Uptime Hamster: 10d 19h 55mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza UNC2447

UNC2447

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: APT UNC2447
Ver en IntelTracker → APTTrail →
UNC2447 is a financially motivated cybercrime group, first tracked by Mandiant in November 2020, known for its aggressive ransomware operations and data theft. The group distinguishes itself through its consistent exploitation of zero-day vulnerabilities in internet-facing appliances and its deployment of proprietary malware alongside legitimate tools. Initially designated as an uncategorized group by Mandiant, Cisco has since assessed with moderate-to-high confidence that UNC2447 operates as a subgroup of the Russia-linked WIZARD SPIDER threat group, often deploying CONTI ransomware in its campaigns. The group has been observed utilizing an affiliate program model, with activity shifting from HelloKitty to FIVEHANDS ransomware. UNC2447 primarily targets organizations in Europe and North America and engages in double extortion to pressure victims.

Aliases del actor

APT UNC2447

Actores similares

apt-unc2447actor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1apt-27actor · 1apt-30actor · 1apt-38actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownotx.alienvault.comAPT UNC2447 indicators and references
DLS / leak siteunknownus-cert.cisa.govAPT UNC2447 indicators and references
DLS / leak siteunknownwww.fireeye.comAPT UNC2447 indicators and references
Repositoriounknowngithub.comAPT UNC2447 indicators and references
DLS / leak siteunknownraw.githubusercontent.comAPT UNC2447 indicators and references
DLS / leak siteunknownotx.alienvault.comAPT UNC2447 indicators and references
Motivacion