UNC229 is an uncategorized intrusion cluster tracked in association with malware-development and post-compromise tooling references. High-confidence reporting links UNC229 to tooling observed under installer- and shell-related categories, indicating use of malware capable of installation and interactive shell or command-execution functionality. The available evidence supports only limited characterization: UNC229 appears in clustering and attribution datasets alongside numerous other UNC and APT designations, but no corroborated public details are provided here on its sponsorship, campaign history, victimology, geography, or relationship to a named nation-state or financially motivated program. Based on the directly supported associations, UNC229 has been observed in connection with malware or tooling used for installation/persistence-related activity and shell-based post-exploitation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.