UNC2659

First seen
2021-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 12:10:45

Targeted industries: technology-and-telecommunications government-and-public-sector energy-and-utilities

Context

UNC2659 has been active since at least January 2021. We have observed the threat actor move through the whole attack lifecycle in under 10 days. UNC2659 is notable given their use of an exploit in the SonicWall SMA100 SSL VPN product, which has since been patched by SonicWall. The threat actor appeared to download several tools used for various phases of the attack lifecycle directly from those tools’ legitimate public websites.

Reports & references

  • internal-fireeye.com — Shining A Light On Darkside Ransomware Operations (report)

External references