UNC2565
0 incidentes
0 paises
0 sectores
apt UNKNOWN Ultimo: -
Aliases: Hive0127, APT UNC2565
UNC2565 is a financially motivated threat group that emerged in late 2020, primarily operating as an Initial Access Broker (IAB) by distributing the JavaScript-based malware loader known as GootLoader. The group consistently employs sophisticated Search Engine Optimization (SEO) poisoning to lure victims into downloading their malicious payloads, differentiating them through this unique infection vector. Over time, UNC2565 has evolved GootLoader with enhanced obfuscation techniques and new infection chains, demonstrating an active development cycle for its tooling. Their primary objective is to gain and subsequently sell or grant initial access to compromised systems for other threat actors, including various ransomware operators, rather than directly engaging in full-scale extortion campaigns themselves. While no specific origin is confirmed, their operations show a global reach without heavy discrimination in target selection.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
Sectores objetivo (SOCRadar)
FinanceHealthCare & Social AssistancePublic AdministrationOil & GasReal EstateLegal Services