CSIDB logo
Threat actor

UNC788

Attribution profile

Type
Nation State
Location
Iran
Known incidents
1 incident
First seen
2022-02-15
Last seen
2022-02-15
Updated
2026-07-15 08:39
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

UNC788 is a threat actor known by that alias and has been publicly linked to operations originating from Iran. The actor’s identity is primarily defined by this alias, with no additional names or variations disclosed in the available material. Geographic attribution to Iran is explicitly stated in the context provided, establishing a clear point of origin for the group’s activities. No further details about the actor’s size, structure, or internal organization are available from the source information.

The targeting pattern evidenced in the reported incident focuses on Ukrainian military agencies and state‑owned banks, indicating a focus on defense and financial sectors within Ukraine. The strategic objective observed was disruption, as the campaign employed distributed denial‑of‑service techniques to cause website outages, block online banking access, trigger login failures, impede payment processing, impair mobile applications, and display erroneous transaction data. Additionally, coordinated false text messages about ATM outages were used to amplify public confusion, supporting a broader aim of undermining confidence in Ukrainian institutions. The only tactical theme explicitly referenced is the use of DDoS attacks as the primary method, with no mention of specific malware families, initial access vectors, or particular tooling styles employed by UNC788.

Attribution of the described DDoS operation was made by authorities to a hybrid warfare campaign that they linked to the Gamaredon threat group, which is associated with Russian intelligence services. This connection establishes a state nexus for the activity, although the direct relationship between UNC788 and Gamaredon is not elaborated beyond the incident being attributed to the latter. The operation carried out on 15 February 2022 serves as a representative example of UNC788’s publicly reported activity, illustrating the actor’s capacity to conduct large‑scale disruption efforts against critical Ukrainian infrastructure. No other campaigns or techniques are detailed in the supplied information, so the profile remains confined to these confirmed facts.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB