UNC4393

Aliases: Storm-1811, CURLY SPIDER, STAC5777, Cardinal

First seen
2022-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
innovator
Resource level
organization
Actor type
criminal
Last IoC activity
2026-04-19 09:42:04
Profile updated
2026-07-07 12:16:56

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

UNC4393 is a financially motivated threat actor primarily using BASTA ransomware. They have been active since early 2022 and have targeted over 40 organizations across various industries. UNC4393 has shown a willingness to cooperate with other threat clusters for initial access and has evolved from using existing tools to developing custom malware. They focus on efficient data exfiltration and multi-faceted extortion, often utilizing tools like COGSCAN and RCLONE for reconnaissance and data theft.

Related threat objects

Reports & references

  • cloud.google.com — Unc4393 Goes Gently Into Silentnight (report)
  • security.com — Black Basta Ransomware Zero Day (report)
  • cloud.google.com — Detecting Disrupting Malvertising Backdoors (report)
  • Microsoft — Threat Actors Misusing Quick Assist In Social Engineering Attacks Leading To Ransomware (report)
  • news.sophos.com — Sophos Mdr Tracks Two Ransomware Campaigns Using Email Bombing Microsoft Teams Vishing (report)
  • esentire.com — Ongoing Email Bombing Campaigns Leading To Remote Access And Post Exploitation (report)
  • redcanary.com — Storm 1811 Black Basta (report)
  • redcanary.com — Intelligence Insights June 2024 (report)
  • x.com — 1881751635598139714 (report)
  • Microsoft — 4267916 (report)
  • services.google.com — M Trends 2023 Report (report)
  • services.google.com — M Trends 2024 (report)
  • x.com — 1880368272610050459 (report)
  • medium.com — Qbot Is Back Connect 2D774052369F (report)
  • CrowdStrike — Crowdstrikeglobalthreatreport2025 (report)
  • CrowdStrike — Curly Spider (report)

External references