UNC2465
UNC2465 is a financially motivated threat cluster and former/current DARKSIDE affiliate active since at least April 2019. Reporting also describes activity since at least March 2020. The group has been linked to complex extortion and ransomware operations and has used DARKSIDE and LOCKBIT ransomware, including a hybrid model combining ransomware with Tor-based data-leak extortion. UNC2465 is strongly associated with the PowerShell-delivered .NET backdoor SMOKEDHAM, which has been central to its intrusions. SMOKEDHAM supports arbitrary .NET or PowerShell command execution, screen capture, keylogging, screenshot generation, and encrypted C2 communications; reporting also notes RC4-encrypted communications, dynamic C2 URLs, and domain fronting, including use of Cloudflare Workers and Azure Edge-hosted infrastructure. UNC2465 has delivered SMOKEDHAM via phishing emails, malicious LNK files hosted through legitimate services such as Google Drive and Dropbox, and trojanized software installers. Mandiant documented a software supply-chain intrusion in which trojanized Nullsoft installers for CCTV-related software were placed on a legitimate vendor website; execution led to a multi-stage infection chain involving a fake MSHTA, PowerShell, and SMOKEDHAM. Observed UNC2465 tradecraft includes use of NGROK, including a legitimate ngrok binary renamed to conhost.exe and executed with ngrok.yml, to expose internal services and bypass firewalls; UltraVNC for remote access; Cobalt Strike Beacon; keyloggers; credential harvesting via LSASS dumping; and lateral movement via RDP. Additional tooling reported across incidents includes Advanced IP Scanner, BLOODHOUND, Mimikatz, PsExec, cron jobs, and WMI. Persistence mechanisms include registry Run keys and Startup-folder LNK files; one report also states the attackers created and hid a new local administrator account. In one observed intrusion, UNC2465 established an ngrok tunnel and began lateral movement in less than 24 hours, then returned days later to deploy a keylogger, Cobalt Strike, and dump LSASS. UNC2465 has targeted backup platforms, deleting backup routines, erasing data, and tampering with user permissions to inhibit recovery. Reporting notes that the group has demonstrated the ability to switch between ransomware and malware affiliate programs, and Mandiant observed former DARKSIDE affiliates, including UNC2465-linked activity, shifting to other RaaS ecosystems such as REvil/SODINOKIBI. Known alias in the provided content: unc2465.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Observables
30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated intrusion activity leveraging the SMOKEDHAM backdoor for initial access, persistence, reconnaissance, lateral movement, and subsequent extortion/ransomware deployment; historically linked to DARKSIDE and later shifting to LOCKBIT.
UNC2465 is a DARKSIDE ransomware affiliate known for conducting supply chain attacks, specifically by Trojanizing software installers on legitimate websites to gain initial access. They use a variety of malware and tools for persistence, lateral movement, credential harvesting, and remote access, and have demonstrated the ability to switch between different ransomware and malware offerings as affiliate programs change.
DarkSide-linked cluster that uses phishing to deliver Smokedham and later deploys DarkSide ransomware, with long dwell times and use of tunneling utilities to expose remote desktop services.
A DARKSIDE-associated intrusion cluster using phishing-delivered SMOKEDHAM infections, long dwell times, credential theft, remote access tunneling, lateral movement, and DARKSIDE deployment, sometimes accompanied by direct victim phone calls.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.