UNC2633 is a distribution threat cluster associated with delivering QAKBOT and enabling downstream financially motivated intrusions, including BASTA ransomware operations. It has been observed exploiting CVE-2022-30190 (Follina) to distribute QAKBOT and has also been linked to broader QAKBOT infection chains commonly delivered through phishing and related delivery mechanisms. UNC2633 functions primarily as an initial-access and malware-distribution facilitator rather than as the principal ransomware operator. UNC2633 is notable for providing access later used by other clusters, especially UNC4393, which overwhelmingly relied on initial access from UNC2633 and UNC2500 QAKBOT infections during earlier BASTA activity. In this role, UNC2633 contributed to intrusion chains that progressed from malware delivery to rapid post-compromise operations, including reconnaissance, data theft, and ransomware deployment by follow-on actors. The cluster is therefore best understood as part of the criminal access ecosystem surrounding QAKBOT-enabled ransomware and extortion activity. High-confidence reporting ties UNC2633 to exploitation for malware distribution and to initial-access operations supporting financially motivated campaigns. Available information directly supports malware delivery and initial compromise activity, but does not by itself establish UNC2633 as the core operator of BASTA or as a standalone ransomware brand.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.