logo

LightBasin__2021__fireeye.com-Live_off_the_Land_How_About_Bringing_Your_Own_Island_An_Overview_of_UNC1945.pdf

ID: 4af3b9f0-69de-4c1f-961a-bbca712d41bf

STIX ID: report--4af3b9f0-69de-4c1f-961a-bbca712d41bf

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2021-01-14

Last Modified Date: 2021-01-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant describes UNC1945 as a highly capable threat actor that exploited an Oracle Solaris zero-day (CVE-2020-14871) and other weaknesses to compromise managed service providers and targeted organizations, deploying custom backdoors (SLAPSTICK, LEMONSTICK), a Solaris/Linux exploitation tool (EVILSUN), and anti-forensic utilities; the report documents long dwell time, SSH tunneling and VM-based operational environments, provides IOCs (hashes, netblocks, detections), and warns of continued targeted activity.