Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LightBasin

Also known as: UNC1945, CL-CRI-0025

Description

UNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromised networks. UNC1945 has demonstrated advanced technical abilities, utilizing various tools and techniques to evade detection and move laterally through networks. They have also been observed targeting other industries, such as financial and professional consulting, and have been linked to other threat actors, including MustangPanada and RedDelta.

Goals & Targeting

Targeted Sectors

Financial services

AI Analysis

· 1 week ago

Executive Summary

LightBasin (UNC1945/CL-CRI-0025) is an advanced persistent threat group targeting telecommunications and financial sectors with Linux-based implants for long-term access. The group employs sophisticated evasion techniques and lateral movement, with potential links to MustangPanada and RedDelta. Their operations suggest a focus on sustained surveillance and data exfiltration.

Goals & Targeting

LightBasin's strategic objectives appear to center on gaining and maintaining long-term access to critical infrastructure within sectors that handle sensitive communications (telecom) and financial data (finance). By targeting these industries, the group likely seeks to conduct sustained surveillance, exfiltrate valuable information, or disrupt operations for strategic advantage. Their expansion into professional consulting suggests an interest in accessing intellectual property or client data. The financial and telecom sectors are attractive due to their high-value data and potential for economic or geopolitical impact.

Enhanced Description

LightBasin, also known as UNC1945 and CL-CRI-0025, is an APT group primarily associated with targeting telecommunications companies but has expanded its activity to include financial services and professional consulting sectors. The group leverages Linux-based implants to establish persistent access within compromised networks, enabling long-term surveillance and data exfiltration. They demonstrate advanced technical capabilities, including the use of multiple evasion strategies and lateral movement techniques to avoid detection. Notably, UNC1945 has been linked to other threat actors such as MustangPanada and RedDelta, suggesting potential collaboration or shared infrastructure. Despite limited public information on their primary motivation, their targeting pattern implies an interest in high-value industries that manage sensitive communications and financial data. The group's operational methods include multi-stage attack sequences and the deployment of custom tools tailored for network infiltration.

Key Capabilities

  • Deployment of Linux-based implants for persistent access
  • Advanced evasion techniques to avoid detection
  • Lateral movement within compromised networks
  • Multi-stage attack strategies
  • Custom tool development for network infiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command and Control
Exfiltration

ATT&CK Techniques

T1132.001 - NTFS Alternate Data Streams
T1055 - Process Injection
T1021 - Remote Services
T1070.001 - Clear Logs
T1071.001 - Application Layer Protocol
T1105 - Ingress Tool Transfer

Software / Tooling

Custom Linux-based implants
Custom RAT (Remote Access Tool)
Tailored network infiltration utilities

Campaigns & Victims

LightBasin's campaigns typically involve multi-stage operations targeting telecom and financial sectors, with a focus on establishing long-term presence. Their activities suggest a low operational tempo, emphasizing stealth and persistence over rapid escalation. Notable operations include the deployment of Linux implants in telecom networks, followed by lateral movement to access financial systems. While no specific campaigns are publicly documented, their methods align with those used by other APT groups, indicating potential shared tactics or affiliations.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication over DNS using fast-flux techniques
  • Staging infrastructure on bulletproof hosting providers
  • Linux-based implants with obfuscated payloads

Recommended Actions

  • Deploy endpoint detection solutions with Linux-specific monitoring capabilities
  • Implement strict network segmentation to limit lateral movement
  • Conduct regular phishing simulations targeting telecom and finance personnel
  • Monitor DNS traffic for signs of fast-flux C2 domains
  • Perform log analysis for evidence of process injection or log-clearing activities

Suggested Tags

APT
telecom-sector
financial-sector
espionage
Linux-implant

Confidence Assessment

Confidence in the described capabilities and targeting is moderate, based on the group's reported use of Linux implants and sector-specific targeting. However, gaps exist in confirmed MITRE techniques, specific tools used, and direct attribution details. The links to MustangPanada and RedDelta require further validation to establish definitive relationships.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
telecom-sector
financial-sector
espionage
Linux-implant

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.