UNC2659 is a threat actor known for completing the full attack lifecycle in under 10 days by exploiting a SonicWall SMA100 SSL VPN vulnerability.
Analyst brief
UNC2659 is a threat actor active since at least January 2021, notable for completing the full attack lifecycle in under 10 days. They primarily target systems by exploiting a now-patched vulnerability in the SonicWall SMA100 SSL VPN product. Their TTPs involve downloading various tools for different attack phases directly from the legitimate public websites of those tools. Defenders must prioritize patching SonicWall SMA100 devices, enhance rapid-response monitoring to counter the fast attack tempo, and review anomaly detection rules for tools fetched from legitimate public sites.
UNC2659
unknown
UNC2659 has been active since at least January 2021. We have observed the threat actor move through the whole attack lifecycle in under 10 days. UNC2659 is notable given their use of an exploit in the SonicWall SMA100 SSL VPN product, which has since been patched by SonicWall. The threat actor appeared to download several tools used for various phases of the attack lifecycle directly from those tools’ legitimate public websites.
Which product's vulnerability does UNC2659 exploit to gain initial access to systems?+
UNC2659 exploits a vulnerability in the SonicWall SMA100 SSL VPN product, which has since been patched, to gain access to systems.
What is notable about how UNC2659 obtains tools during an attack?+
UNC2659 is notable for downloading several tools used for various phases of the attack lifecycle directly from the legitimate public websites of those tools.