UNC1120 is a UNC-tracked intrusion cluster with limited publicly available characterization. It has been associated with spyware-related activity in malware-clustering and tradecraft-correlation datasets, specifically through linkage to the keyword category "spy." The cluster has been observed in association with malware families including DUSTYSKY, OFFTRACK, SCRAPMINT, FINSPY, LOCKLOAD, and WINDOLLAR. Based on the available evidence, UNC1120 is connected to espionage-oriented tooling rather than ransomware or disruptive operations. High-confidence reporting in the supplied facts does not establish nation-state attribution, organizational structure, sub-groups, geographic origin, victim geography, or specific sector targeting. Observed tradecraft support is presently limited to spyware-related post-compromise activity, and broader lifecycle capabilities should be treated as not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.