LightBasin, also tracked as UNC1945, is a highly capable threat actor known for deep expertise in Unix, Linux, and Solaris environments. The actor has been associated with intrusions affecting telecommunications operators and has also been linked to compromises involving managed service providers and organizations in the financial and professional consulting sectors. Reporting consistently characterizes the group as stealth-focused and technically proficient, with extensive use of custom tooling and tradecraft tailored to mission-critical systems that are often less closely monitored than mainstream enterprise platforms. LightBasin has been observed using custom implants and backdoors including SLAPSTICK and TinyShell, as well as a broader toolset associated with credential capture, covert remote access, log manipulation, and persistence. Documented behaviors include use of PAM-based backdoors, keylogging, process and file hiding, command execution, and anti-forensic measures. The actor has also been tied to exploitation of Oracle Solaris authentication weaknesses and to operations involving Solaris-focused malware. The group is notable for targeting telecommunications infrastructure and protocols, including movement across interconnected operator environments. Reported tradecraft includes leveraging telecom-specific infrastructure to tunnel or relay activity, using established implants and SSH for pivoting, and maintaining long-term clandestine access. Victimology also includes managed service providers and downstream client environments, indicating an ability to exploit trusted network relationships. Some reporting notes tactical and tooling overlaps between LightBasin and the financially motivated cluster UNC2891, including shared use of Unix- and Solaris-focused malware families and stealth techniques. However, attribution between these clusters has not been conclusively unified in all cases, and overlap should not be treated as definitive identity. LightBasin is widely described as China-linked in connection with telecommunications espionage activity, though some later reporting has questioned or revised attribution for portions of previously associated telecom intrusions. High-confidence characterization therefore supports describing LightBasin as a China-linked actor associated with stealthy intrusions into telecom and other enterprise environments, with strong Unix/Linux/Solaris tradecraft and capabilities spanning persistence, credential access, lateral movement, defense evasion, and post-compromise operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a tactically overlapping cluster associated with UNC2891, but not the primary subject of the report.
Compromising managed service providers, financial, professional consulting, and telecom industries.
Referenced as a linked/related cluster to UNC2891 per Mandiant; no additional operational details provided in this content beyond the asserted linkage.
Referenced as a cluster previously linked by Mandiant to UNC2891.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.