UNC2447
- First seen
- 2020-05-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:10:54
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:de country_code:fr
Context
UNC2447 is a financially motivated threat actor with ties to multiple hacker groups. They have been observed deploying ransomware, including FiveHands and Hello Kitty, and engaging in double extortion tactics. They have been active since at least May 2020 and target organizations in Europe and North America.
Reports & references
- esentire.com — Hacker Infrastructure Used In Cisco Breach Discovered Attacking A Top Workforce Management Corporation Russias Evil Corp Gang Suspected Reports Esentire (report)
- Cisco Talos — Recent Cyber Attack (report)
- internal-fireeye.com — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)
- rewterz.com — Rewterz Threat Alert Financially Motivated Aggressive Group Carrying Out Ransomware Campaigns Active Iocs (report)