Skip to main content
Mallory
5 malware families

UNC2465

Also known asUNC2465

UNC2465 is a financially motivated threat cluster and former/current DARKSIDE affiliate active since at least April 2019. Reporting also describes activity since at least March 2020. The group has been linked to complex extortion and ransomware operations and has used DARKSIDE and LOCKBIT ransomware, including a hybrid model combining ransomware with Tor-based data-leak extortion. UNC2465 is strongly associated with the PowerShell-delivered .NET backdoor SMOKEDHAM, which has been central to its intrusions. SMOKEDHAM supports arbitrary .NET or PowerShell command execution, screen capture, keylogging, screenshot generation, and encrypted C2 communications; reporting also notes RC4-encrypted communications, dynamic C2 URLs, and domain fronting, including use of Cloudflare Workers and Azure Edge-hosted infrastructure. UNC2465 has delivered SMOKEDHAM via phishing emails, malicious LNK files hosted through legitimate services such as Google Drive and Dropbox, and trojanized software installers. Mandiant documented a software supply-chain intrusion in which trojanized Nullsoft installers for CCTV-related software were placed on a legitimate vendor website; execution led to a multi-stage infection chain involving a fake MSHTA, PowerShell, and SMOKEDHAM. Observed UNC2465 tradecraft includes use of NGROK, including a legitimate ngrok binary renamed to conhost.exe and executed with ngrok.yml, to expose internal services and bypass firewalls; UltraVNC for remote access; Cobalt Strike Beacon; keyloggers; credential harvesting via LSASS dumping; and lateral movement via RDP. Additional tooling reported across incidents includes Advanced IP Scanner, BLOODHOUND, Mimikatz, PsExec, cron jobs, and WMI. Persistence mechanisms include registry Run keys and Startup-folder LNK files; one report also states the attackers created and hid a new local administrator account. In one observed intrusion, UNC2465 established an ngrok tunnel and began lateral movement in less than 24 hours, then returned days later to deploy a keylogger, Cobalt Strike, and dump LSASS. UNC2465 has targeted backup platforms, deleting backup routines, erasing data, and tampering with user permissions to inhibit recovery. Reporting notes that the group has demonstrated the ability to switch between ransomware and malware affiliate programs, and Mandiant observed former DARKSIDE affiliates, including UNC2465-linked activity, shifting to other RaaS ecosystems such as REvil/SODINOKIBI. Known alias in the provided content: unc2465.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics48 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1189
Drive-by Compromise
T1195
Supply Chain Compromise
T1195.002
Compromise Software Supply Chain
T1566×3
Phishing
T1566.002
Spearphishing Link
TA0002
Execution
2 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.005
Visual Basic
T1059.009
Cloud API
TA0003
Persistence
2 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
3 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1068
Exploitation for Privilege Escalation
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
1 technique
T1036
Masquerading
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1003.001
LSASS Memory
T1056
Input Capture
T1056.001×2
Keylogging
TA0007
Discovery
2 techniques
T1046
Network Service Discovery
T1482
Domain Trust Discovery
TA0008
Lateral Movement
2 techniques
T1021
Remote Services
T1021.001
Remote Desktop Protocol
T1021.002
SMB/Windows Admin Shares
T1021.005
VNC
T1021.006
Windows Remote Management
T1570
Lateral Tool Transfer
TA0009
Collection
3 techniques
T1056
Input Capture
T1056.001×2
Keylogging
T1113
Screen Capture
T1560
Archive Collected Data
TA0011
Command and Control
5 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1090.002
External Proxy
T1090.004
Domain Fronting
T1105×2
Ingress Tool Transfer
T1219
Remote Access Tools
T1572
Protocol Tunneling
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
TA0040
Impact
2 techniques
T1486×2
Data Encrypted for Impact
T1657
Financial Theft
IOCS

Observables

30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

security online infoNews
Nov 28, 2024
SMOKEDHAM Backdoor: UNC2465’s Stealth Weapon for Extortion and Ransomware Campaigns

Financially motivated intrusion activity leveraging the SMOKEDHAM backdoor for initial access, persistence, reconnaissance, lateral movement, and subsequent extortion/ransomware deployment; historically linked to DARKSIDE and later shifting to LOCKBIT.

Read more
fireeyeNews
Jun 16, 2021
Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise

UNC2465 is a DARKSIDE ransomware affiliate known for conducting supply chain attacks, specifically by Trojanizing software installers on legitimate websites to gain initial access. They use a variety of malware and tools for persistence, lateral movement, credential harvesting, and remote access, and have demonstrated the ability to switch between different ransomware and malware offerings as affiliate programs change.

Read more
zdnet zero dayNews
May 12, 2021
Researchers track down five affiliates of DarkSide ransomware service | ZDNET

DarkSide-linked cluster that uses phishing to deliver Smokedham and later deploys DarkSide ransomware, with long dwell times and use of tunneling utilities to expose remote desktop services.

Read more
fireeyeNews
May 11, 2021
Shining a Light on DARKSIDE Ransomware Operations

A DARKSIDE-associated intrusion cluster using phishing-delivered SMOKEDHAM infections, long dwell times, credential theft, remote access tunneling, lateral movement, and DARKSIDE deployment, sometimes accompanied by direct victim phone calls.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping33

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables30

Domains, IPs, and hashes tied to this actor, refreshed continuously.