216.73.216.6

Live off the Land? How About Bringing Your Own Island? An Overview of UNC1945

· Published 17/04/2026 18:32 · Modified 20/04/2026 11:22

Export JSON

Essential information

Published
17/04/2026 18:32
Modified
20/04/2026 11:22
Tags
2026-04-17 CVE-2019-0708 CVE-2020-14871 anti-forensics evilsun financial sector lemonstick logbleach managed service providers oksolo openshackle oracle solaris pam backdoor pupyrat rollcoast slapstick ssh tunneling steelcorgi tinyshell unc1945 virtual machines
Related entities
2 vulnerabilities (cve), 5 observables, 1 intrusion sets (apt), 20 techniques (mitre), 10 malware, 1 others

Description

compromised to target organizations within financial and professional consulting industries through third-party network access. The actor demonstrated advanced capabilities across , Windows, and Linux systems, utilizing custom pre-loaded with post-exploitation tools. Operations included exploiting , a zero-day vulnerability in PAM, and deploying multiple custom backdoors including , , and . The threat actor maintained persistence through , credential theft, and techniques while traversing segmented networks. With an observed dwell time of approximately 519 days, demonstrated sophisticated operational security by loading entire containing numerous exploitation tools, modifying timestamps, and selectively manipulating log files to evade detection.

External references