UNC757

Threat Actor updated 6 months ago (2024-05-04T19:03:30.186Z)
Download STIX
Preview STIX
UNC757, also known as Pioneer Kitten or Parisite, is a threat actor recognized for its malicious activities in the cybersecurity landscape. This group's indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs) have been analyzed, leading to the identification of a correlation between this group and other clusters of activity operated by Iranian threat actors. The naming conventions used to identify such groups can often be complex and inconsistent across the cybersecurity industry, but there is little doubt about the harmful intent behind UNC757's actions. The group has shown a concentrated focus on targeting Israeli entities and organizations, as well as those operating within Israel. This pattern aligns with the broader operational tendencies observed among Iranian threat actors, specifically UNC757. Their sophisticated cyber-attacks pose significant security threats to these organizations, potentially disrupting their operations and compromising sensitive data. In a recent incident, Hartman identified the Iranian hackers from UNC757 as the culprits behind an attack on an unspecified elections website. The details of the targeted website were not disclosed, but the incident underscores the group's capabilities and their potential impact on critical infrastructures. As such, organizations must remain vigilant and adopt robust cybersecurity measures to defend against these persistent and evolving threats.
Description last updated: 2023-10-10T21:22:37.233Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Pioneer Kitten is a possible alias for UNC757. Pioneer Kitten, also known as UNC757, Parisite, Lemon Sandstorm, and Rubidium, is a threat actor believed to be associated with the Government of Iran (GOI) and an Iranian IT company. This group has been tracked by various cybersecurity entities such as CrowdStrike Intelligence and the FBI. Investig
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the UNC757 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more