Also known as: tracked as, Aug 5, which focused on CI, CD identities, CVE-2026-40175, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, APT-C-17, Baby Elephant, Hardcore Nationalist, Leafperforator, Rattlesnake, Razor, Playcrypt, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, SideWinder, T-APT-04, India
UNC6426 is a financially motivated adversary that targets cloud‑centric infrastructures, particularly focusing on CI/CD pipelines and identity federation configurations. The group first compromised an npm package, enabling it to inject malicious code into developer workflows and steal a GitHub Personal Access Token. By abusing the GitHub‑to‑AWS OpenID Connect trust chain, UNC6426 was able to create a new administrative IAM role with overly permissive permissions tied to the GitHub‑Actions‑CloudFormation role. Within 72 hours of initial compromise, the actor had full AWS administrator privileges. Leveraging the legitimate open‑source tool Nord Stream for reconnaissance, UNC6426 harvested secrets from CI/CD environments and exfiltrated files from AWS S3 buckets while also conducting data destruction operations against victim cloud resources. Their tactics include exploiting multiple public CVEs—Vulnerabilities such as FortiOS SSL VPN (CVE‑2022‑42475), Junos OS veriexec bypass (CVE‑2025‑21590), VMware vCenter credential theft (CVE‑2022‑22948)—and utilizing a zero‑day exploit (CVE‑2023‑20867) to execute commands across Windows, Linux, and PhotonOS VMs. The actor demonstrates sophisticated cloud persistence methods by implanting malicious AMIs or container images and hijacking services through binary replacement. They also generate disposable email accounts for phishing campaigns, spoof browser and system attributes, bypass multi‑factor authentication, and launch Network DoS attacks as a distraction or disruption technique.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6426 exploits supply‑chain vulnerabilities in npm packages to seize AWS administrative control, leveraging compromised GitHub identities and OpenID Connect trust. The actor then extracts secrets from CI/CD environments, exfiltrates data from S3 buckets, and can destroy files within 72 hours. Rapid escalation of privilege and use of cloud persistence mechanisms make the threat highly disruptive for target organizations.
Goals & Targeting
UNC6426’s strategic objectives focus on financial gain through the theft of cloud credentials, data exfiltration, and asset destruction. By targeting CI/CD identities—particularly those with elevated privileges—and exploiting supply chain pathways, the actor can rapidly ascend to top‑level access within cloud environments. Their selection of sectors (defense, media, finance, telecoms) reflects a preference for organizations that rely heavily on cloud automation pipelines, while their geographic focus spans key technology hubs in CN, US, IR, IL, SA, SG, and JP.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6426 operates primarily through cloud supply‑chain attacks and identity federation exploitation, rapidly escalating from initial foothold to administrator control, typically within 72 hours. Victims are predominantly organizations operating heavy CI/CD pipelines in defense, media, finance, and telecom sectors across multiple regions. The adversary’s modus operandi involves subtle lateral movement via hijacked binaries, stealthy data staging in cloud buckets, and opportunistic DoS attacks on critical services to distract or force manual intervention.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a clear picture of UNC6426’s tactics around npm supply‑chain attacks and cloud credential theft, giving a moderate to high confidence in this specific threat profile. However, gaps remain regarding the full scope of victim organizations, precise attribution depth, exact campaign dates, and detailed tool families used beyond the known open‑source utilities. Additional signals from internal telemetry or broader industry sources would improve situational awareness.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
45
Techniques
63
Tools
7
Campaigns
39
IOCs
0
Observed Data
16
Tactics