← All Threat Actors
Threat Actor Profile

UNC6671

No known aliases in database
▲ High Threat
Middle East Diplomatic Espionage
Origin Unknown
Sponsor State-sponsored
Motivation Espionage and intelligence gathering

Target Sectors

Government Diplomatic organizations Critical Infrastructure Middle Eastern regional entities

Known TTPs

Living-off-the-land (LotL) techniques
Deployment of custom-developed backdoors/implants
Use of compromised legitimate servers for C2 infrastructure
Spear-phishing for initial access
Credential harvesting
Operational security (OPSEC) focused infrastructure rotation

External Resources

CISA Advisories ↗

Related Intelligence

Hacking the mainframe…

LINK COPIED TO CLIPBOARD