Threat Intelligence / Actor / UNC2452

UNC2452

As of 2026-09-29, UNC2452 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning apt, phishing. Also known as Midnight Blizzard. ATT&CK coverage spans 53 techniques across 12 tactics in 5 of 5 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1071.001 (Web Protocols), T1543.003 (Create or Modify System Process: Windows Service).

Nation: Russia · 5 tracked threat(s) · Categories: APT, PHISHING

Also known as: Midnight Blizzard

ATT&CK techniques observed

53 techniques observed across 5 of 5 tracked threats · Credential Access (9), Execution (7), Collection (6), Initial Access (6), Persistence (6), Command and Control (5)

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence