UNC2659 is a threat cluster tracked as a DARKSIDE ransomware affiliate active since at least January 2021. The cluster is associated with financially motivated ransomware intrusions and double-extortion operations in which data is stolen prior to encryption. UNC2659 is notable for exploiting CVE-2021-20016 in SonicWall SMA100 SSL VPN appliances to obtain initial access, then progressing from compromise to ransomware deployment in roughly 10 days. Observed UNC2659 tradecraft includes exploitation of internet-facing VPN infrastructure for initial access, use of TeamViewer to maintain persistence, access to administrative interfaces in virtualized environments, and pre-encryption actions intended to reduce recovery options, including disabling snapshot functionality on ESXi-managed systems. The cluster has also been observed downloading tooling from legitimate public sites and using Rclone to exfiltrate large volumes of victim data before deploying DARKSIDE ransomware. These behaviors align with post-compromise enterprise intrusion activity focused on persistence, data theft, and impact. UNC2659 is one of several affiliate-linked clusters associated with the DARKSIDE ransomware-as-a-service ecosystem. DARKSIDE operators provided ransomware tooling and leak-site support to affiliates in exchange for a share of ransom proceeds, enabling affiliates such as UNC2659 to conduct double-extortion attacks across multiple sectors and countries. No separate sub-groups or widely used aliases for UNC2659 are established beyond its tracking designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DarkSide-linked affiliate cluster that gains initial access via SonicWall SMA100 SSL VPN exploitation, may disable MFA, uses TeamViewer for persistence, and exfiltrates files before encryption.
A DARKSIDE affiliate cluster that gained initial access by exploiting SonicWall SMA100, established persistence with remote administration tools, exfiltrated large volumes of data, and deployed ransomware affecting virtualized environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.