UNC4990 (Italy USB Cryptojacking Operator)
UNC4990 is Mandiant's tracked uncategorized threat cluster designation for the financially-motivated Italy-based threat actor active since at least 2020 leveraging weaponized USB devices for initial infection per Mandiant canonical January 31 2024 "Evolution of UNC4990: Uncovering USB Malware's Hidden Depths" disclosure ("Mandiant assesses with medium confidence that UNC4990 is a financially motivated threat actor operational since at least 2020. Based on the extensive use of Italian infrastructure throughout UNC4990 operations, including using Italian blogging platforms for C2, we believe this actor to be operating out of Italy") with EMPTYSPACE downloader + QUIETBOARD multi-component backdoor + abuse of legitimate services GitHub + GitLab + Vimeo + Ars Technica for encoded payload hosting + Italian blogging platform C2 infrastructure + cryptojacking final-stage with $55K+ wallet profits via QUIETBOARD clipboard cryptocurrency theft.
attribution chain via Mandiant Managed Defense canonical January 31 2024 disclosure + Fortgale "Nebula Broker" alternative tracking December 2023 + Yoroi cross-vendor coverage December 2023 + The Hacker News canonical Italian Businesses Hit by Weaponized USBs coverage + Tech Times canonical UNC4990 Hackers USB Malware Payloads coverage + Security Online + Anvilogic industry coverage.
honest attribution caveat UNC4990 is Mandiant uncategorized cluster designation with medium-confidence financially- motivated criminal attribution + operating-out-of- Italy assessment based on Italian infrastructure usage circumstantial.
it is not known if UNC4990 functions only as initial access facilitator for other actors or has end-goal-cryptojacking objectives (Mandiant observed Coinminer deployment after months of beaconing-only activity in at least one case suggesting access-sale or delayed- monetization business model)
standalone cluster paralleling unc1860 + teamtnt + confucius in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
operational target profile signature Italian organizations primary target + signature health + transportation + construction + logistics multi-industry victimology per Mandiant ("Italian organizations appear to be primarily impacted by this activity... across multiple industries, including health, transportation, construction, and logistics") + signature Italy primary + Europe + United States additional victim distribution per Mandiant; operational attack architecture: (1) cluster- defining weaponized USB devices initial infection vector with LNK shortcuts disguised with common vendor names + storage sizes (KINGSTON 32GB.lnk, D 32GB.lnk) using default Windows drive icon enticing victims to double-click + execution triggers encoded PowerShell script "explorer.ps1" downloading EMPTYSPACE downloader.
(2) cluster- defining EMPTYSPACE downloader signature with multi-programming-language implementation demonstrating modular toolset development + experimentation tradecraft + URL change when Vimeo video taken down showing adaptability; (3) cluster-defining QUIETBOARD multi-component backdoor signature with capabilities including executing commands + Python code + altering clipboards for cryptocurrency theft + gathering detailed system information.
(4) cluster- defining GitHub + GitLab + Vimeo + Ars Technica legitimate services abuse tradecraft signature with encoded payloads disguised as text strings in forums + video descriptions + abuse without exploiting vulnerabilities in these sites establishing detection-evasion via trusted- platform-payload-hosting methodology.
(5) cluster-defining Italian blogging platform C2 infrastructure signature supporting operating- out-of-Italy attribution via extensive Italian infrastructure usage.
(6) cluster-defining LNK shortcut + explorer.ps1 PowerShell chain infection signature with encoded PowerShell evolution from simple encoding to asymmetric encryption + UUID infection-host-tracking adding tradecraft sophistication over time.
(7) cluster-defining cryptojacking final-stage $55K+ wallet profits signature per Tech Times via Mandiant establishing financially-motivated criminal objective via QUIETBOARD clipboard cryptocurrency theft + XMRig Monero coinminer deployment after months of beaconing activity.
(8) cluster- defining "Nebula Broker" Fortgale + Yoroi December 2023 alternative tracking signature establishing pre-Mandiant industry coverage + cross-vendor cluster designation agreement.
(9) honest caveat initial access facilitator vs. cryptojacking end-goal ambiguity per Mandiant ("It is currently not known if UNC4990 functions only as an initial access facilitator for other actors. The end goal of the threat actor is also not clear, although in one instance an open- source cryptocurrency miner is said to have been deployed after months of beaconing activity")
(10) signature multi-industry Italy targeting health + transportation + construction + logistics victimology reflecting opportunistic financially-motivated targeting; cluster fills the Mandiant-UNC4990-Italy-based- financially-motivated-medium-confidence + weaponized-USB-devices-initial-infection-vector + EMPTYSPACE-downloader-QUIETBOARD-multi-component- backdoor + GitHub-GitLab-Vimeo-Ars-Technica- legitimate-services-abuse-tradecraft + Italian- blogging-platform-C2-infrastructure-signature + cryptojacking-final-stage-$55K-wallet-profits + Nebula-Broker-Fortgale-Yoroi-December-2023- alternative-tracking + multi-industry-Italy- health-transportation-construction-logistics- targeting + January-2024-Mandiant-disclosure position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
canonical illustration of Mandiant medium-confidence financially-motivated cluster designation methodology + Italy-based criminal cluster + weaponized USB initial infection vector + EMPTYSPACE / QUIETBOARD modular custom malware family + GitHub/GitLab/Vimeo/Ars Technica legitimate services abuse tradecraft + Italian blogging platform C2 + cryptojacking $55K+ wallet profits financially-motivated objective + Nebula Broker Fortgale/Yoroi cross-vendor alternative tracking cited in essentially all subsequent Italy-based- financially-motivated-USB-malware industry analyses through 2020-2026 period.