UNC4393 Goes Gently into the SILENTNIGHT
ID: b74a313e-baa5-5fcd-9949-26a5949b7f38
STIX ID: report--b74a313e-baa5-5fcd-9949-26a5949b7f38
Feed Name: Google Cloud Threat Intelligence
Mandiant tracks UNC4393 as a financially motivated threat cluster responsible for deploying BASTA ransomware since 2022; the report outlines the group's private affiliate model, rapid operational tempo (median time to ransom ~42 hours), reliance on initial access brokers (historically QAKBOT, later DARKGATE and SILENTNIGHT), multiple supporting malware families (e.g., SYSTEMBC, KNOTWRAP, DAWNCRY, KNOTROCK), and notable TTPs including DNS beaconing and living-off-the-land techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
