Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6748

Also known as: tracked as, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, Turkey, Malaysia, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

UNC6748 targets users in Saudi Arabia through a fake Snapchat website, employing a backdoor known as GHOSTKNIFE for data exfiltration. Their exploitation process initially featured basic obfuscation, which evolved to include anti-debugging measures. The actor primarily leveraged CVE-2025-31277 and CVE-2026-20700 for RCE exploits, but exhibited inconsistencies in exploit support for different iOS versions. Additionally, UNC6748's delivery mechanisms incorporated session storage checks to manage infection attempts.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Aerospace
Media
Education
Manufacturing
Information technology
Maritime
Healthcare
Think tank
Pharmaceutical
Chemical
Mining
Hospitality
Legal services
Nuclear
Entertainment
Utilities

Targeted Countries / Regions

US
CN
GB
IN
SA
JP
DE
KR
UA
TR
IR
RU
TW
FR
CA
IL
AU
KZ
PK
VN
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

· 1 week ago

Executive Summary

UNC6748 is a cyber threat actor targeting users in Saudi Arabia through a fake Snapchat website. They employ the GHOSTKNIFE backdoor for data exfiltration and have demonstrated evolving technical capabilities, initially using basic obfuscation and later incorporating anti-debugging measures. Their primary exploits include CVE-2025-31277 and CVE-2026-20700 for remote code execution (RCE), though inconsistencies in exploit support across iOS versions have been observed.

Goals & Targeting

UNC6748 appears to target users in Saudi Arabia through sophisticated phishing campaigns and exploitation of known vulnerabilities. Their strategic objectives likely include information gathering, potentially for espionage or financial gain. The choice of targeting a specific country suggests they may have regional interests or be aligned with actors seeking to compromise geopolitical targets. Their victims are primarily individuals who fall for their phishing attempts, though the group's long-term goals remain speculative.

Enhanced Description

UNC6748 is a cyber threat actor that has emerged as a significant concern due to their targeted attacks against users in Saudi Arabia. The group gained attention for deploying the GHOSTKNIFE backdoor, which they use to facilitate data exfiltration from compromised systems. Initially reported to have limited technical sophistication, UNC6748 demonstrated signs of evolution by enhancing their obfuscation techniques and incorporating anti-debugging measures, indicating a potential effort to evade detection and analysis. Their exploitation process primarily leverages two critical vulnerabilities: CVE-2025-31277 and CVE-2026-20700, both associated with remote code execution (RCE) capabilities. However, investigations have revealed inconsistencies in their exploit support across different iOS versions, suggesting either limited resources or a focus on specific targets. The group's attack vector initially involved creating fake Snapchat websites to deceive users into providing sensitive information or downloading malicious payloads. Over time, their delivery mechanisms have incorporated session storage checks, likely to manage infection attempts and avoid unnecessary duplication of efforts. This indicates a basic level of operational refinement. While the full scope of UNC6748's activities remains unclear due to limited公开 reporting, their targeting of Saudi Arabia suggests a potential regional or geopolitical focus, possibly aligned with espionage, financial gain, or disruptive objectives.

Key Capabilities

  • Deployment of the GHOSTKNIFE backdoor
  • Basic obfuscation techniques
  • Anti-debugging measures
  • Exploitation of CVE-2025-31277 and CVE-2026-20700 for RCE
  • Session storage checks in delivery mechanisms

MITRE ATT&CK Tactics

Credential Access
Execution
Lateral Movement

ATT&CK Techniques

T1059.003 - PowerShell with base64 encoded command
T1055 - Process injection
T1566.001 - Data transfer tools and techniques

Software / Tooling

GHOSTKNIFE backdoor
Custom malware for RCE exploits
Session storage exploit

Campaigns & Victims

UNC6748 has operated with a regional focus, targeting individuals in Saudi Arabia through phishing campaigns and fake websites. Their campaign activity spans from first seen to last observed dates, though limited reporting obscures the full timeline. The group's victims are likely individuals who interacted with their malicious websites, potentially including Arabic-speaking users or those with specific interests in the region. While their exact modus operandi is not fully understood, their use of fake Snapchat websites and GHOSTKNIFE suggests a focus on stealth and targeted信息采集 rather than large-scale disruption.

IOC Patterns

  • Phishing emails mimicking social media platforms (e.g., Snapchat)
  • Fake website domains registered to host malicious content
  • Network traffic associated with C2 servers used for backdoor communication
  • Presence of GHOSTKNIFE backdoor on compromised systems
  • Exploitation attempts targeting CVE-2025-31277 and CVE-2026-20700

Recommended Actions

  • Monitor for phishing campaigns mimicking popular social media platforms
  • Patch systems to address known vulnerabilities (CVE-2025-31277, CVE-2026-20700)
  • Implement network traffic monitoring to detect C2 communication patterns
  • Use endpoint detection and response (EDR) tools to identify malicious activities
  • Conduct regular user awareness training to mitigate phishing risks

Suggested Tags

APT
Campaign
Espionage
Saudi Arabia

Confidence Assessment

Moderate confidence due to limited available information. Gaps include the actor's exact origin, primary motivation, and long-term strategic goals. The absence of detailed information on their tactics and tools beyond what is already observed (e.g., GHOSTKNIFE) leaves room for further analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. www.securityweek.com — Cited by web research for: Turkey
  3. cloud.google.com — Cited by web research for: GHOSTBLADE
  4. www.techradar.com — Cited by web research for: Utilities

Intel Summary

0

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
Data Exfiltration
APT
Campaign
Espionage
Saudi Arabia

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.