UNC124 is an uncategorized intrusion cluster tracked in association with malware development and deployment activity involving shell-oriented tooling. It appears in malware-clustering and attribution datasets that map developer build-path keywords and related artifacts to malware families and actor clusters. UNC124 is specifically associated with the shell keyword category, indicating observed overlap with malware or tooling characterized as shell-based payloads or backdoor components. High-confidence reporting available here does not establish UNC124 as a named nation-state program, financially motivated crime group, or ransomware operation. It also does not provide corroborated detail on victimology, campaign chronology, geographic origin, or a broader malware portfolio beyond the shell-related association. No sub-groups or widely used alternative aliases are established in the available facts. Based on the available evidence, UNC124 should be treated as a tracked cluster with limited public attribution and sparse confirmed operational detail.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.