UNC6512 is a newly emergent threat operation tracked by Google Threat Intelligence Group. Based on the provided reporting, it has been linked to exploitation of the Windows Server Update Service (WSUS) vulnerability CVE-2025-59287, a critical deserialization of untrusted data flaw. After gaining initial access via this vulnerability, UNC6512 conducted reconnaissance on compromised hosts and related environments and exfiltrated data. Reported victim organizations affected by the broader exploitation activity included technology firms, universities, manufacturers, and healthcare organizations, with most victims located in the United States. The content does not provide a confirmed nation-state attribution or additional aliases/sub-groups beyond UNC6512.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly identified intrusion activity cluster leveraging a critical WSUS untrusted deserialization vulnerability (CVE-2025-59287) to compromise vulnerable WSUS instances for reconnaissance and data exfiltration; activity appears consistent with an initial testing/reconnaissance phase preceding follow-on intrusion opportunities.
Exploitation of the critical Windows Server Update Service vulnerability CVE-2025-59287 to gain initial access, conduct reconnaissance on compromised hosts and related environments, and exfiltrate data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.