LightBasin__2021__fireeye.com-Live_off_the_Land_How_About_Bringing_Your_Own_Island_An_Overview_of_UNC1945.pdf
ID: 4af3b9f0-69de-4c1f-961a-bbca712d41bf
STIX ID: report--4af3b9f0-69de-4c1f-961a-bbca712d41bf
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2021-01-14
Last Modified Date: 2021-01-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant describes UNC1945 as a highly capable threat actor that exploited an Oracle Solaris zero-day (CVE-2020-14871) and other weaknesses to compromise managed service providers and targeted organizations, deploying custom backdoors (SLAPSTICK, LEMONSTICK), a Solaris/Linux exploitation tool (EVILSUN), and anti-forensic utilities; the report documents long dwell time, SSH tunneling and VM-based operational environments, provides IOCs (hashes, netblocks, detections), and warns of continued targeted activity.
