Activity timeline
UNC6692 appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1018 Remote System Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1020 Automated Exfiltration — Exfiltrationobserved in 2 of 2 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 2 of 2 tracked threats
- T1074 Data Staged — Collectionobserved in 2 of 2 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 2 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 2 tracked threats
- T1113 Screen Capture — Collectionobserved in 2 of 2 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1202 Indirect Command Execution — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 2 of 2 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 2 of 2 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 1 of 2 tracked threats
- T1003.001 LSASS Memory — Credential Accessobserved in 1 of 2 tracked threats
- T1003.002 Security Account Manager — Credential Accessobserved in 1 of 2 tracked threats