UNKN is a distinct threat-actor cluster operating a botnet within the Medusa (also known as TangleBot) Android banking-trojan malware-as-a-service ecosystem. The cluster has focused on European victims, particularly in France, Italy, Spain, and the United Kingdom. Medusa campaigns associated with UNKN have used SMS phishing to induce victims to sideload malicious dropper applications masquerading as legitimate applications, including browser, mobile-connectivity, and streaming services. The Medusa payload abuses Android Accessibility Services and provides banking-fraud functionality including keylogging, screen control, SMS manipulation, full-screen overlays, and screenshot capture. Medusa botnets, including UNKN, use centrally managed infrastructure that can dynamically obtain command-and-control addresses from public social-media profiles. UNKN has only a possible, unconfirmed relationship to the similarly named UNKK affiliate tag associated with the RemControl Android banking trojan; available evidence does not establish that they are the same actor. UNKN should also not be conflated with the separately reported REvil operator designation "UNKN" or "Unknown."
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Medusa banking-trojan affiliate possibly linked to UNKK, although Group-IB states that the available evidence does not establish a definitive connection.
Previously attributed affiliate botnet associated with Medusa banking-trojan distribution. It is possibly linked to UNKK, but the report states that available evidence cannot establish a definitive connection.
A distinct threat actor cluster operating a Medusa-associated botnet that delivers malicious Android dropper apps and focuses on European targets, especially France, Italy, Spain, and the UK.
Operator identified as creating the REvil ransomware-as-a-service platform and recruiting affiliates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.