Home Cyber Security

Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

Advice from Mandiant Incident Response

A financially motivated threat actor known as UNC3944, with operational overlaps reported with the Scattered Spider group, poses a significant and evolving cyber threat. Initially targeting telecommunications-related organisations to facilitate SIM swap operations, UNC3944 has broadened its scope to impact a diverse range of industries. Since early 2023, this threat actor has increasingly engaged in ransomware and data theft extortion, demonstrating a persistent and adaptable approach to cybercrime. Notably, UNC3944 has recently focused on financial services organisations in late 2023 and food services in May 2024, suggesting a potential shift in targeting strategy, possibly aimed at increasing prestige and attracting media attention.

Recent observations from Google Threat Intelligence Group (GTIIG) indicate a potential temporary decline in UNC3944 activity following increased law enforcement actions against individuals allegedly associated with the group after 2024. It is plausible that such actions may temporarily disrupt their operations, leading them to halt or significantly curtail their activities, rebuild their capabilities or partnerships, or adapt their tactics to evade detection. However, UNC3944’s established infrastructure and existing toolsets present a continued risk, potentially enabling other threat actors within the broader cybercriminal community to leverage their resources for malicious purposes.

Recent public reporting has implicated threat actors using tactics consistent with Scattered Spider in targeting a UK retail organisation and deploying DragonForce ransomware. Subsequent reporting by BBC News further indicated that actors associated with DragonForce claimed responsibility for attacks on multiple UK retailers. Notably, the operators of DragonForce ransomware had seemingly claimed control of RansomHub, a ransomware-as-a-service (RaaS) affiliate program, in March 2024. This development is significant as UNC3944 was a RansomHub affiliate in 2024, prior to the ALPHV (aka BlackCat) RaaS shut down. While GTIIG has not independently confirmed the direct involvement of UNC3944 or the DragonForce RaaS in these specific retail incidents, the past affiliations and tactical overlaps warrant close monitoring.

Over the past several years, retail organisations have been increasingly targeted by tracked data leak sites (DLS) used by extortion actors to pressure victims and/or leak stolen victim data. Retail organisations accounted for 11 percent of DLS victims thus far in 2025, up from about 8.5 percent in 2024 and 6 percent in 2022 and 2023. This upward trend underscores the growing attractiveness of the retail sector to financially motivated cybercriminals.

Given the evolving tactics and broadening target scope of UNC3944 and related threat actors, organizations across various sectors, particularly retail, financial services, and food services, must adopt a proactive and robust cybersecurity posture. The following guidance outlines key hardening measures to defend against such threats:

1. Enhance Multifactor Authentication (MFA): Implement strong MFA across all critical systems and accounts, including email, VPNs, and internal applications. Ensure that MFA is enforced and not bypassable, and consider using phishing-resistant methods where possible.

2. Strengthen Password Policies: Enforce complex password requirements, mandate regular password resets, and prohibit the reuse of previous passwords. Educate employees on the importance of strong, unique passwords and the risks associated with password reuse.

3. Implement Robust Phishing Awareness Training: Conduct regular and comprehensive training programs to educate employees on identifying and reporting phishing attempts, including social engineering tactics commonly employed by UNC3944. Simulate phishing attacks to assess employee awareness and identify areas for improvement.

4. Enhance Endpoint Detection and Response (EDR): Deploy and maintain a robust EDR solution on all endpoints to provide real-time monitoring, threat detection, and automated response capabilities. Ensure that the EDR solution is properly configured and actively monitored by a security operations team.

5. Implement Network Segmentation: Segment the internal network to limit the lateral movement of attackers in the event of a breach. Isolate critical systems and data assets to minimize the potential impact of a successful intrusion.

6. Maintain Up-to-Date Patch Management: Establish a rigorous patch management process to promptly identify and apply security updates to all operating systems, applications, and firmware. Vulnerabilities in unpatched systems are a common entry point for threat actors.

7. Implement Data Loss Prevention (DLP) Measures: Deploy DLP tools and policies to identify, monitor, and prevent the exfiltration of sensitive data. This can help mitigate the impact of data theft extortion attempts.

8. Enhance Incident Response Capabilities: Develop and regularly test a comprehensive incident response plan to effectively detect, contain, eradicate, and recover from cyber incidents. Ensure that the plan includes specific procedures for ransomware and data extortion scenarios.

9. Implement Regular Security Assessments and Penetration Testing: Conduct periodic vulnerability assessments and penetration testing to identify weaknesses in the security posture and simulate real-world attacks. This can help uncover potential entry points and areas for improvement.

10. Monitor Threat Intelligence: Stay informed about the latest threat intelligence, including the tactics, techniques, and procedures (TTPs) used by UNC3944 and related threat actors. Leverage threat intelligence to proactively update security controls and detection rules.

By implementing these proactive security measures, organizations can significantly reduce their risk of falling victim to UNC3944 and other sophisticated cybercriminal groups. Continuous vigilance, employee education, and a layered security approach are crucial in defending against the evolving cyber threat landscape.