UNC2726, also tracked as GOLD PRELUDE and associated with TA0569, is a financially motivated initial access broker linked to the SocGholish (FakeUpdates) malware ecosystem. The actor is known for compromising legitimate websites and inserting lightweight JavaScript loaders that profile visiting systems, selectively redirect suitable victims, and present fake browser update lures. Follow-on delivery has included access-enablement tooling and malware such as Cobalt Strike, NetSupport RAT, and Python-based backdoors. The group’s tradecraft centers on web-based initial access. Operations commonly use injected stage-1 JavaScript, browser and environment fingerprinting, conditional payload delivery, and selective response behavior from command-and-control infrastructure. Reported campaigns have shown evidence of sustained infrastructure management and, in some cases, DNS-level control over compromised domains, indicating a deeper level of access than simple page injection. The actor has been active since at least 2017. UNC2726 functions primarily as an access broker rather than a ransomware operator itself. It has been linked to downstream access provision for other financially motivated actors, including Evil Corp / Indrik Spider, with subsequent deployment of ransomware such as WastedLocker and Hades by those downstream operators. This places the actor in the intrusion supply chain as an initial-access specialist supporting later-stage post-compromise activity by partners or customers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.