UNC4393 is a financially motivated cybercrime threat cluster and the primary known operator deploying BASTA ransomware. Active since at least early 2022 and tracked since mid-2022, the group is associated with a fast-paced intrusion model characterized by rapid progression from initial access to ransomware deployment, with observed median time to ransom of roughly 42 hours. UNC4393 is assessed to operate within a private, tightly controlled affiliate ecosystem around BASTA rather than a broadly advertised ransomware-as-a-service model. UNC4393 has relied heavily on externally obtained initial access. Early operations predominantly followed QAKBOT infections, commonly delivered through phishing and related delivery chains. After disruption of QAKBOT infrastructure in 2023, the group shifted to other access sources, including DARKGATE delivery activity and later SILENTNIGHT intrusions, with observed delivery trends expanding beyond phishing to malvertising. The actor also benefits from partnerships or purchased access in underground ecosystems. Post-compromise activity combines living-off-the-land techniques with custom tooling and commodity malware. A consistently observed foothold mechanism is DNS BEACON activity, including reuse of distinctive naming conventions. Associated tooling includes SYSTEMBC and PORTYARD tunnelers, KNOTWRAP and DAWNCRY memory-only droppers, KNOTROCK for symbolic-link abuse on network shares, and COGSCAN for network reconnaissance. SILENTNIGHT-linked access has also exposed capabilities relevant to credential targeting, keylogging, screenshot capture, and broader system control. Operationally, UNC4393 conducts rapid reconnaissance, data exfiltration, and actions on objectives before encryption. The group has also been associated with attacks on backup infrastructure intended to inhibit recovery, including deleting backup routines, erasing data, and tampering with permissions. BASTA itself is used for file encryption and has been observed deleting volume shadow copies. UNC4393 is tracked separately from other BASTA-related clusters such as UNC3973 due to distinct tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.