Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC4841

Also known as: SLIME57

Description

UNC4841 is a well-resourced threat actor that has utilized a wide range of malware and purpose-built tooling to enable their global espionage operations. They have been observed selectively deploying specific malware families at high priority targets, with SKIPJACK being the most widely deployed. UNC4841 primarily targeted government and technology organizations, but they have also been observed targeting other verticals.

AI Analysis

· 1 week ago

Executive Summary

UNC4841, also known as SLIME57, is a sophisticated threat actor engaged in global espionage operations. They are well-resourced, deploying custom malware and tooling to target high-value sectors such as government and technology organizations. Despite their unknown type, they exhibit advanced capabilities, making them a significant threat to targeted industries.

Goals & Targeting

UNC4841 targets sectors with high-value information, such as government agencies and technology firms, likely to gather sensitive data and disrupt operations. Their strategic focus on espionage suggests a mission to acquire intelligence that could impact national security or competitive advantage. The inclusion of other verticals indicates a flexible targeting strategy.

Enhanced Description

UNC4841 is a sophisticated threat actor known for their global espionage operations. They have demonstrated the ability to selectively deploy malware, notably SKIPJACK, targeting high-priority sectors including government and technology organizations. Their operational toolkit includes custom-built tools, reflecting a high level of technical proficiency. Despite their unknown type, UNC4841's activities suggest a primary focus on intelligence gathering and espionage. The absence of linked campaigns and specific tools underscores the need for further analysis but highlights their adaptability and strategic targeting.

Key Capabilities

  • Advanced malware development
  • Custom-built espionage tools
  • SKIPJACK malware deployment
  • Lateral movement techniques
  • Persistence mechanisms

MITRE ATT&CK Tactics

Adversary Persister
Credential Access
Discovery
Lateral Movement
Exfiltration
Collection

ATT&CK Techniques

T1059.003
T1055
T1270.001
T1003
T1048
T1566.001

Software / Tooling

SKIPJACK
Cobalt Strike (if used)

Campaigns & Victims

UNC4841's operations are characterized by their global reach and targeted approach. While specific campaigns remain unclear, their activity indicates a focus on long-term espionage objectives. Their victims include government agencies and tech firms, suggesting a deliberate strategy to maximize intelligence yield.

IOC Patterns

  • Spear-phishing with malicious attachments
  • Fileless malware in memory
  • Domain generation for C2 communication
  • Encrypted command-and-control traffic
  • Cobalt Strike beacon activity

Recommended Actions

  • Enhance network monitoring for phishing attempts
  • Implement endpoint detection and response (EDR)
  • Conduct regular credential audits
  • Block unauthorized RDP access
  • Apply patches promptly to mitigate vulnerabilities

Suggested Tags

APT group
Government targeting
Technology sector
Espionage

Confidence Assessment

High confidence in UNC4841's status as a well-resourced threat actor, though specific details like exact campaigns and tools remain unclear. This gap indicates areas needing further intelligence gathering.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Government Targeting
APT group
Government targeting
Technology sector
Espionage

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.