UNC1878
- First seen
- 2019-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:59:38
Targeted industries: financial-services healthcare-and-pharmaceutical education-and-nonprofits
Context
UNC1878 is a financially motivated threat actor that monetizes network access via the deployment of RYUK ransomware. Earlier this year, Mandiant published a blog on a fast-moving adversary deploying RYUK ransomware, UNC1878. Shortly after its release, there was a significant decrease in observed UNC1878 intrusions and RYUK activity overall almost completely vanishing over the summer. But beginning in early fall, Mandiant has seen a resurgence of RYUK along with TTP overlaps indicating that UNC1878 has returned from the grave and resumed their operations.
Reports & references
- twitter.com — 1321865315513520128 (report)
- Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
- gist.github.com — 6Aa7F61246F53A8Dd4Befea86E832456 (report)
- youtube.com — Watch (report)
- Mandiant — The Cycle Of Adversary Pursuit (report)