Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC4487

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, ClickFix, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, fakeCAPTCHA

Description

UNC4487 is a relatively unknown but technologically adept threat actor that has been observed conducting multi‑stage attacks on a broad spectrum of sectors, including media, defense, finance, healthcare, energy, IT, manufacturing, gaming, and government. In March 2024 the group compromised a Ukrainian auto‑insurance portal used by officials for travel arrangements; this breach served as a conduit for installing the MATANBUCHUS ransomware that monetizes access to infected hosts. Subsequent investigations traced the same code signing certificate used across various releases of the ChillyHell macOS backdoor, confirming a single operational thread. Techniqueally, UNC4487 relies on a diverse arsenal: remote‑service exploitation and account hijacking for initial footholds; service binary replacement via improper permissions to raise privileges; and malicious copy‑and‑paste vectors (e.g., ClickFix/fakeCAPTCHA) to deliver payloads inside privileged sessions. The actor also routinely deploys cloud or container images—AWS AMIs, GCP images, Docker containers—to achieve stealth persistence and distribute its command-and-control components. Alongside these, it issues automated denial‑of‑service attacks by exhausting system resources or exploiting software weaknesses, creating a continuous impact on targeted environments. Financial gain remains the primary motivation: ransomware‑like payloads (MATANBUCHUS), data exfiltration for blackmail, and monetization through compromised cloud infrastructure. The group’s use of publicly available tools such as Havex RAT and FAKEUPDATES in conjunction with custom modules underscores a blend of off‑the‑shelf and in‑house development geared toward maximizing revenue while preserving operational resilience.

Goals & Targeting

Targeted Sectors

Media
Defense
Financial services
Healthcare
Energy
Information technology
Manufacturing
Gaming
Government

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 7 hours ago

Executive Summary

UNC4487 is a financially driven threat actor that has targeted high-value entities such as Ukrainian government officials and critical infrastructure. The group deploys sophisticated malware like MATANBUCHUS and ChillyHell, leveraging cloud infrastructure, service binary hijacking, and automated denial‑of‑service attacks to monetize compromised systems. Their operations indicate a blend of social engineering, lateral movement within networks, and persistent exploitation across multiple platforms.

Goals & Targeting

UNC4487 seeks to target valuable, high‑profile organizations across critical sectors—particularly those involved in government, defense, and financial services—to exploit their operational dependencies. By compromising portals that facilitate official travel or essential industry functions, the actor can maintain a persistent foothold. Their strategy is to monetize through ransomware, data exfiltration, and exploitation of cloud infrastructure, while maintaining diverse attack vectors such as social engineering, remote service exploitation, and denial‑of‑service operations.

Enhanced Description

Key Capabilities

  • Denial-of-service (DoS) via resource exhaustion or software vulnerabilities
  • Service binary hijacking through improper permissions
  • Account creation in email clients and cloud providers for phishing and infrastructure acquisition
  • Malicious copy-and-paste execution vectors (Paste & Run)
  • Weaponization of sector-specific file formats such as DICOM (.dcm)
  • Deployment of malicious cloud/VM or container images for persistence
  • HTTP user‑agent spoofing to blend with legitimate traffic
  • Remote services exploitation for lateral movement
  • Discovery through port, vulnerability, and wordlist scanning

MITRE ATT&CK Tactics

Impact
Initial Access
Lateral Movement
Persistence
Discovery
Execution

ATT&CK Techniques

T1037
T1515
T1557
T1583
T1613
T1123
T1547
T1119
T1115
T1530
T1071
T1010
T1560
T1185
T1580
T1217
T1092
T1595
T1548
T1087
T1059
T1020
T1609
T1584
T1612
T1586
T1619
T1554
T1098
T1110
T1531
T1027
T1671
T1197
T1650
T1651
T1134
T1526
T1204.004
T1538
T1105
T1499
T1021
T1136
T1074.003

Software / Tooling

Havex RAT
FAKEUPDATES
ChillyHell
ClickFix
fakeCAPTCHA

Campaigns & Victims

Campaigns appear to follow a predictable tempo: the actor first establishes footholds via compromised portals or phishing, then expands lateral movement internally using remote‑service exploitation. It exploits cloud resources by creating new accounts and deploying malicious VM/container images, allowing persistence across different jurisdictions. The pattern of repeated use of specific code signing certificates (e.g., for MATANBUCHUS) signals an attempt to evade certificate revocation checks and maintain operational continuity across multiple releases. Victims have ranged from Ukrainian government entities to high‑profile corporate infrastructure in media, defense, finance, healthcare, energy, IT, manufacturing, gaming, and other sectors.

IOC Patterns

  • Service binary hijacking via permission misuse
  • Denial-of-service through software vulnerability exploitation
  • Creation and use of email/cloud accounts for targeting
  • Malicious cloud/container image implants in registries
  • HTTP User-Agent header spoofing
  • Clipboard paste‑and‑run activity

Recommended Actions

  • Implement least privilege on services to prevent binary replacement
  • Enforce strict file permissions and integrity monitoring for critical binaries
  • Deploy rate limiting or resource quotas on endpoints to mitigate DoS attacks
  • Detect anomalous account creation patterns in cloud and email platforms; enforce MFA
  • Apply security patches promptly and maintain an up‑to‑date vulnerability management program
  • Validate and sign container/VM images before deployment; block untrusted registries
  • Monitor HTTP traffic for unexpected or spoofed User-Agent strings
  • Audit clipboard activity for paste‑and‑run exploits
  • Sanitize sector‑specific file formats (e.g., DICOM) to prevent embedded payloads

Suggested Tags

Denial of Service
Account Creation
Binary Hijacking
Remote Services Exploitation
Cloud Infrastructure Acquisition
RAT
FAKEUPDATES
ChillyHell
Persistent Cloud/Container Backdoor
Copy‑Paste Exploitation
DICOM Weaponization
User-Agent Spoofing
Port/Vulnerability Scanning

Confidence Assessment

The data shows a moderate to high confidence level in UNC4487’s capabilities and modus operandi based on corroborated malware analysis, technique mapping, and observed incidents. Confidence is lower regarding the full geographic scope and exact targeting criteria beyond Ukrainian government entities; additional intelligence would be required to confirm broader sector or national focus.

ATT&CK Techniques

Exfiltration
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. attack.mitre.org — Cited by web research for: ClickFix
  3. redcanary.com — Cited by web research for: SocGholish
  4. cloud.google.com — Cited by web research for: CVE-2020-14871
  5. https://www.jamf.com/blog/chillyhell-a-modular-macos-backdoor/ — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat — Cited by AI analysis.
  7. https://malpedia.caad.fkie.fraunhofer.de/details/js.fakeupdates — Cited by AI analysis.

Intel Summary

45

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Tags

Critical Infrastructure
Government Targeting
Denial of Service
Account Creation
Binary Hijacking
Remote Services Exploitation
Cloud Infrastructure Acquisition
RAT
FAKEUPDATES
ChillyHell
Persistent Cloud/Container Backdoor
Copy‑Paste Exploitation
DICOM Weaponization
User-Agent Spoofing
Port/Vulnerability Scanning

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.