UNC2165 Targets Hybrid Environments with Ransomware (Campaign)
ID: ef18909f-776f-5f33-aed5-211328475922
STIX ID: report--ef18909f-776f-5f33-aed5-211328475922
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-01-21
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
UNC2165 conducted a hybrid-environment intrusion: initial access via a FAKEUPDATES infection, persistent access with VIPERTUNNEL, reconnaissance and AV disruption, exfiltration of Azure blob data to attacker-controlled cloud servers, and deployment of RANSOMHUB ransomware across on‑premises Windows (via GPO-scheduled tasks) and Linux in Azure (via run command). The operation combined data theft and disruptive ransomware activity across cloud and on‑prem systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
