UNC385 is an uncategorized intrusion cluster tracked under the UNC naming convention. High-confidence reporting links this cluster to installer-related malware development or use, based on associations with the keyword category "install" in malware clustering and build-artifact analysis. Malware families associated with this cluster in that context include SCRAPMINT and related installer-oriented tooling. The available evidence supports only limited characterization: UNC385 has been observed in relation to malware installation activity, but there is insufficient corroborated information here to attribute the cluster to a specific country, define its victimology, or describe a broader operational profile such as espionage, financially motivated intrusion, or ransomware operations. No confirmed aliases, sub-groups, or nation-state attribution are established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.