Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-02

UNC6240

As of 2026-09-29, UNC6240 is a threat actor tracked by Threadlinqs Intelligence across 9 threats spanning data breach, vulnerability, threat actor. ATT&CK coverage spans 123 techniques across 15 tactics in 9 of 9 tracked threats. Most-observed techniques: T1657 (Financial Theft), T1552 (Unsecured Credentials), T1583 (Acquire Infrastructure).

Tracked threats
93 critical · 6 high
First seen
2026-02-02
Last seen
2026-07-14
ATT&CK techniques
123across 9 of 9 threats
Related CVEs
3Referenced by its activity
9 tracked threat(s) · Categories: DATA_BREACH, VULNERABILITY, THREAT_ACTOR, THREAT_INTEL, CAMPAIGN

Activity timeline

UNC6240 appears in 9 tracked threats between and ; the busiest month was 2026-02 with 5 reports.

ATT&CK techniques observed

123 techniques observed across 9 of 9 tracked threats · Credential Access (16), Discovery (16), Resource Development (13), Persistence (11), Initial Access (10), Reconnaissance (10)
  • T1657 Financial Theft — Impactobserved in 9 of 9 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 8 of 9 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 8 of 9 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 7 of 9 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 7 of 9 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 7 of 9 tracked threats
  • T1537 Transfer Data to Cloud Account — Exfiltrationobserved in 7 of 9 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 6 of 9 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 6 of 9 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 6 of 9 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 6 of 9 tracked threats
  • T1566 Phishing — Initial Accessobserved in 6 of 9 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 6 of 9 tracked threats
  • T1588 Obtain Capabilities — Resource Developmentobserved in 6 of 9 tracked threats
  • T1589 Gather Victim Identity Information — Reconnaissanceobserved in 6 of 9 tracked threats

Tracked threats

Related CVEs

3 CVEs referenced by tracked UNC6240 activity