IT sectors in the US, RU, and AU. They frequently leverage app‑specific passwords to bypass MFA, use compromised or rented infrastructure for command and control via popular web services, and deploy polymorphic code that evades traditional detection. The actor also conducts denial‑of‑service attacks against DNS/web/email services, further disrupting targets.

Goals & Targeting

UNC6293’s strategic objectives revolve around monetization through data exfiltration, credential theft, and service disruption that can be sold or leveraged for ransom. The actor targets high‑profile sectors (defense, media, education) and governments in the US, RU, and AU, often selecting victims with well‑exposed cloud environments or publicly accessible application interfaces. Their targeting profile favors organizations or individuals who may be susceptible to phishing (e.g., academia, critics of the Russian regime) and those whose credentials can unlock valuable data or grant privileged access.

Enhanced Description

Key Capabilities

  • Phishing campaigns using ASP lure themes
  • Exploitation of app‑specific passwords to bypass MFA
  • Privilege escalation via cloud permission misconfiguration and just‑in‑time role abuse
  • Acquisition or sharing of compromised infrastructure through initial‑access broker networks
  • Use of rented or leased cloud resources for command-and-control and exfiltration channels
  • Compromise and abuse existing user accounts (email, cloud) for phishing/spam campaigns
  • Creation of local and domain accounts on victim systems to maintain persistence
  • Hijacking or replacing Windows service binaries via permission misuse
  • Implantation of malicious code in cloud or container images for persistence
  • Execution of network denial‑of‑service attacks against DNS, web services, and email
  • Polymorphic/mutating code with obfuscation and packing techniques
  • Port scanning, vulnerability discovery, and wordlist scanning for reconnaissance

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Impact
Exfiltration
Command And Control

ATT&CK Techniques

T1037
T1557
T1583
T1613
T1123
T1543
T1547
T1119
T1115
T1071
T1555
T1659
T1010
T1560
T1185
T1580
T1217
T1092
T1595
T1548
T1087
T1059
T1020
T1609
T1584
T1612
T1586
T1619
T1554
T1098
T1110
T1531
T1671
T1197
T1650
T1651
T1134
T1136
T1526
T1538

Software / Tooling

Conti
MailSniper

Campaigns & Victims

UNC6293 operates multiple overlapping campaigns that frequently use ASP-coded phishing emails targeting academics and critics, exploiting app‑specific passwords to gain MFA bypass. The actor routinely leverages cloud privileges (just‑in‑time roles) for temporary escalation, then drops or expands persistence via local/domain accounts and service hijackings. Early reconnaissance includes port and vulnerability scans as well as wordlist attacks on potential credential stores. In later stages the group may launch denial‑of‑service pulses against DNS and web services to disrupt targets. Their use of third‑party platforms like Google Workspace, GitHub, and Twitter for C&C makes attribution challenging, while their polymorphic payloads reduce the effectiveness of signature‑based defenses.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 3 IPv4 Address 1 Filename 9 SHA-256 Hash 7

References

  1. attack.mitre.org — Cited by web research for: services
  2. cloud.google.com — Cited by web research for: XWorm
  3. attack.mitre.org — Cited by web research for: Process Hollowing
  4. cloud.google.com — Cited by web research for: Government

Intel Summary

40

Techniques

43

Tools

0

Campaigns

38

IOCs

0

Observed Data

13

Tactics

Tags

APT
Critical Infrastructure
State-Sponsored
Espionage

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.