Uptime Hamster: 10d 9h 54mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza [Unnamed group]

[Unnamed group]

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Ver en IntelTracker → APTTrail →
The threat actor, often tracked as UNC2447, emerged in October 2020, initially deploying the FiveHands ransomware, which was a rewrite of the earlier DeathRansom variant. Mandiant identified UNC2447 in November 2020, observing its use of the WARPRISM PowerShell dropper. The group is financially motivated, monetizing intrusions through a double extortion model that combines data encryption with threats of public exposure or sale of exfiltrated data. UNC2447 distinguishes itself through its capability to exploit zero-day vulnerabilities, such as a SonicWall VPN flaw, and its advanced operational sophistication to evade detection. While FiveHands has been linked to DeathRansom and shows connections to HelloKitty ransomware, UNC2447 is currently not attributed to any known nation-state or specific APT group.

Actores similares

silentransomgroupactor · 36GroupIB_TIactor · 11bonacigroupransomware · 2thegreenbloodgroupransomware · 2vanirgroupransomware · 2SilentRansomGroupactor · 2the-green-blood-groupactor · 2apt-equationgroupactor · 1apt-group5actor · 1bluewindgroupactor · 1
Malware asociado
win.sombrat, win.puzzlemaker, emotet
Tecnicas MITRE
T1566.001 - Spearphishing Attachment, T1053.007 - Container Orchestration Job, T1534 - Internal Spearphishing, T1053.001 - At (Linux), T1056.001 - Keylogging, T1204.002 - Malicious File
CVEs relacionadas
CVE-2025-9491, CVE-2025-8088, CVE-2025-64446, CVE-2025-6264, CVE-2025-61884, CVE-2025-61882
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
64
Actualizado
Wed, 01 Ju

Sectores objetivo (SOCRadar)

Public AdministrationSpace & Defense