Threat Intelligence / Actor / UNC6040

UNC6040

As of 2026-07-14, UNC6040 is a threat actor tracked by Threadlinqs Intelligence across 8 threats spanning phishing, data breach, threat actor. ATT&CK coverage spans 86 techniques across 15 tactics in 8 of 8 tracked threats. Most-observed techniques: T1567 (Exfiltration Over Web Service), T1078 (Valid Accounts), T1213 (Data from Information Repositories).

8 tracked threat(s) · Categories: PHISHING, DATA_BREACH, THREAT_ACTOR, THREAT_INTEL, CAMPAIGN

ATT&CK techniques observed

86 techniques observed across 8 of 8 tracked threats · Credential Access (15), Discovery (9), Initial Access (9), Persistence (9), Resource Development (9), Stealth (formerly Defense Evasion) (8)

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence