Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, ClickFix, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, fakeCAPTCHA
UNC4487 is a relatively unknown but technologically adept threat actor that has been observed conducting multi‑stage attacks on a broad spectrum of sectors, including media, defense, finance, healthcare, energy, IT, manufacturing, gaming, and government. In March 2024 the group compromised a Ukrainian auto‑insurance portal used by officials for travel arrangements; this breach served as a conduit for installing the MATANBUCHUS ransomware that monetizes access to infected hosts. Subsequent investigations traced the same code signing certificate used across various releases of the ChillyHell macOS backdoor, confirming a single operational thread. Techniqueally, UNC4487 relies on a diverse arsenal: remote‑service exploitation and account hijacking for initial footholds; service binary replacement via improper permissions to raise privileges; and malicious copy‑and‑paste vectors (e.g., ClickFix/fakeCAPTCHA) to deliver payloads inside privileged sessions. The actor also routinely deploys cloud or container images—AWS AMIs, GCP images, Docker containers—to achieve stealth persistence and distribute its command-and-control components. Alongside these, it issues automated denial‑of‑service attacks by exhausting system resources or exploiting software weaknesses, creating a continuous impact on targeted environments. Financial gain remains the primary motivation: ransomware‑like payloads (MATANBUCHUS), data exfiltration for blackmail, and monetization through compromised cloud infrastructure. The group’s use of publicly available tools such as Havex RAT and FAKEUPDATES in conjunction with custom modules underscores a blend of off‑the‑shelf and in‑house development geared toward maximizing revenue while preserving operational resilience.
Targeted Sectors
Executive Summary
UNC4487 is a financially driven threat actor that has targeted high-value entities such as Ukrainian government officials and critical infrastructure. The group deploys sophisticated malware like MATANBUCHUS and ChillyHell, leveraging cloud infrastructure, service binary hijacking, and automated denial‑of‑service attacks to monetize compromised systems. Their operations indicate a blend of social engineering, lateral movement within networks, and persistent exploitation across multiple platforms.
Goals & Targeting
UNC4487 seeks to target valuable, high‑profile organizations across critical sectors—particularly those involved in government, defense, and financial services—to exploit their operational dependencies. By compromising portals that facilitate official travel or essential industry functions, the actor can maintain a persistent foothold. Their strategy is to monetize through ransomware, data exfiltration, and exploitation of cloud infrastructure, while maintaining diverse attack vectors such as social engineering, remote service exploitation, and denial‑of‑service operations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaigns appear to follow a predictable tempo: the actor first establishes footholds via compromised portals or phishing, then expands lateral movement internally using remote‑service exploitation. It exploits cloud resources by creating new accounts and deploying malicious VM/container images, allowing persistence across different jurisdictions. The pattern of repeated use of specific code signing certificates (e.g., for MATANBUCHUS) signals an attempt to evade certificate revocation checks and maintain operational continuity across multiple releases. Victims have ranged from Ukrainian government entities to high‑profile corporate infrastructure in media, defense, finance, healthcare, energy, IT, manufacturing, gaming, and other sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data shows a moderate to high confidence level in UNC4487’s capabilities and modus operandi based on corroborated malware analysis, technique mapping, and observed incidents. Confidence is lower regarding the full geographic scope and exact targeting criteria beyond Ukrainian government entities; additional intelligence would be required to confirm broader sector or national focus.
No campaigns linked yet.
No observed data linked yet.
45
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
14
Tactics