UNC-6179: Unmasking a Persistent Threat Actor Leveraging Bitbucket Cloud for Global Malware Campaigns

No ratings

Presented at Hack Sydney 2025 by

UNC-6179 is a Threat Actor tracked by Mandiant who has been involved in distributing malware and performing spearphishing with malware implants attached (BADREAD, AdvancedInstaller) using the PDFast software lure, targeted attacks against Tech, Finance, Government entities in Canada, Switzerland, United Kingdom and United States since 2024. However, this TA has been active since 2018, this talk is about the one mistake made by the TA, which lead to multiple malware tools, IoCs and TTPs being linked back to them.