Skip to main content
Mallory
22 malware familiesExploits CVEs in the wild

UNC2447

Also known asUNC2447

UNC2447 is a financially motivated threat group / uncategorized cluster tracked by Mandiant and linked across intrusions by shared SOMBRAT and Cobalt Strike BEACON infrastructure observed in five intrusions between November 2020 and February 2021. Mandiant reported the group exploited the SonicWall SMA 100 series zero-day CVE-2021-20016 prior to patching and deployed the SOMBRAT backdoor in intrusions that culminated in FIVEHANDS ransomware extortion. Mandiant also observed evidence of UNC2447-affiliated actors previously using RAGNARLOCKER ransomware, and noted suspected overlap between HELLOKITTY and FIVEHANDS affiliate activity, while cautioning that not all SOMBRAT or FIVEHANDS incidents necessarily map to UNC2447 due to tool sharing and affiliate program dynamics. The group has been observed targeting organizations in Europe and North America. Observed tradecraft includes use of WARPRISM, a PowerShell dropper that loads payloads directly into memory; Cobalt Strike BEACON HTTPSSTAGER for persistence and HTTPS C2; and SOMBRAT, a 64-bit Windows backdoor with plugin-based architecture that communicates with configurable C2 over DNS, TLS-encrypted TCP, and potentially WebSockets. Mandiant described a hardened SOMBRAT variant with stripped compiler metadata, XOR-encoded inlined strings, and launcher/resource files typically installed under C:\ProgramData\Microsoft. UNC2447 has also been observed using ADFIND, BLOODHOUND, MIMIKATZ, PCHUNTER, RCLONE, ROUTERSCAN, S3BROWSER, ZAP, and 7ZIP during reconnaissance and exfiltration, and may tamper with Windows security settings, firewall rules, and antivirus protection. FOXGRABBER, a utility for harvesting Firefox credential files, was also associated with this activity. Mandiant reported UNC2447 monetized intrusions through FIVEHANDS ransomware and additional pressure tactics including threats of media exposure and offering stolen data for sale on hacker forums. Cisco later assessed with moderate-to-high confidence that its May 2022 intrusion was conducted by an initial access broker with ties to UNC2447, Lapsus$, and Yanluowang ransomware operators. In that incident, the actor used vishing and MFA fatigue to obtain VPN access, then deployed tools including LogMeIn, TeamViewer, Cobalt Strike, PowerSploit, Mimikatz, and Impacket, created persistence, dumped credentials, moved laterally, and exfiltrated limited data; Cisco stated no ransomware was deployed. Cisco also described UNC2447 as having a nexus to Russia and being known for ransomware and double extortion. Known aliases directly provided in the content are limited to UNC2447.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • technology
MITRE ATT&CK

Tradecraft

14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics18 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1190
Exploit Public-Facing Application
TA0002
Execution
1 technique
T1129
Shared Modules
TA0005
Stealth
1 technique
T1027
Obfuscated Files or Information
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
TA0007
Discovery
3 techniques
T1018
Remote System Discovery
T1057
Process Discovery
T1069
Permission Groups Discovery
T1069.002
Domain Groups
TA0009
Collection
1 technique
T1560
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1071.004
DNS
T1105
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
IOCS

Observables

33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyberscoopNews
Nov 7, 2025
Russian national pleads guilty to breaking into networks for Yanluowang ransomware attacks

Referenced as an associated cluster tied (via an initial access broker) to Yanluowang-related activity; specific operations/TTPs are not detailed in this content beyond the stated linkage.

Read more
talos intelligence blogNews
Aug 10, 2022
Cisco Talos shares insights related to recent cyber attack on Cisco

Financially motivated intrusion activity consistent with an initial access broker: vishing/MFA fatigue to obtain VPN access, enrollment of new MFA devices, privilege escalation to admin, extensive credential dumping (NTDS/SAM/LSASS), lateral movement via RDP/Citrix, log clearing/defense evasion, limited exfiltration (Box folder + AD auth data), and repeated re-entry attempts post-eviction. Content notes historical linkage to ransomware operations and double-extortion tradecraft, though no ransomware was deployed in this incident.

Read more
talos intelligence blogNews
Aug 10, 2022
Cisco Talos shares insights related to recent cyber attack on Cisco

Financially motivated intrusion activity consistent with an initial access broker: vishing/MFA fatigue to obtain VPN access, enrollment of new MFA devices, privilege escalation to admin, extensive credential dumping (NTDS/SAM/LSASS), lateral movement via RDP/Citrix, log clearing/defense evasion, limited exfiltration (Box folder + AD auth data), and repeated re-entry attempts post-eviction. Content notes historical linkage to ransomware operations and double-extortion tradecraft, though no ransomware was deployed in this incident.

Read more
ncc group researchNews
Jan 10, 2022
NCC Group’s 2021 Annual Research Report

UNC2447 is associated with the deployment of FiveHands ransomware and is linked to sophisticated ransomware campaigns.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping14

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal22

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables33

Domains, IPs, and hashes tied to this actor, refreshed continuously.

UNC2447 | Mallory