UNC4990

First seen
2020-01-01 00:00:00
Origin
IT
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:12:39

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:it

Context

UNC4990 is a financially motivated threat actor that has been active since at least 2020. They primarily target users in Italy and rely on USB devices for initial infection. The group has evolved their tactics over time, using encoded text files on popular websites like GitHub and Vimeo to host payloads. They have been observed using sophisticated backdoors like QUIETBOARD and EMPTYSPACE, and have targeted organizations in various industries, particularly in Italy.

Reports & references

  • Mandiant — Unc4990 Evolution Usb Malware (report)

External references