Also known as: UNC1945, CL-CRI-0025
UNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromised networks. UNC1945 has demonstrated advanced technical abilities, utilizing various tools and techniques to evade detection and move laterally through networks. They have also been observed targeting other industries, such as financial and professional consulting, and have been linked to other threat actors, including MustangPanada and RedDelta.
Targeted Sectors
Executive Summary
LightBasin (UNC1945/CL-CRI-0025) is an advanced persistent threat group targeting telecommunications and financial sectors with Linux-based implants for long-term access. The group employs sophisticated evasion techniques and lateral movement, with potential links to MustangPanada and RedDelta. Their operations suggest a focus on sustained surveillance and data exfiltration.
Goals & Targeting
LightBasin's strategic objectives appear to center on gaining and maintaining long-term access to critical infrastructure within sectors that handle sensitive communications (telecom) and financial data (finance). By targeting these industries, the group likely seeks to conduct sustained surveillance, exfiltrate valuable information, or disrupt operations for strategic advantage. Their expansion into professional consulting suggests an interest in accessing intellectual property or client data. The financial and telecom sectors are attractive due to their high-value data and potential for economic or geopolitical impact.
Enhanced Description
LightBasin, also known as UNC1945 and CL-CRI-0025, is an APT group primarily associated with targeting telecommunications companies but has expanded its activity to include financial services and professional consulting sectors. The group leverages Linux-based implants to establish persistent access within compromised networks, enabling long-term surveillance and data exfiltration. They demonstrate advanced technical capabilities, including the use of multiple evasion strategies and lateral movement techniques to avoid detection. Notably, UNC1945 has been linked to other threat actors such as MustangPanada and RedDelta, suggesting potential collaboration or shared infrastructure. Despite limited public information on their primary motivation, their targeting pattern implies an interest in high-value industries that manage sensitive communications and financial data. The group's operational methods include multi-stage attack sequences and the deployment of custom tools tailored for network infiltration.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LightBasin's campaigns typically involve multi-stage operations targeting telecom and financial sectors, with a focus on establishing long-term presence. Their activities suggest a low operational tempo, emphasizing stealth and persistence over rapid escalation. Notable operations include the deployment of Linux implants in telecom networks, followed by lateral movement to access financial systems. While no specific campaigns are publicly documented, their methods align with those used by other APT groups, indicating potential shared tactics or affiliations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the described capabilities and targeting is moderate, based on the group's reported use of Linux implants and sector-specific targeting. However, gaps exist in confirmed MITRE techniques, specific tools used, and direct attribution details. The links to MustangPanada and RedDelta require further validation to establish definitive relationships.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics