logo

UNC4393 Goes Gently into the SILENTNIGHT

ID: b74a313e-baa5-5fcd-9949-26a5949b7f38

STIX ID: report--b74a313e-baa5-5fcd-9949-26a5949b7f38

Feed Name: Google Cloud Threat Intelligence

Threat Score
78/100

Date Published: 2024-07-29

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant tracks UNC4393 as a financially motivated threat cluster responsible for deploying BASTA ransomware since 2022; the report outlines the group's private affiliate model, rapid operational tempo (median time to ransom ~42 hours), reliance on initial access brokers (historically QAKBOT, later DARKGATE and SILENTNIGHT), multiple supporting malware families (e.g., SYSTEMBC, KNOTWRAP, DAWNCRY, KNOTROCK), and notable TTPs including DNS beaconing and living-off-the-land techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.