UNC2628 is a financially motivated ransomware intrusion cluster tracked as a DARKSIDE ransomware-as-a-service affiliate and active since at least February 2021. The group is characterized by unusually rapid operations, often progressing from initial access to ransomware deployment within two to three days. It has been associated with multifaceted extortion activity tied to DARKSIDE operations, including data theft prior to encryption. UNC2628 has been observed obtaining initial access through corporate VPN infrastructure using legitimate credentials, with precursor activity consistent with suspicious authentication attempts, password spraying, and brute-force activity. Reporting also indicates use of purchased VPN credentials from criminal marketplaces as a likely access vector in some cases. After access, the group has relied heavily on Cobalt Strike BEACON for post-exploitation and command-and-control, including use of the open-source C3 framework to proxy command-and-control traffic through the Slack API. Credential theft has included use of Mimikatz. Lateral movement has primarily occurred over RDP, and data exfiltration has been conducted over SFTP using Rclone before ransomware execution. UNC2628 is one of several affiliate-linked clusters associated with the DARKSIDE ecosystem, alongside groups such as UNC2659 and UNC2465, but it is distinguished by its compressed intrusion timeline and credential-based access patterns. The cluster has also been assessed as potentially partnering with other ransomware-as-a-service operations including REvil and Netwalker. High-confidence reporting supports classification of UNC2628 as a cybercriminal actor focused on ransomware monetization rather than espionage or influence operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used the open-source C3 command-and-control framework to proxy C2 communications through the Slack API in order to blend in and conceal outbound traffic.
DarkSide-linked affiliate cluster that rapidly moves from initial access to ransomware deployment, often within days, using brute-force and credential-based access methods.
A DARKSIDE affiliate cluster conducting rapid intrusions using stolen or valid VPN credentials, Cobalt Strike, credential theft, lateral movement, data exfiltration, and PsExec-based ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.