UNC4393 is a financially motivated threat cluster tracked as the primary active user of BASTA ransomware. Activity has been tracked since mid-2022, with indications the cluster was active earlier in 2022. The group is associated with a private, tightly controlled BASTA affiliate model rather than a broadly advertised ransomware-as-a-service operation, and has demonstrated a rapid operational tempo with a median time to ransom of roughly 42 hours. UNC4393 has relied heavily on externally obtained initial access. Early operations overwhelmingly followed QAKBOT infections, commonly originating from phishing campaigns and related delivery chains. After disruption of QAKBOT infrastructure in 2023, the cluster shifted to other access sources, including DARKGATE delivery chains and later intrusions associated with SILENTNIGHT. More recent activity indicates a move beyond phishing-only access, including malvertising-linked intrusion paths. Post-compromise, UNC4393 combines living-off-the-land techniques with custom tooling to accelerate reconnaissance, foothold maintenance, lateral movement, data theft, and ransomware deployment. A consistently observed persistence and command-and-control method is DNS beaconing. Malware and utilities associated with the cluster include BASTA ransomware; SYSTEMBC and PORTYARD tunnelers; KNOTWRAP and DAWNCRY memory-only droppers; KNOTROCK for symbolic-link abuse on network shares to facilitate encryption; and COGSCAN for network reconnaissance. BASTA itself is a C++ ransomware family capable of encrypting local files and deleting volume shadow copies. The cluster has also been associated with attacks on backup infrastructure intended to inhibit recovery, including deletion of backup routines, erasure of data, and tampering with user permissions. These behaviors align with a mature extortion-oriented intrusion model focused on rapid execution, operational efficiency, and maximizing pressure on victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only as a source/reference, not discussed as part of the event itself.
Separate named cluster referenced in a distinct report.
Financially motivated activity associated with ransomware and backup-system disruption to prevent recovery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.