UNC2659UNC2659

Also known as: UNC2659

Known aliases
1

Profile

UNC2659 has been active since at least January 2021. We have observed the threat actor move through the whole attack lifecycle in under 10 days. UNC2659 is notable given their use of an exploit in the SonicWall SMA100 SSL VPN product, which has since been patched by SonicWall. The threat actor appeared to download several tools used for various phases of the attack lifecycle directly from those tools’ legitimate public websites.

Aliases· 1

UNC2659

References

  1. http://internal-www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC2630
Actor
UNC6148
Actor
UNC6691
Actor
UNC4540
Actor
UNC6201
Actor
UNC5330
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.