Threat Intelligence / Actor / UNC5792
UNC5792
As of 2026-08-26, UNC5792 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning phishing. Also known as UNC4221, UAC-0185, GRU. ATT&CK coverage spans 28 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1111 (Multi-Factor Authentication Interception), T1036.005 (Match Legitimate Resource Name or Location), T1078 (Valid Accounts).
Also known as: UNC4221, UAC-0185, GRU
ATT&CK techniques observed
- T1111 Multi-Factor Authentication Interception — Credential Access — observed in 2 of 2 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 1 of 2 tracked threats
- T1098.005 Device Registration — Persistence — observed in 1 of 2 tracked threats
- T1102.002 Bidirectional Communication — Command and Control — observed in 1 of 2 tracked threats
- T1123 Audio Capture — Collection — observed in 1 of 2 tracked threats
- T1204.001 Malicious Link — Execution — observed in 1 of 2 tracked threats
- T1528 Steal Application Access Token — Credential Access — observed in 1 of 2 tracked threats
- T1530 Data from Cloud Storage — Collection — observed in 1 of 2 tracked threats
- T1550 Use Alternate Authentication Material — Lateral Movement — observed in 1 of 2 tracked threats
- T1555 Credentials from Password Stores — Credential Access — observed in 1 of 2 tracked threats
- T1566 Phishing — Initial Access — observed in 1 of 2 tracked threats
- T1566.002 Spearphishing Link — Initial Access — observed in 1 of 2 tracked threats
- T1566.003 Phishing — Initial Access — observed in 1 of 2 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltration — observed in 1 of 2 tracked threats
Tracked threats
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp Linked-Device and OAuth Account Takeover — HIGH
- Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover — HIGH
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →