UNC1197 is a UNC-tracked intrusion cluster with limited public characterization. It has been associated with malware and tooling linked to hook- and injection-related functionality, indicating post-compromise tradecraft focused on manipulating process execution and intercepting or redirecting application behavior. Available reporting ties the cluster to malware observed in a hook-related keyword grouping, but does not provide sufficient high-confidence detail on its sponsorship, geographic origin, victimology, or broader operational history. Publicly available information in this context is insufficient to confidently assess whether UNC1197 is financially motivated, state-directed, or part of a larger named intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.