UNC2447

First seen
2020-05-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:10:54

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:de country_code:fr

Context

UNC2447 is a financially motivated threat actor with ties to multiple hacker groups. They have been observed deploying ransomware, including FiveHands and Hello Kitty, and engaging in double extortion tactics. They have been active since at least May 2020 and target organizations in Europe and North America.

Reports & references

  • esentire.com — Hacker Infrastructure Used In Cisco Breach Discovered Attacking A Top Workforce Management Corporation Russias Evil Corp Gang Suspected Reports Esentire (report)
  • Cisco Talos — Recent Cyber Attack (report)
  • internal-fireeye.com — Unc2447 Sombrat And Fivehands Ransomware Sophisticated Financial Threat (report)
  • rewterz.com — Rewterz Threat Alert Financially Motivated Aggressive Group Carrying Out Ransomware Campaigns Active Iocs (report)

External references