Skip to content
THE HUNTER’S LEDGER
Threat Actor
UTA-2026-024
Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant
Status
Active
Distinct actor
MODERATE 75%
Named actor
INSUFFICIENT
First observed
7 Sep 2026
Last updated
7 Sep 2026
Motivation
Access and tunnelling; ransomware deployment by this operator held at LOW
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-024 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.

Summary

An intrusion set that reached Domain Admin in a US organisation, whose second implant resolves its C2 from an Ethereum contract that logs every rotation publicly. The infrastructure served a confirmed ransomware deployment during this operator's tenancy, but whether this operator or a partner deployed the encryptor cannot be settled.

The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.

Targeting

Regions
United States
Sectors
Windows enterprise estate

Reached Domain Admin in one US organisation; the encryptor deployment is attributed only as a graded attribute.

Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.

Reports

Actor identifiers

Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.

contract 0xb3f2897f2bc797e5b9033faef8c81e92b01cb831 Ethereum contract the second implant resolves its C2 from
user-agent Chrome/108.0.6602.492 internally impossible User-Agent in the Sliver beacon

Infrastructure and tooling

Primary host
193.233.202.17 (the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)
Tooling
SliverchiselLigoloEtherRAT-class Node.js bot

MITRE ATT&CK

58 techniques across 12 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.

Resource Development

Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.