UNC4990 is a financially motivated threat actor targeting Italy via USB, using QUIETBOARD backdoor.
Analyst brief
UNC4990 is a financially motivated threat actor active since at least 2020, primarily targeting users in Italy. They rely on USB devices for initial infection and use encoded text files hosted on platforms like GitHub and Vimeo for payload delivery. Their toolkit includes sophisticated backdoors such as QUIETBOARD and EMPTYSPACE. Defenders should focus on controlling USB device usage, monitoring for suspicious network traffic, and inspecting encoded file operations.
UNC4990
unknown
UNC4990 is a financially motivated threat actor that has been active since at least 2020. They primarily target users in Italy and rely on USB devices for initial infection. The group has evolved their tactics over time, using encoded text files on popular websites like GitHub and Vimeo to host payloads. They have been observed using sophisticated backdoors like QUIETBOARD and EMPTYSPACE, and have targeted organizations in various industries, particularly in Italy.