UNC1878

First seen
2019-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:59:38

Targeted industries: financial-services healthcare-and-pharmaceutical education-and-nonprofits

Context

UNC1878 is a financially motivated threat actor that monetizes network access via the deployment of RYUK ransomware. Earlier this year, Mandiant published a blog on a fast-moving adversary deploying RYUK ransomware, UNC1878. Shortly after its release, there was a significant decrease in observed UNC1878 intrusions and RYUK activity overall almost completely vanishing over the summer. But beginning in early fall, Mandiant has seen a resurgence of RYUK along with TTP overlaps indicating that UNC1878 has returned from the grave and resumed their operations.

Reports & references

  • twitter.com — 1321865315513520128 (report)
  • Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
  • gist.github.com — 6Aa7F61246F53A8Dd4Befea86E832456 (report)
  • youtube.com — Watch (report)
  • Mandiant — The Cycle Of Adversary Pursuit (report)

External references