Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6619

Also known as: TGR-STA-1030, Shadow Campaigns, APT28, tracked as, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, CHAR, Olalampo, Storm-0842, Red Sandstorm, DUNE, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris

Description

UNC6619 is a high‑sophistication state‑backed actor whose footprint spans roughly 37 countries including Russia, Poland, Germany, the United States, China, India, and several European Union members. The group’s methodology blends social engineering (phishing emails that link to bogus video‑conferencing portals or embed malicious Office attachments) with exploitation of publicly available applications such as TrueConf and Microsoft Office zero‑days (CVE‑2026‑21509/13). After initial compromise the actor deploys a PowerShell‑based backdoor named PhantomHeart, which uses HTTP or SSH tunnels for command and control. Persistence is achieved via disguised scheduled‑task updates in the LiteManager directory, COM hijacking, and server‑side evasion that filters DLL delivery by geographic region and User–Agent headers. UNC6619 expands lateral reach through a mix of custom Remote Access Tools (e.g., AnyDesk) and SSH tunnels. Its operational toolbox also includes malicious DLL installers disguised as legitimate updates, steganographic payload carriers in Office macros and PNG images, RAR‑archived utilities such as Smart Install Maker and PUMAKIT kernel‑level rootkits, and destructive wiper commands that target user profile directories. The group uses Filen.io cloud storage not only for file delivery but also for encrypted C2 communication and exfiltration over SMTP. In addition to espionage, selected campaigns exhibit sabotage capabilities: deleting files, disabling native endpoint protection, and deploying ransomware variants such as LockBit. Strategically the group focuses on government ministries, critical‑infrastructure sectors (energy, telecommunications, transportation), defense supply chains, financial services, and technology vendors supporting emerging economies. Operations tend to combine long‑term persistence with opportunistic data exfiltration, often exploiting high‑value targets in the geopolitical context of Asia and Europe. Beyond UNC6619, analysts have linked related tool families—Behinder, Neo‑reGeorg, Godzilla, VShell—and cloud‑based components such as PRISMEX and various Prismex sub‑components. Though not all are exclusive to UNC6619, they appear consistently across related campaigns, indicating shared infrastructure or threat‑sharing among state‑aligned actors. Overall the actor exhibits an ability to adapt quickly to emerging zero‑days, leverage widely available cloud services for covert C2, and persist under the guise of legitimate software updates, thereby complicating detection and mitigation efforts.

Goals & Targeting

Targeted Sectors

Government
Critical infrastructure
Financial services
Energy
Defense
Manufacturing
Mining
Transportation
Education
Telecommunications
Construction
Aviation
Maritime
Healthcare
Aerospace
Non profit
Retail
Utilities
Chemical
Nuclear
Media
Hospitality
Pharmaceutical

Targeted Countries / Regions

RU
PL
DE
TW
US
BR
AE
CN
IT
GB
MX
KZ
UA
IL
IN
SA
NG
TR
RO
PK
SG
KR
VN
JP
BY
ES
NL

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

UNC6619, also known as TGR‑STA‑1030 or Shadow Campaigns, is a state‑aligned Asian cyberespionage group that has conducted operations against more than 150 countries. The actor relies on sophisticated spear‑phishing, exploitation of zero‑day vulnerabilities and cloud‑based command‑and‑control (e.g., Filen.io) to gain persistence for espionage and, in some instances, sabotage through destructive payloads.

Goals & Targeting

UNC6619’s primary objective is targeted cyberespionage aimed at collecting strategic information from governments, critical‑infrastructure operators, defense contractors, and financial institutions. The actor also demonstrates a dual capacity for sabotage—deploying destructive wiper payloads against user profiles—to disrupt operations or to signal geopolitical posturing. Target selection focuses disproportionately on nations with significant military or economic ties to the region of origin, but the scope remains global with a particular emphasis on Asia‑Pacific and European state‑affiliated entities. The strategic goals align with broader state interests: securing trade agreements, influencing political outcomes through intelligence gathering, undermining confidence in critical infrastructure, and coercing adversaries by damaging data integrity or availability.

Enhanced Description

Key Capabilities

  • deploy PowerShell-based backdoor (PhantomHeart) using HTTP/SSH C2
  • establish persistence via scheduled tasks disguised as legitimate update scripts in LiteManager
  • repurpose existing tools into custom scripts (e.g., PhantomProxyLite)
  • exploit TrueConf vulnerabilities BDU:2025-10114 and BDU:2025-10116 to replace client distributions
  • distribute malicious DLLs and PowerShell via spear‑phishing emails with video conference links
  • deliver malicious executable attachments and CAB/RAR archives containing utilities such as Smart Install Maker, WinRAR custom, MiniDoor
  • deploy remote management tools (AnyDesk)
  • disable Windows Defender through dedicated utility
  • exfiltrate data via SMTP using a custom exfiltration script
  • hide process windows with a hiding utility
  • recover passwords from email clients
  • perform server‑side evasion by delivering DLLs only for requests matching geographic region and User–Agent headers
  • exploit zero‑day MSHTML vulnerabilities CVE-2026-21509 and CVE-2026-21513 to bypass Office mitigations
  • use macro-enabled Excel dropper with steganographic image carriers
  • implement COM hijacking for persistence
  • utilise Filen.io cloud storage as encrypted C2 channel and data exfiltration surface
  • deploy destructive wiper commands deleting files in user profile directories

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 11 SHA-256 Hash 1 Domain 6 Filename 2

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. unit42.paloaltonetworks.com — Cited by web research for: Rootkit
  3. www.thaicert.or.th — Cited by web research for: eBPF Rootkit
  4. www.bleepingcomputer.com — Cited by web research for: Hospitality

Intel Summary

0

Techniques

41

Tools

0

Campaigns

49

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
Government Targeting
State-sponsored
Cyberespionage
Government targeting
Critical infrastructure

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.