Threat Intelligence / Actor / UNC2452
UNC2452
As of 2026-09-29, UNC2452 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning apt, phishing. Also known as Midnight Blizzard. ATT&CK coverage spans 53 techniques across 12 tactics in 5 of 5 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1071.001 (Web Protocols), T1543.003 (Create or Modify System Process: Windows Service).
Also known as: Midnight Blizzard
ATT&CK techniques observed
- T1528 Steal Application Access Token — Credential Access — observed in 5 of 5 tracked threats
- T1071.001 Web Protocols — Command and Control — observed in 4 of 5 tracked threats
- T1543.003 Create or Modify System Process: Windows Service — Persistence — observed in 4 of 5 tracked threats
- T1548.002 Bypass User Account Control — Privilege Escalation — observed in 4 of 5 tracked threats
- T1685 Disable or Modify Tools — Defense Impairment — observed in 4 of 5 tracked threats
- T1053.005 Scheduled Task — Persistence — observed in 3 of 5 tracked threats
- T1056.001 Keylogging — Credential Access — observed in 3 of 5 tracked threats
- T1059.001 PowerShell — Execution — observed in 3 of 5 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 3 of 5 tracked threats
- T1113 Screen Capture — Collection — observed in 3 of 5 tracked threats
- T1123 Audio Capture — Collection — observed in 3 of 5 tracked threats
- T1547.001 Registry Run Keys / Startup Folder — Persistence — observed in 3 of 5 tracked threats
- T1555.003 Credentials from Web Browsers — Credential Access — observed in 3 of 5 tracked threats
- T1566.002 Spearphishing Link — Initial Access — observed in 3 of 5 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 5 tracked threats
Tracked threats
- Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets — HIGH
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US — HIGH
- CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate Travelers — CRITICAL
- CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign — HIGH
- Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365 — HIGH
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →