UNC2565 (Hive0127) is a financially motivated group delivering SODINOKIBI ransomware via SEO-driven GOOTLOADER infections.
Analyst brief
UNC2565 (Hive0127) is a likely financially motivated threat group, as their activity overlaps with SODINOKIBI ransomware deployments. They primarily target victims through malicious websites that use SEO techniques to rank high in search results. The group leverages the GOOTLOADER downloader to deliver Cobalt Strike BEACON and subsequently uses tools like BLOODHOUND and KERBEROAST for reconnaissance and credential harvesting. Defenders should focus on detecting anomalous SEO-driven traffic, GOOTLOADER execution, and post-exploitation AD reconnaissance tools.
UNC2565
Hive0127
unknown
UNC2565 is a threat group that has used the GOOTLOADER downloader to deliver Cobalt Strike BEACON. These intrusions have stemmed from victims accessing malicious websites that use SEO techniques to improve Google search rankings. After obtaining a foothold in the environment, UNC2565 has conducted reconnaissance and credential harvesting activity using common tools such as BLOODHOUND and KERBEROAST. UNC2565's motivations are currently unknown but overlaps with activity that has led to SODINOKIBI ransomware. This suggests that the threat group may be financially motivated.
UNC2565 gains initial access through malicious websites that use SEO techniques to rank high in search results. When users visit these sites, the GOOTLOADER downloader is executed.
How is UNC2565 connected to SODINOKIBI ransomware?+
UNC2565's activity overlaps with SODINOKIBI ransomware deployments. This connection suggests the group may be financially motivated.