UNC1040 is a UNC-tracked intrusion cluster associated in malware-clustering references with hook-related tooling. It is linked to the malware family WATERFAIRY through build-artifact and keyword-based analytic associations. Available high-confidence information indicates use of tradecraft involving code hooking and related post-compromise tooling, but the cluster is otherwise sparsely characterized in the supplied facts. There is no directly supported evidence here to attribute UNC1040 to a specific nation state or country of origin, define a broader alias set, identify confirmed victim geography, or establish a consistent sectoral targeting pattern. Based on the directly supported association, UNC1040 should be understood as a limited-confidence tracked cluster connected to hook-centric malware activity rather than a comprehensively profiled threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.