UNC4466 is identified as an affiliate of the ALPHV ransomware-as-a-service operation, also known as BlackCat and Noberus. As an ALPHV affiliate, UNC4466 is associated with financially motivated ransomware activity conducted under a RaaS model in which affiliates carry out intrusions while the core operators maintain the malware and extortion infrastructure. ALPHV is a prominent multi-platform ransomware operation active since at least late 2021 and known for using Rust to support broad cross-platform deployment and defense evasion. Activity associated with ALPHV affiliates includes double extortion, combining system encryption with theft of victim data and threats to publish stolen information on leak sites. The broader ALPHV ecosystem has targeted Windows, Linux, VMware ESXi, and network-attached storage environments, and has incorporated features such as Safe Mode reboot-based encryption, updated Linux encryption workflows, ARM-compatible builds, and custom exfiltration tooling. Tradecraft associated with ALPHV affiliates includes multiple initial access routes such as use of valid accounts, exploitation of exposed remote services and public-facing vulnerabilities, social engineering, and access obtained through brokers. Post-compromise behavior associated with the ALPHV ecosystem includes data exfiltration, enterprise-wide ransomware deployment, and extortion operations backed by leak-site pressure. UNC4466 should therefore be understood as part of a financially motivated affiliate ecosystem rather than as an independent nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.