Also known as: tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, Turkey, Malaysia, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
UNC6748 targets users in Saudi Arabia through a fake Snapchat website, employing a backdoor known as GHOSTKNIFE for data exfiltration. Their exploitation process initially featured basic obfuscation, which evolved to include anti-debugging measures. The actor primarily leveraged CVE-2025-31277 and CVE-2026-20700 for RCE exploits, but exhibited inconsistencies in exploit support for different iOS versions. Additionally, UNC6748's delivery mechanisms incorporated session storage checks to manage infection attempts.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6748 is a cyber threat actor targeting users in Saudi Arabia through a fake Snapchat website. They employ the GHOSTKNIFE backdoor for data exfiltration and have demonstrated evolving technical capabilities, initially using basic obfuscation and later incorporating anti-debugging measures. Their primary exploits include CVE-2025-31277 and CVE-2026-20700 for remote code execution (RCE), though inconsistencies in exploit support across iOS versions have been observed.
Goals & Targeting
UNC6748 appears to target users in Saudi Arabia through sophisticated phishing campaigns and exploitation of known vulnerabilities. Their strategic objectives likely include information gathering, potentially for espionage or financial gain. The choice of targeting a specific country suggests they may have regional interests or be aligned with actors seeking to compromise geopolitical targets. Their victims are primarily individuals who fall for their phishing attempts, though the group's long-term goals remain speculative.
Enhanced Description
UNC6748 is a cyber threat actor that has emerged as a significant concern due to their targeted attacks against users in Saudi Arabia. The group gained attention for deploying the GHOSTKNIFE backdoor, which they use to facilitate data exfiltration from compromised systems. Initially reported to have limited technical sophistication, UNC6748 demonstrated signs of evolution by enhancing their obfuscation techniques and incorporating anti-debugging measures, indicating a potential effort to evade detection and analysis. Their exploitation process primarily leverages two critical vulnerabilities: CVE-2025-31277 and CVE-2026-20700, both associated with remote code execution (RCE) capabilities. However, investigations have revealed inconsistencies in their exploit support across different iOS versions, suggesting either limited resources or a focus on specific targets. The group's attack vector initially involved creating fake Snapchat websites to deceive users into providing sensitive information or downloading malicious payloads. Over time, their delivery mechanisms have incorporated session storage checks, likely to manage infection attempts and avoid unnecessary duplication of efforts. This indicates a basic level of operational refinement. While the full scope of UNC6748's activities remains unclear due to limited公开 reporting, their targeting of Saudi Arabia suggests a potential regional or geopolitical focus, possibly aligned with espionage, financial gain, or disruptive objectives.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6748 has operated with a regional focus, targeting individuals in Saudi Arabia through phishing campaigns and fake websites. Their campaign activity spans from first seen to last observed dates, though limited reporting obscures the full timeline. The group's victims are likely individuals who interacted with their malicious websites, potentially including Arabic-speaking users or those with specific interests in the region. While their exact modus operandi is not fully understood, their use of fake Snapchat websites and GHOSTKNIFE suggests a focus on stealth and targeted信息采集 rather than large-scale disruption.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence due to limited available information. Gaps include the actor's exact origin, primary motivation, and long-term strategic goals. The absence of detailed information on their tactics and tools beyond what is already observed (e.g., GHOSTKNIFE) leaves room for further analysis.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics