Also known as: tracked as, steal Microsoft Exchange emails, the 'auth code flow, SVR, Cozy Bear, Midnight Blizzard, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, endpoint detection, such as storage arrays, load balancers, wireless access point controllers, Royal Ransomware
UNC3524, first observed by Mandiant in December 2019, emerged from the broader Russian state‑sponsored threat ecosystem. The group employs spear‑phishing campaigns under the moniker "Eye Spy on Your Email" to compromise employees who handle corporate development and M&A activities. Once inside a network, UNC3524 installs small, custom backdoors such as QuietExit—built atop the Dropbear SSH client—directly onto trusted infrastructure devices (SAN arrays, load balancers, wireless access point controllers) that typically do not run endpoint security software. Complementary footholds include REGEORG web shells placed on DMZ web servers, which expose SOCKS proxies and enable lateral movement and additional persistence. Beyond initial access, the actor’s tactics blend data theft with opportunistic extortion. UNC3524 extracts emails and documents through a combination of native Microsoft Exchange Web Services APIs or Outlook MAPI, leveraging credential harvesting tools like PowerShell and Mimikatz, and custom Impacket utilities for Lateral Movement. The group also uses protocol tunneling (SSH, GOST, FRP, ngrok) to obfuscate C2 traffic, dynamic DNS resolution for remote command delivery, and encryption of exfiltrated payloads, sometimes combining it with ransomware‑style double tactics. Despite having no large commercial malware families in its arsenal, the actor’s footprint is carefully engineered to avoid detection, exploiting devices that are less likely to support antivirus or EDR solutions. Operational intelligence indicates a strong link between UNC3524 and APT29’s toolset while maintaining distinct indicators, particularly IoT exploitation and targeted email harvesting for high‑stakes corporate decisions. The group’s long dwell times (up to 18+ months) suggest an espionage mandate that may be financed by financial gain through ransomware or data monetization. Overall, UNC3524 exemplifies a modern APT with hybrid motivations: covert intelligence gatherers using a minimalist, low‑profile approach complemented by opportunistic extortion. Its tactics, tools, and procedures underscore the need for comprehensive visibility across all layers of enterprise infrastructure.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC3524, also known as Midnight Blizzard and Cranefly, is a Russian state-sponsored espionage group that first appeared in late 2019. The actor focuses on infiltrating corporate email accounts of employees involved in mergers, acquisitions, and large transactions, gaining persistent access through lightweight backdoors on network appliances such as SAN arrays, load balancers, and IoT cameras. Its sophisticated use of living‑off‑the‑land binaries and low‑profile remote access tools enables it to remain undetected for up to 18 months while exfiltrating data via Exchange Web Services and occasionally employing a double‑extortion strategy that encrypts victim data.
Goals & Targeting
UNC3524’s strategic objectives revolve around extracting high‑value business intelligence and corporate secrets that influence mergers and acquisitions, thereby creating financial opportunities through ransomware or data leakage. By targeting executive decision‑makers in sectors from finance to media, the actor ensures that the information they capture can drive market movements or competitive advantage. The group exploits trusted appliances and IoT devices due to their limited security monitoring, allowing undetected persistence for extended periods. Typical victims are organizations engaged in large business transactions or with sensitive corporate development processes; geographically, the actor focuses on U.S., European, Asian, and Middle Eastern firms that fit its economic objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC3524 typically launches campaigns over several weeks, beginning with a spear‑phishing email targeted at M&A or corporate development personnel. Upon opening the attachment or clicking a link, the actor gains foothold in a victim environment and then immediately deploys backdoors to trusted network appliances and a secondary REGEORG web shell on a DMZ host. The group monitors Exchange Web Services for high‑value emails, exfiltrates them via SSH tunnels or HTTP proxies, and keeps persistence by re‑inserting the backdoor should any removal occur. Their operational tempo allows them to remain inside networks for up to 18 months, with periodic reconnection attempts after defensive actions. Key victim types are medium‑to‑large enterprises in finance, media, telecommunications, and government that have complex merger & acquisition processes or high-value data sets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple corroborating reports from Mandiant (2022) and publicly vetted incident details, providing high confidence in the identified tactics, techniques, and tools. However, certain aspects remain less well documented, such as precise financial objectives versus pure espionage motives and exact first/last seen dates. Additionally, limited public information is available on whether the group actively integrates ransomware operations. Therefore, while we are confident about the actor’s capabilities and typical procedures, gaps persist regarding long‑term strategic goals and potential future tool development.
No campaigns linked yet.
No observed data linked yet.
57
Techniques
61
Tools
0
Campaigns
39
IOCs
0
Observed Data
11
Tactics