UNC4990 is a financially motivated threat actor assessed to have operated since at least 2020 and likely to operate from Italy. The actor has targeted organizations in Italy, with additional victimization observed in Europe and the United States, across sectors including health care, transportation, construction, and logistics. UNC4990 is notable for combining broad USB-borne propagation with modular malware and cryptocurrency theft activity. The actor’s operations commonly begin with removable-drive infection and social-engineering-style execution chains that rely on deceptive shortcuts and PowerShell to launch follow-on payloads. A recurring malware component associated with the cluster is EMPTYSPACE, a downloader observed in multiple variants including Python implementations. EMPTYSPACE profiles the host, communicates with multiple command-and-control endpoints, and executes server-supplied payloads in memory. UNC4990 has also used third-party web services to stage encoded content for retrieval during execution. Another core malware family linked to UNC4990 is QUIETBOARD, a Python-based modular backdoor. QUIETBOARD supports arbitrary command execution, host profiling, screenshot capture, repeated command-and-control polling, and execution of additional Python code delivered by the operator. Its removable-media propagation component infects USB drives by hiding legitimate content and replacing it with deceptive launch mechanisms, enabling further spread. QUIETBOARD also includes a clipboard hijacking capability designed to replace copied cryptocurrency wallet addresses with attacker-controlled alternatives, indicating direct crypto-theft activity. Related wallet-replacement activity has also been observed on compromised Italian websites, including sites associated with universities. Observed post-compromise behavior includes persistent beaconing, collection of system and wireless-network information, and in at least one case deployment of an open-source coinminer after extended access. UNC4990’s tradecraft reflects an emphasis on initial access through infected removable media, persistence, payload delivery, in-memory execution, host reconnaissance, and monetization through both cryptocurrency theft and opportunistic follow-on abuse. Known associated malware includes EMPTYSPACE and QUIETBOARD.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.