UTA-2026-024 is an unidentified post-exploitation activity cluster that compromised an unnamed United States organization and sought durable control of its Windows Active Directory environment. The operation used a Sliver beacon and tooling for credential access, including collection of Windows credential-related registry hives and LSASS memory dumping with Mimikatz. Operators created privileged domain and local accounts, enabled Remote Desktop Protocol while disabling Network Level Authentication, and disabled endpoint-protection services. Persistence was established through SYSTEM-level scheduled tasks with forged metadata and backdated registration details; a recurring task retrieved the current payload chain without retaining a fixed payload locally. The activity also modified DNS-filtering administration and internal DNS resolution to permit attacker command-and-control communications. A Node.js implant resolved changing command-and-control domains through a publicly readable Ethereum smart contract, providing resilient infrastructure rotation. Infrastructure associated with the activity has been linked to a separate ransomware incident, but ransomware deployment was not observed in this intrusion and no responsible threat actor has been identified.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-compromise Windows Active Directory intrusion targeting an unnamed US organization. The operators established domain-level persistence and control through privileged account creation, credential theft, endpoint-security disabling, scheduled SYSTEM tasks, RDP configuration changes, DNS-filter manipulation, and Sliver/Node.js command-and-control infrastructure. The reporting links the infrastructure to a confirmed ransomware incident but does not attribute the activity to named people or confirm ransomware deployment in this intrusion.
A Windows-domain post-compromise campaign against an unnamed US organization. The operators used Sliver and a Node.js implant with Ethereum smart-contract-based C2 resolution; created privileged accounts; disabled endpoint-protection services; stole credentials from registry hives and LSASS; enabled RDP while disabling NLA; created SYSTEM scheduled-task persistence; and modified internal DNS and a DNS-filter allowlist to retain C2 access. The reporting does not identify the people behind the activity or establish ransomware deployment in this incident.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.