Skip to content

Threat actor

UNC3973

Last fetched

UNC3973 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

UNC3973 is a financially motivated threat actor tracked by Mandiant, distinguished from the broader BASTA ransomware ecosystem (primarily tracked as UNC4393) due to its unique operational characteristics and TTPs. This actor has demonstrated a specific focus on supply chain compromises, as evidenced by their June campaign targeting credit unions in western Canada via a compromised managed service provider (MSP). UNC3973 leverages unauthorized service accounts with elevated privileges, specifically domain administrator accounts shared between the compromised MSP and the target organizations, to gain initial access.This actor's post-exploitation activity includes attempts to disable security controls and deploy the SYSTEMBC tunneler for command and control (C2) communication, followed by attempts to deploy BASTA ransomware. While their attempts to deploy both SYSTEMBC and BASTA have been observed, these were thankfully thwarted by endpoint security solutions in observed instances. The targeted, supply chain-enabled nature of UNC3973's intrusions, coupled with its use of privileged shared accounts and attempts at deploying BASTA, all suggest that it is an exclusive group, perhaps even affiliates working closely with or possibly operating under the direct control, BASTA ransomware operators. This group's ability to exploit centralized access points, like MSPs, represents a significant threat to organizations reliant on third-party providers.

Techniques by tactic

No ATT&CK techniques are recorded for UNC3973 in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to UNC3973 today — this states the absence of a published link, not that UNC3973 has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from UNC3973 into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.