Live off the Land? How About Bringing Your Own Island? An Overview of UNC1945
Essential information
- Published
- 17/04/2026 18:32
- Modified
- 20/04/2026 11:22
- Tags
- 2026-04-17 CVE-2019-0708 CVE-2020-14871 anti-forensics evilsun financial sector lemonstick logbleach managed service providers oksolo openshackle oracle solaris pam backdoor pupyrat rollcoast slapstick ssh tunneling steelcorgi tinyshell unc1945 virtual machines
- Related entities
- 2 vulnerabilities (cve), 5 observables, 1 intrusion sets (apt), 20 techniques (mitre), 10 malware, 1 others
Description
UNC1945 compromised managed service providers to target organizations within financial and professional consulting industries through third-party network access. The actor demonstrated advanced capabilities across Oracle Solaris, Windows, and Linux systems, utilizing custom virtual machines pre-loaded with post-exploitation tools. Operations included exploiting CVE-2020-14871, a zero-day vulnerability in Oracle Solaris PAM, and deploying multiple custom backdoors including SLAPSTICK, LEMONSTICK, and STEELCORGI. The threat actor maintained persistence through SSH tunneling, credential theft, and anti-forensics techniques while traversing segmented networks. With an observed dwell time of approximately 519 days, UNC1945 demonstrated sophisticated operational security by loading entire virtual machines containing numerous exploitation tools, modifying timestamps, and selectively manipulating log files to evade detection.