UNC4108 is a threat cluster of unknown motivation associated with the deployment of remote-access and post-exploitation tooling. The cluster has used PowerShell to deploy VOLTMARKER, NetSupport RAT, and the GhostWeaver PowerShell backdoor, and has conducted host and environment reconnaissance. GhostWeaver is also tracked as UNC4108 and has been delivered through MintsLoader in observed activity. UNC4108 has leveraged initial access obtained through the UNC5518 access-as-a-service ClickFix ecosystem, rather than being identified as the operator of that initial-access operation. NetSupport RAT deployments associated with UNC4108 have used concealed installation and execution methods intended to reduce user visibility and establish remote control of compromised hosts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
51 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cluster of unknown motivation assessed as a likely downstream customer of UNC5518 in this activity. It is known to use PowerShell to deploy VOLTMARKER and NetSupport RAT while conducting hands-on reconnaissance.
Leverages initial access obtained by UNC5518 and conducts follow-on payload deployment, including NetSupport RAT and VOLTMARKER.
UNC4108 is a threat actor that leverages access provided by UNC5518 to deploy tools such as VOLTMARKER and NetSupport RAT using PowerShell.
Activity cluster associated with MintsLoader; uses it to deploy multiple secondary payloads including infostealers, form-grabber plugins, NetSupport RAT, and a backdoored BOINC client.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.