Also known as: tracked as, Synaptics worm, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
UNC6293 is identified by Google Threat Intelligence Group (GTIG) as a Russian government‑linked adversary with low-confidence linkage to APT29. Their primary motivation is financial gain, and they have conducted multiple campaigns using social engineering—particularly ASP‑based phishing—to target academics, critics, and organizations in defense, media, education, financial services, government, and IT realms. The actor exploits application‑specific passwords to bypass multi‑factor authentication, and abuses cloud permission configurations (just‑in‑time role requests) to achieve temporary elevated privileges. In addition to credential theft and privilege escalation, UNC6293 acquires or shares access through initial‑access broker networks and uses rented or compromised infrastructure in services such as Dropbox, AWS, Microsoft OneDrive, Google Workspace, and GitHub for hosting malicious payloads. They also embed malicious code into cloud or container images for persistence and leverage common web platforms (e.g., Google, Twitter) for command‑and‑control channels. Their malware is highly polymorphic, employing code obfuscation, encryption, packing, and runtime mutation to avoid signature‑based detection. The actor demonstrates capabilities across the attack lifecycle: initial access via phishing and app‑specific passwords; credential theft through password store extraction and MFA bypass; privilege escalation using cloud configuration abuse; persistence by creating local/domain accounts and hijacking service binaries; lateral movement via compromised remote access tools; impact through DoS attacks on DNS and web services; and exfiltration over encrypted tunnels or popular cloud storage. UNC6293 has operated in at least two distinct campaigns—one heavily themed around Ukrainian events—underscoring their opportunistic approach.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6293 is a Russian state‑linked threat actor focused on financial gain, employing sophisticated phishing and cloud privilege abuse tactics against defense, media, education, financial services, government, and IT sectors in the US, RU, and AU. They frequently leverage app‑specific passwords to bypass MFA, use compromised or rented infrastructure for command and control via popular web services, and deploy polymorphic code that evades traditional detection. The actor also conducts denial‑of‑service attacks against DNS/web/email services, further disrupting targets.
Goals & Targeting
UNC6293’s strategic objectives revolve around monetization through data exfiltration, credential theft, and service disruption that can be sold or leveraged for ransom. The actor targets high‑profile sectors (defense, media, education) and governments in the US, RU, and AU, often selecting victims with well‑exposed cloud environments or publicly accessible application interfaces. Their targeting profile favors organizations or individuals who may be susceptible to phishing (e.g., academia, critics of the Russian regime) and those whose credentials can unlock valuable data or grant privileged access.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6293 operates multiple overlapping campaigns that frequently use ASP-coded phishing emails targeting academics and critics, exploiting app‑specific passwords to gain MFA bypass. The actor routinely leverages cloud privileges (just‑in‑time roles) for temporary escalation, then drops or expands persistence via local/domain accounts and service hijackings. Early reconnaissance includes port and vulnerability scans as well as wordlist attacks on potential credential stores. In later stages the group may launch denial‑of‑service pulses against DNS and web services to disrupt targets. Their use of third‑party platforms like Google Workspace, GitHub, and Twitter for C&C makes attribution challenging, while their polymorphic payloads reduce the effectiveness of signature‑based defenses.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
43
Tools
0
Campaigns
38
IOCs
0
Observed Data
13
Tactics