Threat Intelligence / Actor / UNC5792

UNC5792

As of 2026-08-26, UNC5792 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning phishing. Also known as UNC4221, UAC-0185, GRU. ATT&CK coverage spans 28 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1111 (Multi-Factor Authentication Interception), T1036.005 (Match Legitimate Resource Name or Location), T1078 (Valid Accounts).

Nation: Russia · 2 tracked threat(s) · Categories: PHISHING

Also known as: UNC4221, UAC-0185, GRU

ATT&CK techniques observed

28 techniques observed across 2 of 2 tracked threats · Resource Development (7), Credential Access (4), Initial Access (4), Reconnaissance (4), Collection (2), Command and Control (1)

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence