UNC5518 is a financially motivated, access-as-a-service threat cluster tracked since June 2024. It compromises legitimate websites and uses illicit advertising and search-engine poisoning to direct visitors to fraudulent CAPTCHA-style verification pages. These ClickFix lures socially engineer victims into pasting and executing malicious PowerShell through the Windows Run dialog, thereby establishing initial access. UNC5518 appears to monetize this access by providing it to downstream threat actors rather than conducting all subsequent intrusion activity itself. Known consumers of this access include UNC5774, which has deployed the CORNFLAKE.V3 backdoor, and UNC4108, which has deployed NetSupport RAT and VOLTMARKER. UNC5518 has no publicly established state-sponsored attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated access-as-a-service broker that compromises legitimate websites at scale to host fake ClickFix pages, then sells or hands resulting footholds to downstream operators. In this case, it is assessed as the ClickFix delivery operator for the NetSupport RAT chain.
Access-as-a-service activity leveraging ClickFix-style social engineering and fake CAPTCHA pages to trick users and establish initial access, then deploying the CORNFLAKE.V3 backdoor.
Access-as-a-service operation using ClickFix via fake CAPTCHA pages to deploy CORNFLAKE.V3 backdoor and broker access.
Financially motivated activity leveraging malvertising/search poisoning to drive victims to fake CAPTCHA pages that trick them into running a malicious PowerShell command, resulting in CORNFLAKE.V3 backdoor deployment and follow-on payload execution (credential harvesting, additional backdoors, AD recon).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.