UNC1945, commonly associated with the name LightBasin and also rendered Light_Basin, is a threat activity cluster distinguished by advanced expertise in Linux, Unix, and Oracle Solaris environments. Its documented targets include managed service providers and organizations in the financial and professional consulting industries. Compromise of managed service providers has also enabled access to their clients. UNC1945 has used an exploit targeting a stack-based buffer overflow in the Solaris Pluggable Authentication Modules library through SSH keyboard-interactive authentication. Its tooling includes the SLAPSTICK authentication backdoor, TINYSHELL remote-access backdoor, STEELCORGI payload packer, and Mimikatz credential-dumping utility. Its operations emphasize persistent access, credential compromise, lateral movement, and concealment within mission-critical systems. LightBasin has historically been associated with telecommunications intrusions, but some telecom activity previously assigned that name was subsequently attributed to Liminal Panda. UNC2891 shares tools and techniques with UNC1945, but the clusters have not been conclusively established as a single actor. UNC2891’s CAKETAP-enabled ATM fraud and physical-device intrusions should therefore not be treated as established UNC1945 operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a tactically overlapping cluster associated with UNC2891, but not the primary subject of the report.
Compromising managed service providers, financial, professional consulting, and telecom industries.
Referenced as a linked/related cluster to UNC2891 per Mandiant; no additional operational details provided in this content beyond the asserted linkage.
Referenced as a cluster previously linked by Mandiant to UNC2891.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.