Home/Threat Actor/UNC4990 (Italy USB Cryptojacking Operator)
Threat Actor

UNC4990 (Italy USB Cryptojacking Operator)

unc4990 · financially_motivated_italy_based_criminal_mandiant_medium_confidence_unc4990 · active since 2020-12

UNC4990 is Mandiant's tracked uncategorized threat cluster designation for the financially-motivated Italy-based threat actor active since at least 2020 leveraging weaponized USB devices for initial infection per Mandiant canonical January 31 2024 "Evolution of UNC4990: Uncovering USB Malware's Hidden Depths" disclosure ("Mandiant assesses with medium confidence that UNC4990 is a financially motivated threat actor operational since at least 2020. Based on the extensive use of Italian infrastructure throughout UNC4990 operations, including using Italian blogging platforms for C2, we believe this actor to be operating out of Italy") with EMPTYSPACE downloader + QUIETBOARD multi-component backdoor + abuse of legitimate services GitHub + GitLab + Vimeo + Ars Technica for encoded payload hosting + Italian blogging platform C2 infrastructure + cryptojacking final-stage with $55K+ wallet profits via QUIETBOARD clipboard cryptocurrency theft.

attribution chain via Mandiant Managed Defense canonical January 31 2024 disclosure + Fortgale "Nebula Broker" alternative tracking December 2023 + Yoroi cross-vendor coverage December 2023 + The Hacker News canonical Italian Businesses Hit by Weaponized USBs coverage + Tech Times canonical UNC4990 Hackers USB Malware Payloads coverage + Security Online + Anvilogic industry coverage.

honest attribution caveat UNC4990 is Mandiant uncategorized cluster designation with medium-confidence financially- motivated criminal attribution + operating-out-of- Italy assessment based on Italian infrastructure usage circumstantial.

it is not known if UNC4990 functions only as initial access facilitator for other actors or has end-goal-cryptojacking objectives (Mandiant observed Coinminer deployment after months of beaconing-only activity in at least one case suggesting access-sale or delayed- monetization business model)

standalone cluster paralleling unc1860 + teamtnt + confucius in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

operational target profile signature Italian organizations primary target + signature health + transportation + construction + logistics multi-industry victimology per Mandiant ("Italian organizations appear to be primarily impacted by this activity... across multiple industries, including health, transportation, construction, and logistics") + signature Italy primary + Europe + United States additional victim distribution per Mandiant; operational attack architecture: (1) cluster- defining weaponized USB devices initial infection vector with LNK shortcuts disguised with common vendor names + storage sizes (KINGSTON 32GB.lnk, D 32GB.lnk) using default Windows drive icon enticing victims to double-click + execution triggers encoded PowerShell script "explorer.ps1" downloading EMPTYSPACE downloader.

(2) cluster- defining EMPTYSPACE downloader signature with multi-programming-language implementation demonstrating modular toolset development + experimentation tradecraft + URL change when Vimeo video taken down showing adaptability; (3) cluster-defining QUIETBOARD multi-component backdoor signature with capabilities including executing commands + Python code + altering clipboards for cryptocurrency theft + gathering detailed system information.

(4) cluster- defining GitHub + GitLab + Vimeo + Ars Technica legitimate services abuse tradecraft signature with encoded payloads disguised as text strings in forums + video descriptions + abuse without exploiting vulnerabilities in these sites establishing detection-evasion via trusted- platform-payload-hosting methodology.

(5) cluster-defining Italian blogging platform C2 infrastructure signature supporting operating- out-of-Italy attribution via extensive Italian infrastructure usage.

(6) cluster-defining LNK shortcut + explorer.ps1 PowerShell chain infection signature with encoded PowerShell evolution from simple encoding to asymmetric encryption + UUID infection-host-tracking adding tradecraft sophistication over time.

(7) cluster-defining cryptojacking final-stage $55K+ wallet profits signature per Tech Times via Mandiant establishing financially-motivated criminal objective via QUIETBOARD clipboard cryptocurrency theft + XMRig Monero coinminer deployment after months of beaconing activity.

(8) cluster- defining "Nebula Broker" Fortgale + Yoroi December 2023 alternative tracking signature establishing pre-Mandiant industry coverage + cross-vendor cluster designation agreement.

(9) honest caveat initial access facilitator vs. cryptojacking end-goal ambiguity per Mandiant ("It is currently not known if UNC4990 functions only as an initial access facilitator for other actors. The end goal of the threat actor is also not clear, although in one instance an open- source cryptocurrency miner is said to have been deployed after months of beaconing activity")

(10) signature multi-industry Italy targeting health + transportation + construction + logistics victimology reflecting opportunistic financially-motivated targeting; cluster fills the Mandiant-UNC4990-Italy-based- financially-motivated-medium-confidence + weaponized-USB-devices-initial-infection-vector + EMPTYSPACE-downloader-QUIETBOARD-multi-component- backdoor + GitHub-GitLab-Vimeo-Ars-Technica- legitimate-services-abuse-tradecraft + Italian- blogging-platform-C2-infrastructure-signature + cryptojacking-final-stage-$55K-wallet-profits + Nebula-Broker-Fortgale-Yoroi-December-2023- alternative-tracking + multi-industry-Italy- health-transportation-construction-logistics- targeting + January-2024-Mandiant-disclosure position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

canonical illustration of Mandiant medium-confidence financially-motivated cluster designation methodology + Italy-based criminal cluster + weaponized USB initial infection vector + EMPTYSPACE / QUIETBOARD modular custom malware family + GitHub/GitLab/Vimeo/Ars Technica legitimate services abuse tradecraft + Italian blogging platform C2 + cryptojacking $55K+ wallet profits financially-motivated objective + Nebula Broker Fortgale/Yoroi cross-vendor alternative tracking cited in essentially all subsequent Italy-based- financially-motivated-USB-malware industry analyses through 2020-2026 period.

financially_motivated_italy_based_criminal_mandiant_medium_confidence_unc4990 confidence: high 18 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

UNC4990 is Mandiant's tracked uncategorized threat cluster designation for the financially-motivated Italy-based threat actor active since at least 2020 leveraging weaponized USB devices for initial infection, EMPTYSPACE downloader + QUIETBOARD multi-component backdoor with clipboard cryptocurrency theft, abuse of legitimate services GitHub + GitLab + Vimeo + Ars Technica for encoded payload hosting, Italian blogging platform C2 infrastructure, cryptojacking final- stage with $55K+ wallet profits. Italy-based financially-motivated medium-confidence attribution per Mandiant January 31 2024 disclosure + Fortgale "Nebula Broker" alternative tracking December 2023 + Yoroi cross-vendor coverage + Hacker News + Tech Times + Security Online + Anvilogic industry coverage. Standalone cluster paralleling unc1860 + teamtnt + confucius in v0.1.178 heterogeneous nation- state + criminal cluster gap-filler cell.

Operational target profile
  • Italian organizations signature primary.
  • Health + transportation + construction + logistics signature multi-industry.
  • Italy primary + Europe + US additional Operational attack architecture: (1) Weaponized USB devices initial infection vector (cluster-defining) (2) EMPTYSPACE downloader + QUIETBOARD multi- component backdoor (cluster-defining) (3) GitHub + GitLab + Vimeo + Ars Technica legitimate services abuse tradecraft (cluster- defining) (4) Italian blogging platform C2 infrastructure (cluster-defining) (5) LNK shortcut + explorer.ps1 PowerShell chain infection (cluster-defining) (6) Cryptojacking final-stage $55K+ wallet profits (signature) (7) Nebula Broker Fortgale/Yoroi December 2023 alternative tracking (cluster-defining) (8) Initial access facilitator vs. cryptojacking end-goal ambiguity (honest caveat) The cluster fills the Mandiant-UNC4990-Italy- based-financially-motivated-medium-confidence + weaponized-USB-devices-initial-infection-vector + EMPTYSPACE-downloader-QUIETBOARD-multi-component- backdoor + GitHub-GitLab-Vimeo-Ars-Technica- legitimate-services-abuse-tradecraft + Italian- blogging-platform-C2-infrastructure-signature + cryptojacking-final-stage-$55K-wallet-profits + Nebula-Broker-Fortgale-Yoroi-December-2023- alternative-tracking + multi-industry-Italy- health-transportation-construction-logistics- targeting + January-2024-Mandiant-disclosure position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

Aliases

18
unc4990unc_4990unc4990 activity clustermandiant unc4990 trackingunc4990 italy financially motivated usb malwarenebula brokernebula_brokerunc4990 emptyspace downloaderunc4990 quietboard multi-component backdoorunc4990 weaponized usb devices initial infectionunc4990 github gitlab vimeo ars technica payload hostingunc4990 italian blogging platform c2 infrastructureunc4990 lnk shortcut explorer.ps1 powershell chainunc4990 cryptojacking xmrig coinminer monerounc4990 january 2024 mandiant disclosureunc4990 italian organizations health transportation construction logisticsunc4990 financially motivated medium-confidence operating italyunc4990 ars technica github vimeo legitimate services abuse

Notable Campaigns

11
2024UNC4990 January 31 2024 Mandiant Canonical Disclosure Signature
2023UNC4990 Nebula Broker Fortgale + Yoroi December 2023 Alternative Tracking Signature
2020-2026Continued Industry Reference Status (2020-2026)
2020-2024UNC4990 EMPTYSPACE + QUIETBOARD Modular Custom Malware Family Signature
2020-2024UNC4990 Weaponized USB Devices Initial Infection Vector Canonical Signature
2020-2024UNC4990 GitHub + GitLab + Vimeo + Ars Technica Legitimate Services Abuse Tradecraft Signature
2020-2024UNC4990 Italian Blogging Platform C2 Infrastructure Signature
2020-2024UNC4990 Cryptojacking + QUIETBOARD Clipboard Cryptocurrency Theft $55K+ Wallet Profits Signature
2020-2024UNC4990 Initial Access Facilitator vs. Cryptojacking End-Goal Ambiguity Signature
2020-2024UNC4990 Multi-Industry Italy Targeting Signature (Health + Transportation + Construction + Logistics)
2020UNC4990 Origin, 2020 Italy USB Malware Emergence

Attribution & Reporting

Attributed by
Mandiant Managed Defense (canonical UNC4990 January 31 2024 disclosure)Mandiant blog "Evolution of UNC4990 Uncovering USB Malware's Hidden Depths" (canonical)Fortgale (canonical Nebula Broker alternative tracking December 2023)Yoroi (canonical December 2023 alternative coverage)The Hacker News (canonical Italian Businesses Hit by Weaponized USBs coverage)Tech Times (canonical UNC4990 USB Malware Payloads on Media Hosting Platforms coverage)SecurityOnline (canonical UNC4990 A Threat Actor with USB Trick coverage)Anvilogic (canonical UNC4990 USB Malware Campaign Analysis coverage)
Key reporting
reportMandiant Managed Defense (Jan 31 2024): Evolution of UNC4990 Uncovering USB Malware's Hidden Depths, canonical disclosure
reportFortgale (Dec 2023): Nebula Broker alternative tracking canonical disclosure
reportYoroi (Dec 2023): alternative coverage canonical
reportThe Hacker News: Italian Businesses Hit by Weaponized USBs Spreading Cryptojacking Malware, canonical coverage
reportTech Times: UNC4990 Hackers USB Malware Payloads on Media Hosting Platforms, canonical coverage
reportSecurityOnline / Brina Blum: UNC4990 A Threat Actor with USB Trick Up Its Sleeve, canonical coverage
reportAnvilogic: UNC4990 USB Malware Campaign Analysis, canonical coverage

Operational

State sponsor

UNC4990 is Mandiant's tracked uncategorized threat cluster designation for the financially-motivated Italy-based threat actor active since at least 2020 leveraging weaponized USB devices for initial infection. Per Mandiant: "Mandiant assesses with medium confidence that UNC4990 is a financially motivated threat actor operational since at least 2020. Based on the extensive use of Italian infrastructure throughout UNC4990 operations, including using Italian blogging platforms for C2, we believe this actor to be operating out of Italy." Honest attribution caveat: UNC4990 is Mandiant uncategorized cluster designation with medium- confidence financially-motivated criminal attribution.

Operating-out-of-Italy assessment based on Italian infrastructure usage + Italian blogging platform C2 (medium-confidence circumstantial). It is not known if UNC4990 functions only as an initial access facilitator for other actors or has end-goal-cryptojacking objectives, Mandiant observed Coinminer deployment after months of beaconing-only activity in at least one case suggesting access- sale or delayed-monetization business model. Attribution chain: (1) Mandiant canonical January 31 2024 UNC4990 disclosure: Mandiant Managed Defense published "Evolution of UNC4990: Uncovering USB Malware's Hidden Depths" report establishing canonical UNC4990 Italy-based financially-motivated attribution.

(2) Italy-based financially-motivated cluster designation: per Mandiant: "Mandiant Managed Defense has been tracking UNC4990, an actor who heavily uses USB devices for initial infection. UNC4990 primarily targets users based in Italy and is likely motivated by financial gain. Our research shows this campaign has been ongoing since at least 2020." (3) Weaponized USB devices initial infection vector signature: per Mandiant + The Hacker News: UNC4990 strategy revolves around weaponizing USB drives with LNK shortcuts disguised with common vendor names and storage sizes (e.g. "KINGSTON (32GB).lnk" or "D (32GB).lnk") using default Windows drive icon.

LNK execution triggers encoded PowerShell script "explorer.ps1" downloading EMPTYSPACE downloader. (4) EMPTYSPACE downloader signature: per Mandiant: EMPTYSPACE is UNC4990's primary downloader implemented in multiple programming languages demonstrating modular toolset development + experimentation tradecraft. (5) QUIETBOARD multi-component backdoor signature: per Mandiant: QUIETBOARD ultimate payload is sophisticated multi-component backdoor with capabilities including executing commands + Python code + altering clipboards for cryptocurrency theft + gathering detailed system information.

(6) GitHub + GitLab + Vimeo + Ars Technica legitimate services abuse tradecraft signature: per Mandiant: UNC4990 abuses legitimate services including Ars Technica + GitHub + GitLab + Vimeo to host encoded payloads disguised as text strings in forums + video descriptions. "The abuse of these legitimate services did not involve exploiting any known or unknown vulnerabilities in these sites, nor did any of these organizations have anything misconfigured to allow for this abuse", cluster-defining legitimate-services-abuse tradecraft. (7) Italian blogging platform C2 infrastructure signature: per Mandiant: extensive use of Italian infrastructure throughout UNC4990 operations + Italian blogging platforms for command-and-control supporting operating-out-of- Italy attribution. (8) Cryptojacking final-stage with $55K+ wallet profits signature: per Tech Times via Mandiant: cryptocurrency wallet addresses linked to UNC4990 campaign have amassed profits exceeding $55,000 establishing financially- motivated criminal objective.

(9) "Nebula Broker" Fortgale/Yoroi alternative tracking December 2023: per The Cloud Consultancy + Hacker News: "Details of the campaign were previously documented by Fortgale and Yoroi in early December 2023, with the former tracking the adversary under the name Nebula Broker." Cluster-defining alternative- tracking signature. (10) Multi-industry Italy targeting signature: per Mandiant: UNC4990 attacks single out multiple industries including health + transportation + construction + logistics, primarily Italy-based organizations.

Operational target profile
  • Italian organizations signature primary target per Mandiant.
  • Health sector signature per Mandiant.
  • Transportation sector signature per Mandiant.
  • Construction sector signature per Mandiant.
  • Logistics sector signature per Mandiant.
  • Italy-based users primary per Mandiant.
  • Europe + U.S. additional victims per Mandiant report The cluster fills the Mandiant-UNC4990-Italy- based-financially-motivated-medium-confidence + weaponized-USB-devices-initial-infection-vector + EMPTYSPACE-downloader-QUIETBOARD-multi-component- backdoor + GitHub-GitLab-Vimeo-Ars-Technica- legitimate-services-abuse-tradecraft + Italian- blogging-platform-C2-infrastructure-signature + cryptojacking-final-stage-$55K-wallet-profits + Nebula-Broker-Fortgale-Yoroi-December-2023- alternative-tracking + multi-industry-Italy- health-transportation-construction-logistics- targeting + January-2024-Mandiant-disclosure position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
Motivations
financially_motivated_italy_based_criminal_mandiant_medium_confidence, weaponized_usb_devices_initial_infection_vector_signature, cryptojacking_final_stage_wallet_profits_signature, emptyspace_quietboard_modular_custom_malware_family_signature, github_gitlab_vimeo_ars_technica_legitimate_services_abuse_tradecraft, italian_blogging_platform_c2_infrastructure_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)29/60 · 48%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MODULAR TOOLSET EXPERIMENTATION PREDISPOSITION SIGNATURE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin