Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-04

UNC6780

As of 2026-09-26, UNC6780 is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning supply chain, apt. ATT&CK coverage spans 69 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1078 (Valid Accounts), T1105 (Ingress Tool Transfer).

Tracked threats
42 critical · 2 high
First seen
2026-04-30
Last seen
2026-09-26
ATT&CK techniques
69across 4 of 4 threats
Related CVEs
0None referenced
4 tracked threat(s) · Categories: SUPPLY_CHAIN, APT

Activity timeline

UNC6780 appears in 4 tracked threats between and ; the busiest month was 2026-04 with 1 report.

ATT&CK techniques observed

69 techniques observed across 4 of 4 tracked threats · Credential Access (10), Stealth (formerly Defense Evasion) (10), Command and Control (8), Initial Access (7), Discovery (6), Resource Development (5)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 3 of 4 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 4 tracked threats
  • T1195 Supply Chain Compromise — Initial Accessobserved in 3 of 4 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 3 of 4 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 4 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 4 tracked threats
  • T1059.007 JavaScript — Executionobserved in 2 of 4 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 4 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 4 tracked threats
  • T1195.001 Compromise Software Dependencies and Development Tools — Initial Accessobserved in 2 of 4 tracked threats
  • T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 2 of 4 tracked threats
  • T1518 Software Discovery — Discoveryobserved in 2 of 4 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 2 of 4 tracked threats
  • T1530 Data from Cloud Storage — Collectionobserved in 2 of 4 tracked threats

Tracked threats