UNC2565, also tracked as Hive0127, is a threat actor associated with GootLoader activity. The actor is linked to the operation and distribution of GootLoader, a JavaScript-based malware loader commonly delivered through SEO poisoning and compromised WordPress infrastructure. Recent activity has featured updated obfuscation and delivery tradecraft, including browser-side filename deception using custom web fonts with glyph substitution, delivery of XOR-encrypted archive payloads via WordPress comment functionality, and continued use of Windows 8.3 short filenames for evasion. Persistence has also shifted from scheduled tasks to the Windows Startup folder. UNC2565 functions primarily as an initial-access actor. Intrusions associated with its GootLoader activity have escalated rapidly to hands-on-keyboard compromises, including domain controller compromise within hours in observed cases. Post-compromise activity linked to GootLoader access has included deployment of the Supper backdoor, remote access tooling, lateral movement using Windows Remote Management, creation of administrative accounts, and follow-on ransomware operations. Reporting has linked GootLoader-derived access to subsequent activity by Storm-0494 and to ransomware deployments including INC, Rhysida, BlackCat, Zeppelin, and Quantum Locker. The actor’s tradecraft demonstrates strong emphasis on initial access, defense evasion, persistence, and enabling downstream post-exploitation by partner or follow-on operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated with GootLoader infections delivered via SEO poisoning and compromised WordPress infrastructure; recent cases led to hands-on-keyboard intrusions including lateral movement and domain controller compromise.
Associated with renewed GootLoader activity using new obfuscation techniques, including custom WOFF2 fonts with glyph substitution and WordPress comment endpoints to deliver XOR-encrypted ZIP payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.