UNC is a temporary, uncategorized cluster designation used by Mandiant for intrusion activity that has not yet been fully attributed to a named threat actor or intrusion set. In the context of exploitation of CVE-2023-4966 in Citrix NetScaler ADC and NetScaler Gateway, multiple distinct UNC clusters were tracked exploiting the vulnerability to steal authenticated session material and hijack legitimate user sessions, enabling access without passwords or multi-factor authentication. Observed follow-on activity included post-compromise reconnaissance in Active Directory environments, internal network scanning, credential theft through LSASS memory dumping, lateral movement via RDP, and deployment of a .NET backdoor known as FREEFIRE alongside remote management tools such as Atera, AnyDesk, and Splashtop. The tracked UNC clusters showed limited tooling overlap and no shared infrastructure, indicating multiple separate actors rather than a single cohesive group. Because UNC is a placeholder designation rather than a stable actor identity, origin, long-term targeting patterns, and dominant motivation are not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.