UNC4393 is a financially motivated threat actor known for multi-faceted extortion and data theft with BASTA ransomware.
Analyst brief
UNC4393 is a financially motivated threat actor primarily leveraging BASTA ransomware. The group targets organizations across diverse industries with a focus on multi-faceted extortion and efficient data exfiltration. Key TTPs include initial access via Spearphishing Voice (vishing), execution with PowerShell, lateral movement using Cobalt Strike and Impacket, and data theft via tools like RCLONE before encryption with BASTA ransomware. Defenders must prioritize user education against vishing attacks, rigorously monitor remote access tools like Quick Assist for unauthorized use, and implement network segmentation to detect lateral movement activities.
UNC4393
Storm-1811CURLY SPIDERSTAC5777
unknown
UNC4393 is a financially motivated threat actor primarily using BASTA ransomware. They have been active since early 2022 and have targeted over 40 organizations across various industries. UNC4393 has shown a willingness to cooperate with other threat clusters for initial access and has evolved from using existing tools to developing custom malware. They focus on efficient data exfiltration and multi-faceted extortion, often utilizing tools like COGSCAN and RCLONE for reconnaissance and data theft.