All threat actors

UNC5227

Alert me

A financially motivated intrusion cluster active since late 2023. It uses stolen or brute-forced VPN credentials, open-source tools, PORTLIGHT, and data-exfiltration utilities, and its access has led to deployments of LockBit, ALPHV, Rhysida, and RansomHub ransomware.

Create a free account to see the reports

Sign in or create a free account to see every report that names UNC5227.

Create free account