New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

UNC4191 Threat Group Targets Entities In The Philippines

December 1, 2022

The UNC4191 threat group was discovered targeting entities in the Philippines with custom malware and the NCAT command-line networking utility. The malicious software is written in C/C++, replicates by infecting new removable drives, and creates a reverse shell to the actor's command and control server. Registry Run keys are used for persistence while multiple legitimate binaries are leveraged for DLL Side-Loading.