Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6426

Also known as: tracked as, Aug 5, which focused on CI, CD identities, CVE-2026-40175, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, APT-C-17, Baby Elephant, Hardcore Nationalist, Leafperforator, Rattlesnake, Razor, Playcrypt, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, SideWinder, T-APT-04, India

Description

UNC6426 is a financially motivated adversary that targets cloud‑centric infrastructures, particularly focusing on CI/CD pipelines and identity federation configurations. The group first compromised an npm package, enabling it to inject malicious code into developer workflows and steal a GitHub Personal Access Token. By abusing the GitHub‑to‑AWS OpenID Connect trust chain, UNC6426 was able to create a new administrative IAM role with overly permissive permissions tied to the GitHub‑Actions‑CloudFormation role. Within 72 hours of initial compromise, the actor had full AWS administrator privileges. Leveraging the legitimate open‑source tool Nord Stream for reconnaissance, UNC6426 harvested secrets from CI/CD environments and exfiltrated files from AWS S3 buckets while also conducting data destruction operations against victim cloud resources. Their tactics include exploiting multiple public CVEs—Vulnerabilities such as FortiOS SSL VPN (CVE‑2022‑42475), Junos OS veriexec bypass (CVE‑2025‑21590), VMware vCenter credential theft (CVE‑2022‑22948)—and utilizing a zero‑day exploit (CVE‑2023‑20867) to execute commands across Windows, Linux, and PhotonOS VMs. The actor demonstrates sophisticated cloud persistence methods by implanting malicious AMIs or container images and hijacking services through binary replacement. They also generate disposable email accounts for phishing campaigns, spoof browser and system attributes, bypass multi‑factor authentication, and launch Network DoS attacks as a distraction or disruption technique.

Goals & Targeting

Targeted Sectors

Defense
Media
Financial services
Telecommunications
Government
Non profit
Manufacturing
Energy
Information technology

Targeted Countries / Regions

CN
US
IR
IL
SA
SG
JP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

UNC6426 exploits supply‑chain vulnerabilities in npm packages to seize AWS administrative control, leveraging compromised GitHub identities and OpenID Connect trust. The actor then extracts secrets from CI/CD environments, exfiltrates data from S3 buckets, and can destroy files within 72 hours. Rapid escalation of privilege and use of cloud persistence mechanisms make the threat highly disruptive for target organizations.

Goals & Targeting

UNC6426’s strategic objectives focus on financial gain through the theft of cloud credentials, data exfiltration, and asset destruction. By targeting CI/CD identities—particularly those with elevated privileges—and exploiting supply chain pathways, the actor can rapidly ascend to top‑level access within cloud environments. Their selection of sectors (defense, media, finance, telecoms) reflects a preference for organizations that rely heavily on cloud automation pipelines, while their geographic focus spans key technology hubs in CN, US, IR, IL, SA, SG, and JP.

Enhanced Description

Key Capabilities

  • Exploits npm supply‑chain to gain AWS administrative access
  • Creates and uses cloud provider accounts for infrastructure acquisition
  • Hijacks services by replacing binary executables to achieve privilege escalation
  • Implants malicious container images or AMIs for persistence
  • Generates email accounts for phishing and operational use
  • Spoofs browser and system attributes (User‑Agent, OS string)
  • Intercepts and bypasses multi‑factor authentication mechanisms
  • Conducts Network Denial‑of‑Service attacks to disrupt services
  • Exploits CVE‑2022‑42475 in FortiOS SSL VPNs to gain access
  • Exploits CVE‑2025‑21590 in Junos OS to bypass veriexec and inject code
  • Exploits CVE‑2022‑22948 in VMware vCenter to retrieve encrypted credentials from the Postgres database
  • Uses zero‑day CVE‑2023‑20867 to execute privileged commands across Windows, Linux, PhotonOS VMs
  • Abuses GitHub‑to‑AWS OpenID Connect trust to create new administrator role
  • Uses Nord Stream open‑source tool for reconnaissance and secret extraction in CI/CD environments
  • Exfiltrates data from AWS S3 buckets and destroys files within 72 hours

MITRE ATT&CK Tactics

Initial Access
Credential Access
Persistence
Exfiltration
Defense Evasion
Impact
Privilege Escalation

ATT&CK Techniques

T1037
T1557
T1583
T1003
T1564
T1675
T1040
T1140
T1555
T1560
T1595
T1548
T1087
T1059
T1070
T1083
T1104
T1041
T1554
T1212
T1098
T1571
T1068
T1531
T1027
T1573
T1685
T1203
T1570
T1095
T1588
T1650
T1134
T1105
T1587
T1686
T1008
T1195.002
T1136.003
T1074.004
T1036.003
T1499
T1190

Software / Tooling

Nord Stream
GitHub Actions
AWS IAM/Role Manipulation
CVE-2023-20867 Zero-Day Exploit

Campaigns & Victims

UNC6426 operates primarily through cloud supply‑chain attacks and identity federation exploitation, rapidly escalating from initial foothold to administrator control, typically within 72 hours. Victims are predominantly organizations operating heavy CI/CD pipelines in defense, media, finance, and telecom sectors across multiple regions. The adversary’s modus operandi involves subtle lateral movement via hijacked binaries, stealthy data staging in cloud buckets, and opportunistic DoS attacks on critical services to distract or force manual intervention.

IOC Patterns

  • NPM package URL patterns
  • Cloud provider account creation patterns
  • Docker image repository paths
  • AWS S3 bucket names
  • Suspicious User-Agent strings indicative of spoofing
  • High‑volume traffic patterns consistent with Network Denial‑of‑Service attacks
  • Presence of known CVE identifiers such as CVE-2022-42475, CVE-2025-21590, CVE-2022-22948 and CVE-2023-20867

Recommended Actions

  • Enforce multi‑factor authentication for all privileged accounts to mitigate credential compromise risk.
  • Regularly patch and update FortiOS, Junos OS, and VMware vCenter against known CVE vulnerabilities.
  • Monitor logs for anomalous User-Agent strings or spoofed system attributes that could indicate lateral movement or stealthy activity.
  • Detect and mitigate high‑volume traffic indicative of DoS attempts targeting critical services such as cloud APIs or VPNs.
  • Restrict privileged command execution on virtual machines (including PhotonOS) and enforce least privilege principles for container images and AMIs.
  • Audit IAM role assignments and OpenID Connect trust relationships to ensure federated identities are appropriately scoped.
  • Implement continuous monitoring of CI/CD pipelines for malicious package introductions or unauthorized secret exfiltration.

Suggested Tags

supply‑chain attack
npm exploitation
cloud account takeover
CI/CD identity targeting
AWS admin access
service binary hijacking
MFA bypass
Network DoS
CVE exploitation
Privilege escalation
User‑Agent spoofing

Confidence Assessment

The available data provides a clear picture of UNC6426’s tactics around npm supply‑chain attacks and cloud credential theft, giving a moderate to high confidence in this specific threat profile. However, gaps remain regarding the full scope of victim organizations, precise attribution depth, exact campaign dates, and detailed tool families used beyond the known open‑source utilities. Additional signals from internal telemetry or broader industry sources would improve situational awareness.

ATT&CK Techniques

Exfiltration
1 technique
Lateral Movement
1 technique
Reconnaissance
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. fortiguard.fortinet.com — Cited by web research for: APT-C-17
  3. www.sentinelone.com — Cited by web research for: Singularity
  4. attack.mitre.org — Cited by web research for: STOP
  5. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  6. https://mallory.ai/actors/019cdc39-ecbd-7586-9bc4-a06bc3cafccc — Cited by AI analysis.
  7. https://thehackernews.com/2026/03/weekly-recap-chrome-0-days-router.html — Cited by AI analysis.
  8. https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026 — Cited by AI analysis.

Intel Summary

45

Techniques

63

Tools

7

Campaigns

39

IOCs

0

Observed Data

16

Tactics

Tags

Supply Chain Attack
Wiper / Destructive
supply‑chain attack
npm exploitation
cloud account takeover
CI/CD identity targeting
AWS admin access
service binary hijacking
MFA bypass
Network DoS
CVE exploitation
Privilege escalation
User‑Agent spoofing

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.