Skip to content
THE HUNTER’S LEDGER
Threat Actors
Unattributed Threat Actors
The operators behind the reports. A UTA is a tracking label this publication assigns to an actor it has observed but cannot yet link to a publicly named group, so that the same operator can be recognised across reports. Each profile summarises what the reports already say and points back to them.
Sep 2026 · MODERATE 75% · 1 report · United States
UTA-2026-024
Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant
SliverchiselLigoloEtherRAT-class Node.js bot
Aug 2026 · MODERATE 72% · 1 report · Ecuador
UTA-2026-023
Telecom-focused operator reaching a carrier's credential plane through a customer's managed router
Custom WebLogic T3 suitehand-rolled LDAP exploitation serverchisel
Aug 2026 · 1 report · Germany
UTA-2026-021
Assembler-model intrusion operator staging other actors' tooling against one German victim forest
CloudSync RATParalell loaderSharp4WebCmd web shellcommercial RMM products
Jul 2026 · HIGH 85% · 1 report · China
UTA-2026-020
Self-branded commodity cryptojacking operator mass-exploiting exposed Chinese enterprise software
GOCLOUD and OmniHunter toolkitXMRigFOFA-driven scanning
Jul 2026 · MODERATE 65% · 1 report · China
UTA-2026-019
Grey-market personal-data harvester running scores of LLM-assisted attack scripts against Chinese consumer platforms
Open-source agent frameworkSoftEther VPNcommodity exploitation scripts
Jul 2026 · MODERATE · 1 report · Indonesia, Thailand, Malaysia, Philippines
UTA-2026-018
Hands-on-keyboard operator exploiting four Southeast Asian governments with a bespoke edge-device toolkit
Custom Go tunnelchiselbespoke n-day exploitation scripts
May 2026 · LOW 60% · 3 reports
UTA-2026-017
GHOST cryptojacker kit customer (operator B) using public mining pools, host abandoned
GHOST cryptojacker kitXMRig
May 2026 · LOW 65% · 3 reports
UTA-2026-016
GHOST cryptojacker kit customer (operator A) with self-hosted mining pool proxies
GHOST cryptojacker kitXMRigHysteria v2
May 2026 · LOW 55% · 2 reports
UTA-2026-015
Operator running Claude Code and OpenClaw side by side, observed at capsule depth only
Claude CodeOpenClaw
May 2026 · LOW 60% · 2 reports
UTA-2026-014
DDoS-for-hire operator running an AI co-authored C2 framework over a Pandora-Mirai botnet
Pandora-Mirai variantMatrix C2Atlassian Rovodev
May 2026 · MODERATE 78% · 3 reports · Turkey
UTA-2026-013
Espionage-flavoured operator harvesting a state-affiliated insurer's observability stack through an AI agent platform
OpenClawcustom ARPA correlation platformTimescaleDBNeo4j
May 2026 · MODERATE 83% · 4 reports · United States
UTA-2026-012 bandcampro (Trend Micro)
AI-augmented credential-mill operator using an LLM for per-target password mutation
Gemini CLIcustom Python C2Cloudflare Tunnelnuclei
May 2026 · HIGH 87% · 1 report
UTA-2026-011
Financially motivated operator weaponising a cPanel authentication bypass with a custom harvesting toolkit
Custom Python and Bash harvesterFlask C2 dashboardParklogic TDS
May 2026 · MODERATE 72% · 4 reports
UTA-2026-010
Rhadamanthys MaaS customer with a self-built loader (customer side only, never the vendor)
Rhadamanthys (vendor product)custom loader
May 2026 · MODERATE 78% · 3 reports · Russia, Iran, China, United States
UTA-2026-009
Multi-product fraud operator pairing a real VPN service with a brand-impersonation phishing library
EspoCRM back-officeMarzban panelcustom web stack
May 2026 · MODERATE 75% · 3 reports · Turkey
UTA-2026-008
Developer and operator of the BellaMain Turkish phishing-as-a-service panel
BellaMain PhaaS panel
May 2026 · LOW 58% · 1 report
UTA-2026-007
HijackLoader customer running a 15-month multi-vector phishing campaign into an AsyncRAT-class RAT
HijackLoaderPenguishRugmiAsyncRAT-class RAT
Apr 2026 · 1 report
UTA-2026-006
Stock AdaptixC2 operator with an operator-written PowerShell and .NET injection chain
AdaptixC2SharpHoundRubeusMimikatz
Apr 2026 · MODERATE 72% · 1 report
UTA-2026-005
Chaos ransomware builder user with a private five-stage crypter
Chaos ransomware builderOrcus RATUACME
Apr 2026 · 3 reports
UTA-2026-004
Developer of the OpenStrike multi-implant C2 toolkit, with a cracked Cobalt Strike arsenal
OpenStrikeCobalt Strike (cracked)CovertVPN
Apr 2026 · LOW 55% · 1 report · United States
UTA-2026-003
Commodity MaaS consumer running Shadow RAT and XWorm from one Windows VPS
Shadow RATXWormScreenConnect
Apr 2026 · MODERATE 72% · 1 report
UTA-2026-002
XiebroC2 and Covenant operator working from a Chinese-language build environment
XiebroC2Covenant
Feb 2026 · MODERATE 68% · 2 reports
UTA-2026-001
Sliver C2 operator with an automated ScareCrow, Donut and SysWhispers3 build pipeline
SliverScareCrowDonutSysWhispers3

Designations are numbered in the order they were created and are never reused. A designation whose report is published preview-style is listed once the report goes live. Confidence is the published report's figure for "one trackable operator"; named-actor attribution is INSUFFICIENT for every designation here, which is what the label means.