Threat actor
UNC1878
Last fetched
UNC1878 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 64 techniques.
Description
UNC1878 is a financially motivated threat actor that monetizes network access via the deployment of RYUK ransomware. Earlier this year, Mandiant published a blog on a fast-moving adversary deploying RYUK ransomware, UNC1878. Shortly after its release, there was a significant decrease in observed UNC1878 intrusions and RYUK activity overall almost completely vanishing over the summer. But beginning in early fall, Mandiant has seen a resurgence of RYUK along with TTP overlaps indicating that UNC1878 has returned from the grave and resumed their operations.
Techniques by tactic
Persistence
- T1053.005 · Scheduled Task
- T1078 · Valid Accounts
- T1078.002 · Domain Accounts
- T1112 · Modify Registry
- T1133 · External Remote Services
- T1136.001 · Local Account
- T1136.002 · Domain Account
- T1197 · BITS Jobs
- T1543.003 · Windows Service
- T1547.001 · Registry Run Keys / Startup Folder
- T1547.004 · Winlogon Helper DLL
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to UNC1878 today — this states the absence of a published link, not that UNC1878 has no infrastructure.
References
- https://twitter.com/anthomsec/status/1321865315513520128
- https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html
- https://gist.github.com/aaronst/6aa7f61246f53a8dd4befea86e832456
- https://www.youtube.com/watch?v=CgDtm05qApE
- https://www.fireeye.com/blog/threat-research/2020/03/the-cycle-of-adversary-pursuit.html
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from UNC1878 into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.