LightBasin, tracked by Mandiant as UNC1945, is a sophisticated threat actor associated primarily with long-term intrusions into telecommunications environments. Its operations have targeted mobile-operator infrastructure, including Linux and Oracle Solaris systems and systems supporting roaming and GPRS-related services. The group has used custom implants and backdoors, including SLAPSTICK and GTPDoor, to maintain covert access, execute commands, and communicate through telecommunications protocols and infrastructure. It has leveraged compromised operator environments and roaming-network relationships to move between telecommunications networks, demonstrating specialized knowledge of carrier technology. LightBasin tradecraft includes persistence through authentication-related backdoors and deployed implants, defense evasion through process masquerading and covert protocol tunneling, and lateral movement through trusted or interconnected telecommunications infrastructure. It has also been associated with exploitation of a Solaris PAM vulnerability. Reporting has linked LightBasin activity to managed-service-provider compromises and targeting of financial and professional-services organizations. UNC2891 has substantial tooling and tactical overlaps with LightBasin, but public reporting has not established conclusive attribution of both clusters to a single actor. Some later reporting reassigned certain telecommunications intrusions previously attributed to LightBasin to Liminal Panda; consequently, attribution for individual overlapping campaigns should be assessed carefully.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a tactically overlapping cluster associated with UNC2891, but not the primary subject of the report.
Compromising managed service providers, financial, professional consulting, and telecom industries.
Referenced as a linked/related cluster to UNC2891 per Mandiant; no additional operational details provided in this content beyond the asserted linkage.
Referenced as a cluster previously linked by Mandiant to UNC2891.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.