UNC6418 is an unattributed threat actor tracked for targeted intelligence-gathering activity associated with phishing operations focused on Ukraine. The actor has been observed using generative AI tooling to accelerate reconnaissance, specifically to identify sensitive account credentials and email addresses associated with intended victims. This activity indicates a workflow in which AI-assisted target profiling and information collection support subsequent social-engineering operations. Observed tradecraft centers on reconnaissance and initial access preparation through phishing. UNC6418 has used AI-assisted research to compile targeting information and then moved to active phishing against the identified accounts. Public reporting does not attribute UNC6418 to a specific state or criminal organization at high confidence, and no confirmed sub-groups or widely used aliases beyond the UNC6418 tracking name are established in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used Google Gemini for targeted intelligence gathering (credentials and email addresses), followed by a phishing campaign focused on Ukraine.
Used Gemini to support targeted intelligence gathering focused on identifying sensitive account credentials and email addresses.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.