UNC2465 is a financially motivated cybercriminal threat cluster active since at least April 2019 that conducts ransomware and data-leak extortion operations. It has operated as a ransomware-as-a-service affiliate using DarkSide and LockBit. Its intrusions center on SMOKEDHAM, a PowerShell-based .NET backdoor supporting arbitrary command execution, screen capture, and keylogging. UNC2465 obtains initial access through phishing, malicious shortcuts distributed through legitimate file-hosting services, and trojanized software installers. It has compromised a legitimate security-camera software provider's website to replace downloadable installers and has used malvertising to distribute counterfeit software packages. Infection chains employ DLL sideloading, obfuscated PowerShell, and persistence through registry autorun entries, startup shortcuts, scheduled tasks, and Windows service manipulation. SMOKEDHAM uses encrypted command-and-control communications and domain fronting to conceal attacker infrastructure. After compromise, UNC2465 uses tools including Advanced IP Scanner and BloodHound for discovery, Mimikatz and LSASS memory dumping for credential theft, and keyloggers for surveillance. It deploys Cobalt Strike Beacon and abuses legitimate remote-access tools such as UltraVNC. Ngrok tunnels expose internal remote-desktop services and bypass network restrictions, while RDP, WMI, and PsExec facilitate lateral movement. The actor has targeted backup platforms, deleted backup routines, erased backup data, and altered permissions to obstruct recovery. Its extortion activity combines ransomware encryption with threats to disclose stolen information, and operators have called victim support lines to direct attention to ransom notes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-speaking, financially motivated activity cluster active since at least mid-2019. The report attributes the observed European intrusions to UNC2465 with moderate confidence, documenting malvertising-delivered SmokedHam, credential and data theft, lateral movement, and Qilin encryption of ESXi virtual disks. Historically associated with DarkSide and suspected of affiliations with LockBit and Hunters International. Its possible transition to Qilin affiliation in 2025 remains an assessment rather than a confirmed date. Cacciatore is tentatively linked through shared delivery tooling and communication patterns.
Named RaaS affiliate mentioned because prior reporting linked it to use of SMOKEDHAM; the article speculates but does not confirm any current affiliation with Hunters International.
Financially motivated intrusion activity leveraging the SMOKEDHAM backdoor for initial access, persistence, reconnaissance, lateral movement, and subsequent extortion/ransomware deployment; historically linked to DARKSIDE and later shifting to LOCKBIT.
UNC2465 is a DARKSIDE ransomware affiliate known for conducting supply chain attacks, specifically by Trojanizing software installers on legitimate websites to gain initial access. They use a variety of malware and tools for persistence, lateral movement, credential harvesting, and remote access, and have demonstrated the ability to switch between different ransomware and malware offerings as affiliate programs change.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.