Mandiant has identified a new ALPHV (BlackCat ransomware) affiliate, identified as UNC4466, that targets publicly exposed Veritas Backup Exec installations vulnerable to CVE-2021-27876, CVE-2021-27877, and CVE-2021-27878 for an initial intrusion into victims’ networks. A commercial web scanning service has identified more than 8,500 Veritas Backup Exec installations exposed online – some unpatched and vulnerable. According to Mandiant’s research into previous ALPHV intrusions, stolen credentials are a key factor in this shift toward opportunistic targeting of known vulnerabilities. This post will walk you through the full UNC4466 attack cycle, as well as provide pointers to detection opportunities.
In November 2021, ALPHV emerged as a ransomware-as-a-service that some researchers say is the successor to BLACKMATTER and DARKSIDE. While other ransomware operators enforced rules to avoid hitting critical infrastructure or healthcare entities, ALPHV continued to relentlessly target these sensitive sectors.

Attack phases
Initial breach and foothold creation
In late 2022, UNC4466 gained access to an internet-exposed Windows server running Veritas Backup Exec version 21.0 using the Metasploit module “exploit/multi/veritas/beagent_sha_auth_rce.” Shortly thereafter, the Metasploit persistence module was used to maintain persistent access to the system for the remainder of this intrusion.
Internal Recognition
After gaining access to the Veritas Backup Exec server, UNC4466 used Internet Explorer – which is installed by default on outdated Windows systems – to download Famatech’s Advanced IP Scanner from its website, hxxps://download.advanced-ip-scanner[.]com. This program is able to thoroughly scan individual IP addresses or address ranges for any open ports and provides details such as hostnames, operating system information and hardware manufacturer.
In its attack, UNC4466 used ADRecon to collect network data, account access information, and host details from the victim's system. This tool is triggered by a privileged domain user, which then generates reports on Active Directory, such as Trusts, Site Subnets, and password policies, along with other basic details such as user accounts or computer lists. These can be exported in various formats such as CSV, XML, JSON, and HTML for further evaluation and analysis.
The UNC4466 malicious group relied heavily on the Background Intelligent Transfer Service (BITS) to download a variety of tools that included LAZAGNE, LIGOLO, WINSW, RCLONE, and finally, the ALPHV ransomware encryptor.
Command and Control
To communicate with the victim's network, UNC4466 used SOCKS5 tunneling, a technique commonly used to bypass security systems and other network defensive controls. They did this through two different tools: LIGOLO and REVSOCKS.
Privilege escalation
The malicious actor used various credential access tools, such as Mimikatz, LaZagne, and Nanodump, to obtain plaintext passwords and other confidential information.
In November 2022, the UNC4466 threat actor used the MIMIKATZ security support provider injection module ("MISC::MemSSP"). This module collects cleartext credentials as they are used, manipulating the Local Security Authority Server Service (LSASS) on victim systems. This module creates a file named `C:\Windows\System32\mimilsa.log`.


[Nanodump] was also used to dump the LSASS memory. Like the examples shown on the Helpsystems GitHub page, the output file specified was a file in the `C:\Windows\Temp\ directory.
Avoiding detection
UNC4466 uses a variety of tactics to evade detection. Not only does it delete event logs, but it also uses the Set-MpPreference cmdlet to disable Microsoft Defender.
Command and Control
By leveraging BITS transfers (Start-BitsTransfer PowerShell cmdlet) to transfer resources directly to the `c:\ProgramData` staging directory, UNC4466 was able to access and download two key SOCKS5 tunneling tools, REVSOCKS & LIGOLO, from their respective GitHub repositories.
Completed mission
In late 2022, UNC4466 implemented a default domain policy with immediate tasks to disable security applications and install the Rust-based ALPHV ransomware. Once downloaded, the cryptographer was automatically launched.

Revelation
As of the date of this blog post, an Internet scanning service found over 8,500 IP addresses broadcasting a “Symantec/Veritas Backup Exec ndmp” service on three different ports – 10000, 9000, and 10001. It is worth noting that while these results do not precisely identify vulnerable systems, as their application versions are unknown, they demonstrate how common publicly exposed instances are that can be exploited by potential hackers.
Information source: mandiant.com
