UNC5774 is a financially motivated threat cluster that uses the CORNFLAKE backdoor family as a loader for follow-on payloads. The group has been observed leveraging access obtained through UNC5518's ClickFix-based access-as-a-service operation, in which victims are socially engineered into executing malicious commands from fraudulent CAPTCHA pages. CORNFLAKE.V3, attributed to UNC5774, is available in JavaScript and PHP variants and can retrieve and execute shell commands, executables, and DLLs. It collects basic host information and transmits it over HTTP, can proxy command-and-control traffic through Cloudflare Tunnels, and establishes persistence through a Windows Registry Run key. CORNFLAKE.V3 is an evolution of CORNFLAKE.V2 and earlier C-based CORNFLAKE downloader variants.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated downstream customer of UNC5518 mentioned as contextual attribution background; it is not assessed as the operator of the NetSupport RAT activity described here.
Uses initial access obtained by UNC5518 (access brokerage/hand-off implied) for follow-on operations; no further details provided in the content.
UNC5774 is a financially motivated group that uses the CORNFLAKE backdoor to deploy additional malicious payloads after gaining access via UNC5518's initial infection vector.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.