UNC6353
As of 2026-08-17, UNC6353 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning zero day, vulnerability. Also known as CryptoWaters. ATT&CK coverage spans 54 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel).
Also known as: CryptoWaters
ATT&CK techniques observed
- T1005 Data from Local System — Collection — observed in 3 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 3 tracked threats
- T1056 Input Capture — Collection — observed in 3 of 3 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalation — observed in 3 of 3 tracked threats
- T1082 System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- T1113 Screen Capture — Collection — observed in 3 of 3 tracked threats
- T1189 Drive-by Compromise — Initial Access — observed in 3 of 3 tracked threats
- T1203 Exploitation for Client Execution — Execution — observed in 3 of 3 tracked threats
- T1518 Software Discovery — Discovery — observed in 3 of 3 tracked threats
- T1555 Credentials from Password Stores — Credential Access — observed in 3 of 3 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- T1055 Process Injection — Privilege Escalation — observed in 2 of 3 tracked threats
- T1059.007 JavaScript — Execution — observed in 2 of 3 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
Tracked threats
- DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors (CVE-2026-20700, CVE-2025-43529, CVE-2025-31277) — CRITICAL
- Coruna iOS Exploit Kit — 23 Exploits Across 5 Chains Targeting iOS 13-17.2.1 (CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 + 20 More) — CRITICAL
- Coruna iOS Exploit Kit — Government-Grade 23-Exploit Arsenal Proliferates from Surveillance Vendor to Russian Espionage and Chinese Cybercriminals Targeting 42K+ Devices — CRITICAL
Related CVEs
CVE-2026-20700, CVE-2025-43529, CVE-2025-43520, CVE-2025-43510, CVE-2025-31277, CVE-2025-14174, CVE-2024-23222, CVE-2023-43000, CVE-2023-42917, CVE-2023-42916, CVE-2023-41993, CVE-2023-41991, CVE-2023-41990, CVE-2023-41974, CVE-2023-41064, CVE-2023-41061, CVE-2023-38606, CVE-2023-37450, CVE-2023-32435, CVE-2023-32434, CVE-2023-32409, CVE-2023-32373, CVE-2023-28206, CVE-2023-28204, CVE-2023-23529, CVE-2023-23514, CVE-2022-48503, CVE-2022-46689, CVE-2022-42856, CVE-2022-32917, CVE-2021-30952