All threat actors

UNC2165

Alert me

A financially motivated cluster with strong overlap with the sanctioned Evil Corp cybercrime group. Since 2019 it has used FakeUpdates and varied ransomware brands, including Hades and LockBit-related deployments, apparently changing tooling and partners to complicate attribution and sanctions enforcement.

Create a free account to see the reports

Sign in or create a free account to see every report that names UNC2165.

Create free account