UNC2682 is a threat activity cluster tracked for exploitation of SonicWall Email Security vulnerabilities, including CVE-2021-20021, CVE-2021-20022, and CVE-2021-20023. The actor used BEHINDER web shells to backdoor compromised systems and operated post-compromise with high privileges on affected servers. Observed tradecraft included clearing application logs to reduce visibility, using living-off-the-land techniques for credential access, exporting Windows registry hives to obtain password hashes and LSA secrets, and dumping process memory from LSASS and Apache Tomcat via built-in Windows functionality. The actor also staged email archive data for collection and accessed victim emails and files. UNC2682 demonstrated lateral movement and remote execution within victim environments, including use of WMI-based execution through Impacket tooling after leveraging local administrator password reuse across hosts. The intrusion also involved brief internal reconnaissance and broader post-exploitation activity. The actor’s ultimate objective was not determined with high confidence, but observed behavior shows a capable intrusion set focused on backdooring internet-facing email security infrastructure, credential theft, data access, and movement through victim networks. No high-confidence attribution to a specific country or state sponsor is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.