# UNC5792

> As of 2026-08-26, UNC5792 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning phishing. Also known as UNC4221, UAC-0185, GRU. ATT&CK coverage spans 28 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1111 (Multi-Factor Authentication Interception), T1036.005 (Match Legitimate Resource Name or Location), T1078 (Valid Accounts).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** PHISHING
- **Also known as:** UNC4221, UAC-0185, GRU
- **As of:** 2026-08-26

## ATT&CK techniques observed

28 techniques observed across 2 of 2 tracked threats. Tactics: Resource Development (7), Credential Access (4), Initial Access (4), Reconnaissance (4), Collection (2), Command and Control (1).

- [T1111](https://attack.mitre.org/techniques/T1111/) Multi-Factor Authentication Interception — Credential Access — observed in 2 of 2 tracked threats
- [T1036.005](https://attack.mitre.org/techniques/T1036/005/) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts — Initial Access — observed in 1 of 2 tracked threats
- [T1098.005](https://attack.mitre.org/techniques/T1098/005/) Device Registration — Persistence — observed in 1 of 2 tracked threats
- [T1102.002](https://attack.mitre.org/techniques/T1102/002/) Bidirectional Communication — Command and Control — observed in 1 of 2 tracked threats
- [T1123](https://attack.mitre.org/techniques/T1123/) Audio Capture — Collection — observed in 1 of 2 tracked threats
- [T1204.001](https://attack.mitre.org/techniques/T1204/001/) Malicious Link — Execution — observed in 1 of 2 tracked threats
- [T1528](https://attack.mitre.org/techniques/T1528/) Steal Application Access Token — Credential Access — observed in 1 of 2 tracked threats
- [T1530](https://attack.mitre.org/techniques/T1530/) Data from Cloud Storage — Collection — observed in 1 of 2 tracked threats
- [T1550](https://attack.mitre.org/techniques/T1550/) Use Alternate Authentication Material — Lateral Movement — observed in 1 of 2 tracked threats
- [T1555](https://attack.mitre.org/techniques/T1555/) Credentials from Password Stores — Credential Access — observed in 1 of 2 tracked threats
- [T1566](https://attack.mitre.org/techniques/T1566/) Phishing — Initial Access — observed in 1 of 2 tracked threats
- [T1566.002](https://attack.mitre.org/techniques/T1566/002/) Spearphishing Link — Initial Access — observed in 1 of 2 tracked threats
- [T1566.003](https://attack.mitre.org/techniques/T1566/003/) Phishing — Initial Access — observed in 1 of 2 tracked threats
- [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration Over Web Service — Exfiltration — observed in 1 of 2 tracked threats

## Tracked threats

- [Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp Linked-Device and OAuth Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-2170) — HIGH
- [Russian FSB/GRU Actors (UNC5792, UNC4221) Phish Signal Backup Recovery Keys for Persistent Account Takeover](https://intel.threadlinqs.com/threat/TL-2026-1814) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC5792
