UNC1878 is a financially motivated group known for monetizing network access via RYUK ransomware.
Analyst brief
UNC1878 is a financially motivated threat actor that monetizes network access through the deployment of RYUK ransomware. According to Mandiant, the group was active in spring, saw a significant decrease in summer, but resurged in early fall with overlapping TTPs. Their key TTPs involve rapid network intrusion followed by RYUK ransomware deployment. Defenders should focus on initial access vectors, monitor for RYUK propagation activity using YARA rules, and ensure rapid containment procedures are in place.
UNC1878
unknown
UNC1878 is a financially motivated threat actor that monetizes network access via the deployment of RYUK ransomware. Earlier this year, Mandiant published a blog on a fast-moving adversary deploying RYUK ransomware, UNC1878. Shortly after its release, there was a significant decrease in observed UNC1878 intrusions and RYUK activity overall almost completely vanishing over the summer. But beginning in early fall, Mandiant has seen a resurgence of RYUK along with TTP overlaps indicating that UNC1878 has returned from the grave and resumed their operations.