UNC6240
· Published 15/06/2026 21:16 · Modified 15/06/2026 21:16
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 15/06/2026 21:16
- Modified
- 15/06/2026 21:16
- Updated at
- 15/06/2026 21:16
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 20 attack patterns (mitre), 1 malware, 1 sectors, 1 countries, 8 indicators, 1 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
AlienVault Confidence 100 1 CVE 20 MITREs 1 Malware 8 IOCs 8 Observables 1 APTPublished 11/06/2026 23:09 · Modified 15/06/2026 19:16 · threat-report
Attack patterns (MITRE) (20)
-
T1027 usesObfuscated Files or Information
-
T1505.003 usesWeb Shell
-
T1133 usesExternal Remote Services
-
T1552.001 usesCredentials In Files
-
T1069 usesPermission Groups Discovery
-
T1078 usesValid Accounts
-
T1190 usesExploit Public-Facing Application
-
T1491 usesDefacement
-
T1021.004 usesSSH
-
T1083 usesFile and Directory Discovery
-
T1041 usesExfiltration Over C2 Channel
-
T1059.004 usesUnix Shell
-
T1110.001 usesPassword Guessing
-
T1114 usesEmail Collection
-
T1036.005 usesMatch Legitimate Resource Name or Location
-
T1018 usesRemote System Discovery
-
T1573.002 usesAsymmetric Cryptography
-
T1486 usesData Encrypted for Impact
-
T1071.001 usesWeb Protocols
-
T1560.001 usesArchive via Utility
Malware (1)
-
MeshCentral usesFamilyPublished 11/06/2026 21:09 · Modified 11/06/2026 21:09
Sectors (1)
- Education targets
Countries (1)
- United States of America targets
Indicators (8)
-
68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309indicates -
c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711findicates -
f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fcindicates -
176.120.22.24indicates -
azurenetfiles.netindicates -
d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2findicates -
2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35indicates -
http://azurenetfiles.net:443/agent.ashxindicates
Vulnerabilities (CVE) (1)
CVE-2026-35273
KEV
9.8
Critical
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 11/06/2026
- Modified
- 12/06/2026