UNC1756 is a persona or sub-group publicly associated with Conti’s 2022 ransomware campaign against Costa Rican government entities. The name appeared in Conti’s public communications claiming responsibility for the intrusion into Costa Rica’s Ministry of Finance and related government targets, and was also used on the Russian-language Exploit forum to solicit access to Costa Rican networks while specifying collaboration with Russian-speaking partners. Available reporting ties UNC1756 to the Costa Rica operation specifically, but does not establish it as an independent long-standing intrusion set separate from Conti. The activity attributed to UNC1756 centered on financially motivated ransomware and extortion operations against Costa Rican public-sector organizations. Reported behavior included seeking initial access to government networks, conducting repeated intrusion attempts across multiple state entities, stealing large volumes of data, and using public leak-and-pressure tactics after ransom demands were refused. The operation involved ransom escalation and publication of stolen data, consistent with double-extortion tradecraft associated with Conti. Costa Rican government bodies were the primary known targets in the available evidence. UNC1756 should be understood as a threat actor label linked to the Conti ecosystem rather than a fully distinct, well-profiled group. High-confidence aliases beyond the lowercase styling variant are not established in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster that claimed responsibility for the Costa Rica finance ministry intrusion via Conti’s leak site, demanded $10M then $20M, and published 672GB of data after non-payment.
Named activity cluster/handle associated with the Costa Rica intrusion attributed by Conti; used Russian-language cybercrime forum Exploit to solicit/purchase access to Costa Rican networks prior to the disclosed compromise.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.