Full Report
2025-03-28 • Intrinsec • David Sardinha • ps1.sload, win.netsupportmanager_rat, win.remcos, win.smokeloader Open article on Malpedia
Analysis Summary
Based on the provided context, the article describes tracking **UACs (Unattributed or Undisclosed Cyber Actors)** operations, focusing on their evolution from espionage to Psychological Operations (PsyOps) and the bulletproof infrastructure they utilize. The summary below reflects the nature of the threat actor category described, rather than a single, named entity, as the source material appears to be a broad report grouping actors by behavior (UACs).
# Threat Actor: Unattributed/Undisclosed Cyber Actors (UACs)
## Attribution & Identity
The summary focuses on groups categorized as **UACs (Unattributed or Undisclosed Cyber Actors)**, whose operations span various objectives, including espionage and Psychological Operations (PsyOps). The specific report cited is from Intrinsec by David Sardinha, dated March 28, 2025.
## Activity Summary
The report tracks the operations of UACs in 2025, noting an expanding focus from traditional cyber espionage activities into more assertive **PsyOps** campaigns. A significant part of the analysis covers the use of **bulletproof providers** to host and facilitate these operations.
## Tactics, Techniques & Procedures
The TTPs discussed relate heavily to the observed toolsets and infrastructure utilized by these actors.
- Observation of espionage and PsyOps campaign tactics.
- Use of specific malware families associated with these operations:
- `ps1.sload`
- `win.netsupportmanager_rat`
- `win.remcos`
- `win.smokeloader`
## Targeting
The context describes a broad operational landscape given the nature of UACs and the transition to PsyOps.
- Sectors: Not explicitly detailed, but implied to include sectors relevant to state-sponsored espionage and public influence operations (PsyOps).
- Geography: Not explicitly detailed in the provided context block.
- Victims: Not specifically listed in the context block.
## Tools & Infrastructure
- Malware families used: `ps1.sload`, `win.netsupportmanager_rat`, `win.remcos`, `win.smokeloader`.
- Infrastructure: Heavy reliance on **bulletproof providers** for hosting malicious operations and infrastructure.
## Implications
UACs operating in 2025 demonstrate an evolution in targeting methodology, integrating traditional cyber threats (espionage) with information warfare techniques (PsyOps). Their reliance on bulletproof hosting suggests significant resourcefulness in maintaining operational security and obfuscating attribution.
## Mitigations
(No specific mitigations were detailed in the provided context block. General defense recommendations for groups using these malware families would apply, such as robust endpoint detection and rapid patching against known vulnerabilities exploited by RATs/Loaders.)