Threat Intelligence / Actor / UNC6353

UNC6353

As of 2026-08-17, UNC6353 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning zero day, vulnerability. Also known as CryptoWaters. ATT&CK coverage spans 54 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel).

Nation: Russia · 3 tracked threat(s) · Categories: ZERO_DAY, VULNERABILITY

Also known as: CryptoWaters

ATT&CK techniques observed

54 techniques observed across 3 of 3 tracked threats · Command and Control (9), Resource Development (9), Stealth (formerly Defense Evasion) (8), Collection (6), Credential Access (5), Execution (5)

Tracked threats

Related CVEs

31 CVEs referenced by tracked UNC6353 activity

CVE-2026-20700, CVE-2025-43529, CVE-2025-43520, CVE-2025-43510, CVE-2025-31277, CVE-2025-14174, CVE-2024-23222, CVE-2023-43000, CVE-2023-42917, CVE-2023-42916, CVE-2023-41993, CVE-2023-41991, CVE-2023-41990, CVE-2023-41974, CVE-2023-41064, CVE-2023-41061, CVE-2023-38606, CVE-2023-37450, CVE-2023-32435, CVE-2023-32434, CVE-2023-32409, CVE-2023-32373, CVE-2023-28206, CVE-2023-28204, CVE-2023-23529, CVE-2023-23514, CVE-2022-48503, CVE-2022-46689, CVE-2022-42856, CVE-2022-32917, CVE-2021-30952

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence