Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-02

UNC5537

As of 2026-10-04, UNC5537 is a threat actor tracked by Threadlinqs Intelligence across 6 threats spanning data breach, threat actor, threat intel. ATT&CK coverage spans 82 techniques across 14 tactics in 6 of 6 tracked threats. Most-observed techniques: T1530 (Data from Cloud Storage), T1657 (Financial Theft), T1078 (Valid Accounts).

Tracked threats
61 critical · 5 high
First seen
2026-02-02
Last seen
2026-10-04
ATT&CK techniques
82across 6 of 6 threats
Related CVEs
0None referenced
6 tracked threat(s) · Categories: DATA_BREACH, THREAT_ACTOR, THREAT_INTEL, CAMPAIGN

Activity timeline

UNC5537 appears in 6 tracked threats between and ; the busiest month was 2026-02 with 5 reports.

ATT&CK techniques observed

82 techniques observed across 6 of 6 tracked threats · Credential Access (15), Resource Development (11), Initial Access (9), Collection (7), Discovery (7), Impact (7)
  • T1530 Data from Cloud Storage — Collectionobserved in 6 of 6 tracked threats
  • T1657 Financial Theft — Impactobserved in 6 of 6 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 5 of 6 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 5 of 6 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 5 of 6 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 5 of 6 tracked threats
  • T1566 Phishing — Initial Accessobserved in 5 of 6 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 5 of 6 tracked threats
  • T1588 Obtain Capabilities — Resource Developmentobserved in 5 of 6 tracked threats
  • T1074 Data Staged — Collectionobserved in 4 of 6 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 4 of 6 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 4 of 6 tracked threats
  • T1119 Automated Collection — Collectionobserved in 4 of 6 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 4 of 6 tracked threats
  • T1204 User Execution — Executionobserved in 4 of 6 tracked threats

Tracked threats