# UNC2452

> As of 2026-09-29, UNC2452 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning apt, phishing. Also known as Midnight Blizzard. ATT&CK coverage spans 53 techniques across 12 tactics in 5 of 5 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1071.001 (Web Protocols), T1543.003 (Create or Modify System Process: Windows Service).

- **Nation:** Russia
- **Tracked threats:** 5
- **Categories:** APT, PHISHING
- **Also known as:** Midnight Blizzard
- **As of:** 2026-09-29

## ATT&CK techniques observed

53 techniques observed across 5 of 5 tracked threats. Tactics: Credential Access (9), Execution (7), Collection (6), Initial Access (6), Persistence (6), Command and Control (5).

- [T1528](https://attack.mitre.org/techniques/T1528/) Steal Application Access Token — Credential Access — observed in 5 of 5 tracked threats
- [T1071.001](https://attack.mitre.org/techniques/T1071/001/) Web Protocols — Command and Control — observed in 4 of 5 tracked threats
- [T1543.003](https://attack.mitre.org/techniques/T1543/003/) Create or Modify System Process: Windows Service — Persistence — observed in 4 of 5 tracked threats
- [T1548.002](https://attack.mitre.org/techniques/T1548/002/) Bypass User Account Control — Privilege Escalation — observed in 4 of 5 tracked threats
- [T1685](https://attack.mitre.org/techniques/T1685/) Disable or Modify Tools — Defense Impairment — observed in 4 of 5 tracked threats
- [T1053.005](https://attack.mitre.org/techniques/T1053/005/) Scheduled Task — Persistence — observed in 3 of 5 tracked threats
- [T1056.001](https://attack.mitre.org/techniques/T1056/001/) Keylogging — Credential Access — observed in 3 of 5 tracked threats
- [T1059.001](https://attack.mitre.org/techniques/T1059/001/) PowerShell — Execution — observed in 3 of 5 tracked threats
- [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts — Initial Access — observed in 3 of 5 tracked threats
- [T1113](https://attack.mitre.org/techniques/T1113/) Screen Capture — Collection — observed in 3 of 5 tracked threats
- [T1123](https://attack.mitre.org/techniques/T1123/) Audio Capture — Collection — observed in 3 of 5 tracked threats
- [T1547.001](https://attack.mitre.org/techniques/T1547/001/) Registry Run Keys / Startup Folder — Persistence — observed in 3 of 5 tracked threats
- [T1555.003](https://attack.mitre.org/techniques/T1555/003/) Credentials from Web Browsers — Credential Access — observed in 3 of 5 tracked threats
- [T1566.002](https://attack.mitre.org/techniques/T1566/002/) Spearphishing Link — Initial Access — observed in 3 of 5 tracked threats
- [T1027](https://attack.mitre.org/techniques/T1027/) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 5 tracked threats

## Tracked threats

- [Midnight Blizzard (GTG-20006) Used Claude AI Agents to Automate Malware Evasion, Hijack Hotel Wi-Fi (CaptiveCrunch), and Take Over WhatsApp Accounts Against Ukrainian/European Government and Drone-Supply-Chain Targets](https://intel.threadlinqs.com/threat/TL-2026-2446) — HIGH
- [Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US](https://intel.threadlinqs.com/threat/TL-2026-2091) — HIGH
- [CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate Travelers](https://intel.threadlinqs.com/threat/TL-2026-1853) — CRITICAL
- [CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign](https://intel.threadlinqs.com/threat/TL-2026-2765) — HIGH
- [Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365](https://intel.threadlinqs.com/threat/TL-2026-0323) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC2452
