UNC1945, also known as LightBasin, is a suspected Chinese cyber-espionage threat actor tracked by Mandiant and linked to intrusions against telecommunications companies. The group is described as seeking long-term, stealthy unauthorized access to victim networks and has been reported operating since 2016. Reported targeting includes telecommunications operators, as well as managed service providers and organizations in the financial and professional consulting industries. LightBasin activity has been associated with Linux and Oracle Solaris environments. Reported tradecraft includes use of custom tooling, SSH, previously established implants, and movement across telecom infrastructure, including use of external DNS servers in GPRS networks to connect between compromised telecom operators. The group has been reported to target telecom-specific protocols and infrastructure, and to tunnel activity through an SGSN emulator to improve operational security and reduce inspection. Malware and tooling associated in the provided content include the Solaris PAM backdoor SLAPSTICK and TinyShell for command execution and C2 over HTTP. The content also notes Mandiant identified a Solaris PAM vulnerability and stated it would provide more information on how UNC1945 used it. The provided content also states that Mandiant previously linked UNC2891 to UNC1945/LightBasin and that UNC2891 shares tactical overlaps with UNC1945, including Linux/Unix/Solaris-focused tradecraft and use of TinyShell and CAKETAP-related activity in ATM-switching environments. However, the content does not establish that all UNC2891 activity is definitively UNC1945. The content further notes that as of October 2025, CrowdStrike updated prior attribution and reassigned intrusions previously attributed to LightBasin to Liminal Panda, indicating attribution in some reporting has changed. Known aliases in the provided content are LightBasin, Light_Basin, and UNC1945.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromising managed service providers, financial, professional consulting, and telecom industries.
Referenced as a linked/related cluster to UNC2891 per Mandiant; no additional operational details provided in this content beyond the asserted linkage.
Referenced as a cluster previously linked by Mandiant to UNC2891.
Threat actor previously identified compromising managed service providers and targeting the financial and professional consulting industries; mentioned here due to tactical overlaps with UNC2891.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.