Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
11 malware families

UNC4393

Also known asUNC4393

UNC4393 is a financially motivated threat cluster tracked by Mandiant since mid-2022 and assessed to have likely been active since early 2022. It is described as the primary active user of BASTA ransomware and is associated with Basta ransomware operations. Mandiant assesses that BASTA operates through a private, tightly controlled affiliate model rather than a publicly marketed ransomware-as-a-service program, with UNC4393 conducting most observed deployments; UNC3973 is tracked separately due to distinct TTPs. UNC4393 has primarily relied on initial access from QAKBOT infections, especially in earlier activity, with QAKBOT commonly delivered via phishing emails, malicious links or attachments, and HTML smuggling chains. After the late-2023 disruption of QAKBOT infrastructure, UNC4393 was observed leveraging access associated with DARKGATE delivery via phishing and later following successful SILENTNIGHT intrusions, with SILENTNIGHT campaigns reportedly shifting toward malvertising. The cluster is noted for a rapid operational tempo, with a median time to ransom of approximately 42 hours, and for quickly conducting reconnaissance, data exfiltration, and actions on objectives. After gaining access, UNC4393 combines living-off-the-land techniques with custom malware. A consistently observed foothold mechanism is DNS BEACON, including reuse of distinctive DNS beacon naming conventions. Malware and tooling associated with UNC4393 in the provided content include BASTA, SYSTEMBC, KNOTWRAP, KNOTROCK, DAWNCRY, PORTYARD, and COGSCAN. BASTA is a C++ ransomware family that encrypts local files and can delete volume shadow copies. SYSTEMBC and PORTYARD are tunnelers; KNOTWRAP and DAWNCRY are memory-only droppers; KNOTROCK is a .NET utility used to create symbolic links on network shares and execute what is presumed to be a BASTA payload; and COGSCAN is a .NET reconnaissance assembly used to enumerate hosts on the network. The content also states that UNC4393 has been observed targeting backup platforms, deleting backup routines, erasing data, and tampering with user permissions to prevent recovery.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics28 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0004
Privilege Escalation
1 technique
T1055
Process Injection
TA0005
Stealth
3 techniques
T1027
Obfuscated Files or Information
T1027.006
HTML Smuggling
T1027.007
Dynamic API Resolution
T1055
Process Injection
T1620
Reflective Code Loading
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1056.001
Keylogging
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
TA0007
Discovery
1 technique
T1016
System Network Configuration Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0009
Collection
3 techniques
T1056
Input Capture
T1056.001
Keylogging
T1074
Data Staged
T1113
Screen Capture
TA0011
Command and Control
4 techniques
T1071
Application Layer Protocol
T1071.004
DNS
T1090
Proxy
T1105
Ingress Tool Transfer
T1568
Dynamic Resolution
T1568.002
Domain Generation Algorithms
TA0040
Impact
2 techniques
T1486
Data Encrypted for Impact
T1490
Inhibit System Recovery
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping22

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal11

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.