UNC7005, also tracked by Microsoft as STORM-2945, is a suspected Russian-linked cyber-espionage initial-access cluster first identified in February 2026. It is assessed with moderate confidence to be related to an ICE RELIC subcluster associated with initial-access operations; ICE RELIC is also known as APT29, Cozy Bear, and Midnight Blizzard and has been widely associated with Russia's SVR. UNC7005 has targeted academia, diplomatic and government personnel, nonprofit personnel, defense-sector contacts, and researchers, particularly across Ukraine, Western Europe, and the United States. UNC7005 conducts tailored social-engineering operations using diplomatic-event, conference, embassy, and trusted-organization themes. It has abused application-password phishing, OAuth authorization flows, Microsoft device-code authentication, and WhatsApp device-linking workflows to obtain account access, authentication tokens, and linked messaging sessions. The cluster has impersonated conferences and organizations to direct victims through legitimate authentication interfaces, reducing the likelihood that credential-security controls detect the activity. Its WhatsApp campaigns induced victims to link their accounts to attacker-controlled devices; follow-on pages have solicited microphone and camera access to record audio and video. The cluster has also delivered commodity information stealers, including VIDAR to Windows systems and ATOMIC/AtomicStealer to macOS systems, through fraudulent companion-application lures. These payloads collect browser-resident credentials, cookies, and other saved data. UNC7005 activity has been linked to malicious redirection from hospitality and event-network captive portals, including operations using adversary-in-the-middle-style traffic manipulation to present spoofed authentication pages and distribute malware. The group uses browser fingerprinting and automation-detection checks to hinder analysis. Its operational profile is considered less sophisticated and less operationally secure than that of UNC6293, despite overlaps in targeting and tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
51 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A suspected Russian espionage cluster using multi-vector social engineering and authentication abuse. It targets high-value individuals through conference-themed lures, device-code and QR-code phishing, captive-portal hijacking, and information-stealer delivery.
Conducting Russian-linked account-theft campaigns that use fake event invitations and device-code phishing to compromise Microsoft and WhatsApp accounts.
Russian-linked espionage cluster tied to ICE RELIC that conducts credential theft and access operations using application password phishing, device code phishing, OAuth phishing, captive portal hijacking, and MaaS-delivered infostealers.
Suspected Russian cyber-espionage cluster conducting social-engineering-driven phishing and OAuth abuse against individuals in academia, aerospace and defense, government, and think tanks. Also linked to hospitality captive-portal redirect lures.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.