UNC2447 — Ransomware Profile

UNC2447 is the designation Mandiant gave to a financially motivated intrusion set, created as a tracked cluster in November 2020 after analysts observed the then-novel WARPRISM PowerShell dropper installing Cobalt Strike BEACON at two of its Managed Defense clients. The crew exploited CVE-2021-20016 — a critical SQL injection flaw in SonicWall's Secure Mobile Access SMA 100 series remote-access appliances — as a zero-day before a patch was available, and deployed the SOMBRAT backdoor alongside its ransomware. It monetised intrusions through double extortion, encrypting victims with FIVEHANDS ransomware (analysed separately by CISA as a variant built on the NTRUEncrypt public-key scheme) and then applying pressure through threats of media attention and offers of victim data for sale on hacker forums. Mandiant suspects that the associated affiliate programme used HELLOKITTY ransomware from May 2020 through December 2020 before shifting to FIVEHANDS from approximately January 2021, and it also observed UNC2447-affiliated actors previously using RAGNARLOCKER; because ransomware families circulate through affiliate programmes, those families are not treated here as the same actor. Mandiant observed the group targeting organisations in Europe and North America. Cisco Talos later assessed with moderate to high confidence that the 2022 breach of Cisco was carried out by an initial access broker with ties to both UNC2447 and Lapsus$.

Also tracked as

FiveHands

Vendor research

Read the full analysis on IntelFusions