UTA0178 is a threat actor targeting Germany, known for ICS VPN exploitation and lateral RDP movement.
Analyst brief
The threat actor tracked as UTA0178 (also known as UNC5221 and Red Dev 61) primarily targets entities in Germany. After gaining initial access via an ICS VPN appliance, the actor pivots laterally across systems using compromised credentials, often logging into additional systems via RDP. Their TTPs heavily rely on "living off the land," supplemented by the deployment of webshells, proxy utilities, and file modifications for credential harvesting. Defenders should focus on monitoring for anomalies in VPN appliances, unusual RDP authentication attempts across multiple hosts, and unauthorized file system changes to detect credential theft.
UTA0178
UNC5221Red Dev 61
unknown
While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the incident which primarily consisted of webshells, proxy utilities, and file modifications to allow credential harvesting. Once UTA0178 had access into the network via the ICS VPN appliance, their general approach was to pivot from system to system using compromised credentials. They would then further compromise credentials of users on any new system that was breached, and use these credentials to log into additional systems via RDP. Volexity observed the attacker obtaining credentials in a variety of ways.