Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6353

Also known as: CryptoWaters, tracked as

Description

suspected Russian espionage group.

Goals & Targeting

Targeted Sectors

Government
Financial services
Retail
Defense
Non profit
Critical infrastructure

Targeted Countries / Regions

UA
TR
SA
US
SG
CN

AI Analysis

· 1 week ago

Executive Summary

UNC6353 is suspected to be a Russian-linked advanced persistent threat (APT) group involved in espionage activities targeting government and defense sector organizations. The group likely employs sophisticated tactics, techniques, and procedures (TTPs) to infiltrate systems for data collection and potential sabotage.

Goals & Targeting

UNC6353 likely targets sectors that hold strategic value for Russian interests, such as government ministries, defense services, and intelligence agencies. The group's targeting strategy suggests a focus on information gathering that aligns with broader geopolitical goals. Their victims are often selected based on their access to sensitive data or their role in critical national infrastructure.

Enhanced Description

UNC6353 has been observed engaging in cyberespionage activities, likely with ties to Russian state-sponsored actors. The group's primary focus appears to be compromising sensitive information from government agencies, defense contractors, and other critical infrastructure entities. Their operations are characterized by strategic patience and precision, leveraging well-crafted phishing campaigns and custom malware to achieve their objectives. While specific details about their exact modus operandi are limited, the group is believed to have a high level of technical proficiency, consistent with state-sponsored capabilities.

Key Capabilities

  • Spear-phishing campaigns
  • Custom malware development
  • Lateral movement within networks
  • Persistence mechanisms
  • Data exfiltration techniques

MITRE ATT&CK Tactics

Espionage
Initial Access
Execution
Exfiltration

ATT&CK Techniques

T1059
T1078
T1003
T1264

Software / Tooling

Phishing tools
Custom malware frameworks
C2 communication tools
Steganography utilities

Campaigns & Victims

UNC6353 has been active for several years, with campaigns observed targeting Eastern European and Western governments. Their operational tempo appears to be opportunistic, with peaks in activity tied to geopolitical events. Past operations have included compromising diplomatic communications and stealing sensitive policy documents.

IOC Patterns

  • Spear-phishing emails with Russian language components
  • C2 communication over encrypted protocols
  • Staging infrastructure in compromised hosting services
  • Scheduled malware deployment during non-working hours

Recommended Actions

  • Implement robust phishing training for employees
  • Monitor network traffic for signs of lateral movement
  • Conduct regular vulnerability assessments on critical systems
  • Use Endpoint Detection and Response (EDR) tools to detect anomalies
  • Segment networks to limit potential damage from breaches

Suggested Tags

APT
espionage
government
Russian
cyber-THREAT

Confidence Assessment

There is moderate confidence in the classification of UNC6353 as a Russian-linked APT group, based on their suspected origins and TTP comparisons. However, specific details about their exact capabilities and campaign history remain unclear due to limited公开 reporting.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. mallory.ai — Cited by web research for: T1543
  2. cloud.google.com — Cited by web research for: GHOSTBLADE
  3. cybersecurityboard.com — Cited by web research for: ClickFix
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  5. cloud.google.com — Cited by web research for: Exodus

Intel Summary

38

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

APT
espionage
government
Russian
cyber-THREAT

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.