UNC1149 is an uncategorized intrusion cluster tracked under Mandiant’s UNC naming convention. High-confidence reporting in the available data links UNC1149 to malware and tooling associated with payload delivery and shell functionality, and also to injection-related tradecraft. Specifically, the cluster is associated with the malware families RANSACK and LIMITLESS in payload-related contexts, and with RANSACK in shell-related contexts. UNC1149 is also linked to injection-oriented activity through keyword-based clustering that maps the group to malware and development artifacts suggestive of code injection tradecraft. Based on the available evidence, UNC1149 demonstrates post-compromise capability centered on payload execution, shell access, and process injection. No reliable attribution to a nation state, criminal ecosystem, source country, victim geography, or specific industry vertical is established from the supplied facts alone.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.