[Unnamed group]
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
The threat actor, often tracked as UNC2447, emerged in October 2020, initially deploying the FiveHands ransomware, which was a rewrite of the earlier DeathRansom variant. Mandiant identified UNC2447 in November 2020, observing its use of the WARPRISM PowerShell dropper. The group is financially motivated, monetizing intrusions through a double extortion model that combines data encryption with threats of public exposure or sale of exfiltrated data. UNC2447 distinguishes itself through its capability to exploit zero-day vulnerabilities, such as a SonicWall VPN flaw, and its advanced operational sophistication to evade detection. While FiveHands has been linked to DeathRansom and shows connections to HelloKitty ransomware, UNC2447 is currently not attributed to any known nation-state or specific APT group.
Sectores objetivo (SOCRadar)
Public AdministrationSpace & Defense