UNC2447 is a financially motivated group known for deploying FiveHands and Hello Kitty ransomware with double extortion tactics.
Analyst brief
UNC2447 is a financially motivated threat actor active since at least May 2020, with ties to multiple hacker groups and known for deploying FiveHands and Hello Kitty ransomware. The group primarily targets organizations in Europe and North America, employing double extortion tactics that combine data theft and encryption. Key TTPs include the use of ransomware variants and threats to leak exfiltrated data on dedicated leak sites. Defenders should focus on detecting initial access vectors like exploited VPN appliances, monitoring for unusual data exfiltration, and strengthening lateral movement defenses.
UNC2447
unknown
UNC2447 is a financially motivated threat actor with ties to multiple hacker groups. They have been observed deploying ransomware, including FiveHands and Hello Kitty, and engaging in double extortion tactics. They have been active since at least May 2020 and target organizations in Europe and North America.