UNC2686 is a cybercrime threat cluster associated with BazarCall-style social-engineering campaigns active from at least early 2021. It is assessed to overlap tactically with later extortion activity attributed to UNC3753 and to have ties to the broader Conti ransomware ecosystem. UNC2686 has been described as an offshoot or closely related cluster within that criminal milieu. The cluster is known for callback-phishing and voice-phishing operations designed to trick targets into engaging with attacker-controlled call centers, after which victims are guided into actions that enable compromise. Reported tooling associated with UNC2686 includes BazarLoader variants as well as TrickBot, Ursnif, and SilentNight, indicating capability spanning initial access, post-exploitation, credential-focused intrusion activity, and data theft-enabling follow-on operations. Its tradecraft aligns with socially engineered intrusion chains rather than opportunistic mass exploitation. UNC2686 is primarily linked to financially motivated cybercrime. Available high-confidence reporting in this context supports its role in BazarCall-style intrusion activity and its relationship to Conti-linked operations, but does not directly establish specific victim countries, industry concentration, or independent ransomware/extortion tactics for UNC2686 itself beyond those overlaps.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster noted for overlap with UNC3753 and for conducting BazarCall-style social engineering campaigns.
Threat cluster known for BazarCall-style callback phishing campaigns and assessed as tactically overlapping with UNC3753; described as an offshoot of Conti.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.