# UNC6780

> As of 2026-09-26, UNC6780 is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning supply chain, apt. ATT&CK coverage spans 69 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1078 (Valid Accounts), T1105 (Ingress Tool Transfer).

- **Tracked threats:** 4
- **Categories:** SUPPLY_CHAIN, APT
- **As of:** 2026-09-26

## ATT&CK techniques observed

69 techniques observed across 4 of 4 tracked threats. Tactics: Credential Access (10), Stealth (formerly Defense Evasion) (10), Command and Control (8), Initial Access (7), Discovery (6), Resource Development (5).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 4 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 4 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 4 tracked threats
- [T1195](https://intel.threadlinqs.com/technique/T1195) Supply Chain Compromise — Initial Access — observed in 3 of 4 tracked threats
- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 3 of 4 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 4 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 4 tracked threats
- [T1059.007](https://intel.threadlinqs.com/technique/T1059.007) JavaScript — Execution — observed in 2 of 4 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 4 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 4 tracked threats
- [T1195.001](https://intel.threadlinqs.com/technique/T1195.001) Compromise Software Dependencies and Development Tools — Initial Access — observed in 2 of 4 tracked threats
- [T1195.002](https://intel.threadlinqs.com/technique/T1195.002) Compromise Software Supply Chain — Initial Access — observed in 2 of 4 tracked threats
- [T1518](https://intel.threadlinqs.com/technique/T1518) Software Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1526](https://intel.threadlinqs.com/technique/T1526) Cloud Service Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 2 of 4 tracked threats

## Tracked threats

- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — HIGH
- [Miasma Supply Chain Attack Toolkit Open-Sourced on GitHub (Shai-Hulud / Mini Shai-Hulud Variant)](https://intel.threadlinqs.com/threat/TL-2026-0736) — CRITICAL
- [GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day Exploit (2FA Bypass), PROMPTFLUX/HONESTCUE/CANFAIL/LONGSTREAM/PROMPTSPY AI-Enabled Malware, and APT27/APT45/UNC2814/UNC5673/UNC6201/TeamPCP AI-Augmented Operations](https://intel.threadlinqs.com/threat/TL-2026-0495) — HIGH
- [lightning PyPI Package Compromise — Versions 2.6.2 & 2.6.3 Execute Bun-Based JavaScript Credential Stealer on Import (Shai-Hulud-Overlapping)](https://intel.threadlinqs.com/threat/TL-2026-0444) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC6780
