Also known as: CryptoWaters, tracked as
suspected Russian espionage group.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6353 is suspected to be a Russian-linked advanced persistent threat (APT) group involved in espionage activities targeting government and defense sector organizations. The group likely employs sophisticated tactics, techniques, and procedures (TTPs) to infiltrate systems for data collection and potential sabotage.
Goals & Targeting
UNC6353 likely targets sectors that hold strategic value for Russian interests, such as government ministries, defense services, and intelligence agencies. The group's targeting strategy suggests a focus on information gathering that aligns with broader geopolitical goals. Their victims are often selected based on their access to sensitive data or their role in critical national infrastructure.
Enhanced Description
UNC6353 has been observed engaging in cyberespionage activities, likely with ties to Russian state-sponsored actors. The group's primary focus appears to be compromising sensitive information from government agencies, defense contractors, and other critical infrastructure entities. Their operations are characterized by strategic patience and precision, leveraging well-crafted phishing campaigns and custom malware to achieve their objectives. While specific details about their exact modus operandi are limited, the group is believed to have a high level of technical proficiency, consistent with state-sponsored capabilities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6353 has been active for several years, with campaigns observed targeting Eastern European and Western governments. Their operational tempo appears to be opportunistic, with peaks in activity tied to geopolitical events. Past operations have included compromising diplomatic communications and stealing sensitive policy documents.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is moderate confidence in the classification of UNC6353 as a Russian-linked APT group, based on their suspected origins and TTP comparisons. However, specific details about their exact capabilities and campaign history remain unclear due to limited公开 reporting.
No campaigns linked yet.
No observed data linked yet.
38
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics