UNC4108 is a Mandiant-tracked threat cluster with unknown motivation that has been observed leveraging access obtained through third-party initial-access operations and using PowerShell-centric tradecraft to deploy additional malware. The cluster has been linked to delivery of NetSupport RAT, VOLTMARKER, and the GhostWeaver PowerShell backdoor, and has been associated with MintsLoader as a delivery mechanism in some intrusion chains. UNC4108 has been observed in activity where victims were first compromised through ClickFix-style social engineering that used fake verification or CAPTCHA prompts to induce execution of malicious PowerShell commands. In related operations, UNC4108 appears to have benefited from access established by another cluster operating an access-as-a-service model, rather than being solely responsible for the initial compromise itself. Once active on a host, UNC4108 has conducted reconnaissance and used PowerShell to stage and deploy follow-on tooling. Known tooling associated with UNC4108 includes GhostWeaver, a PowerShell-based backdoor or RAT, as well as NetSupport RAT and VOLTMARKER. The cluster’s observed behavior supports characterization as a post-compromise operator focused on payload delivery, reconnaissance, and remote access enablement. Public reporting in the supplied material does not establish a confirmed national affiliation, victimology profile, or dominant operational objective for UNC4108.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
45 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Leverages initial access obtained by UNC5518 and conducts follow-on payload deployment, including NetSupport RAT and VOLTMARKER.
UNC4108 is a threat actor that leverages access provided by UNC5518 to deploy tools such as VOLTMARKER and NetSupport RAT using PowerShell.
Activity cluster associated with MintsLoader; uses it to deploy multiple secondary payloads including infostealers, form-grabber plugins, NetSupport RAT, and a backdoored BOINC client.
Activity cluster associated (in this reporting) with GhostWeaver delivery via MintsLoader to establish persistence and enable follow-on plugin loading.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.