UNC4393
Aliases: Storm-1811, CURLY SPIDER, STAC5777, Cardinal
- First seen
- 2022-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- innovator
- Resource level
- organization
- Actor type
- criminal
- Last IoC activity
- 2026-04-19 09:42:04
- Profile updated
- 2026-07-07 12:16:56
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
UNC4393 is a financially motivated threat actor primarily using BASTA ransomware. They have been active since early 2022 and have targeted over 40 organizations across various industries. UNC4393 has shown a willingness to cooperate with other threat clusters for initial access and has evolved from using existing tools to developing custom malware. They focus on efficient data exfiltration and multi-faceted extortion, often utilizing tools like COGSCAN and RCLONE for reconnaissance and data theft.
Related threat objects
- Storm-1811 (threat-actor)
Reports & references
- cloud.google.com — Unc4393 Goes Gently Into Silentnight (report)
- security.com — Black Basta Ransomware Zero Day (report)
- cloud.google.com — Detecting Disrupting Malvertising Backdoors (report)
- Microsoft — Threat Actors Misusing Quick Assist In Social Engineering Attacks Leading To Ransomware (report)
- news.sophos.com — Sophos Mdr Tracks Two Ransomware Campaigns Using Email Bombing Microsoft Teams Vishing (report)
- esentire.com — Ongoing Email Bombing Campaigns Leading To Remote Access And Post Exploitation (report)
- redcanary.com — Storm 1811 Black Basta (report)
- redcanary.com — Intelligence Insights June 2024 (report)
- x.com — 1881751635598139714 (report)
- Microsoft — 4267916 (report)
- services.google.com — M Trends 2023 Report (report)
- services.google.com — M Trends 2024 (report)
- x.com — 1880368272610050459 (report)
- medium.com — Qbot Is Back Connect 2D774052369F (report)
- CrowdStrike — Crowdstrikeglobalthreatreport2025 (report)
- CrowdStrike — Curly Spider (report)