logo

Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

ID: 94e54f46-cbae-5710-b0bf-ecffb9ee3627

STIX ID: report--94e54f46-cbae-5710-b0bf-ecffb9ee3627

Feed Name: Threat Intelligence

Threat Score
75/100

Date Published: 2025-05-06

Date Updated: 2026-04-27

Author: Mandiant

...
...

This report describes observed UNC3944 activity focused on help-desk impersonation and identity/privilege abuse, enumerates reconnaissance and lateral movement techniques (including ADRecon, ADExplorer, SharpHound), and provides comprehensive mitigation and detection recommendations across authentication, MFA registration controls, administrative role hardening, endpoint and network segmentation, PAM/backup protections, and monitoring rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.