UNC4536 is a financially motivated cybercriminal group distributing ICEDID, REDLINESTEALER, and CARBANAK malware.
Analyst brief
UNC4536 is a financially motivated cybercriminal group distributing malware such as ICEDID, REDLINESTEALER, and CARBANAK through malvertising and SEO poisoning. They target victims by masquerading trojanized MSIX installers as popular software and hosting them on fake sites promoted via Google Ads. Their key TTPs include the NUMOZYLOD PowerShell script to deliver tailored payloads like the CARBANAK backdoor, and they also deploy NetSupport RAT in campaigns aimed at IT administrators. Defenders should focus on monitoring suspicious software download behaviors, detecting NUMOZYLOD in PowerShell logs, and blocking unauthorized remote administration tool installations.
UNC4536
unknown
UNC4536 is a threat actor that distributes malware, including ICEDID, REDLINESTEALER, and CARBANAK, primarily through malvertising and trojanized MSIX installers masquerading as popular software. They utilize SEO poisoning tactics to direct victims to malicious sites that mimic legitimate software hosting platforms, facilitating the download of compromised installers. The actor employs a PowerShell script known as NUMOZYLOD to deliver tailored payloads, such as the CARBANAK backdoor, to their partners. Additionally, UNC4536 has been linked to campaigns that distribute NetSupport RAT, targeting IT administrators through fake sites promoted via Google Ads.