basicsecurity.net
Proof, not just disclosure.
Threats / Actors / UNC2452
G0118 Nation-stateour call,
not MITRE’s
Revoked by ATT&CK

UNC2452

How MITRE ATT&CK characterizes this group1: UNC2452 is a suspected Russian state-sponsored threat group responsible for the 2020 SolarWinds software supply chain intrusion. Victims of this campaign include government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. The group also compromised at least one think tank by late 2019.

Origin / sponsor: not established from a curated public advisory — see Coverage & confidence. Not asserted here.

Also tracked as: NOBELIUM StellarParticle Dark Halo — ATT&CK group page1
Read this as · tier is our editorial call, not MITRE’s

Read as a state-directed operator, not a smash-and-grab.

A nation-state classification means patience, tradecraft, and an intelligence objective. When this name attaches to a vulnerability, the question shifts from “will someone exploit it” to “has a well-resourced service already built it into an operation.” All tradecraft below is sourced to MITRE ATT&CK.

0
Techniques
ATT&CK count1
0
Named tools / malware
ATT&CK count2
0
Attributed campaigns
ATT&CK count1
0
Tactics spanned
ATT&CK count1
coverage gap
Activity bounds
no attributed campaign
01

Known for

— signature moves, each sourced to ATT&CK
SparseATT&CK carries no campaigns or software for this group at this snapshot — the signature moves are a coverage gap, stated not hidden.
02

Tradecraft heatmap

— ATT&CK techniques mapped onto the five attacker-outcome narratives

No techniques are recorded for this group in the ATT&CK snapshot below — the tradecraft heatmap is empty. That is an honest coverage gap (sparse / legacy / revoked group), never a claim that the actor does nothing.1

03

Arsenal

— named tools & malware ATT&CK attributes to this group
No named arsenalCoverage gap

ATT&CK attributes no software to G0118 at this snapshot. Absence is a finding, not a claim of harmlessness.

04

Campaign highlights

— attributed operations in the ATT&CK record
?

No attributed campaigns — coverage gap

Stated, not hidden
ATT&CK lists no first-class campaign object for G0118 at this snapshot. Public reporting may tie this actor to operations; those enter only with a named advisory under the same cite-or-die rule.
05

Latest activity

— with explicit confidence, and what we cannot yet claim
ATT&CK
snapshot

The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.

ATT&CK snapshot, compiled 2026-06-22Coverage gap — live “currently active” status not asserted
CVE ↔ actor bridge: no confirmed CVE link is established for this group. ATT&CK provides no first-class group→CVE relationship, so this card does not claim specific CVEs as “exploited by this actor” unless a named advisory says so. Absence of a CVE here is a coverage gap, never a clean bill — confirmed links surface as a cited, linked list as the advisory bridge grows.
06

Coverage & confidence

— what we know, and what we don’t

Established (cited)

  • Group identity, aliases, description — MITRE ATT&CK group page
  • 4 third-party research citations — ATT&CK external references
  • Coverage gaps — stated, not hidden

  • Origin/sponsor not established from a curated public advisory. ATT&CK prose may imply attribution but is not asserted here — absence of a curated source is a coverage finding, not a clean bill of attribution.
  • Threat tier is OUR editorial classification (rule-based), not a MITRE field — labeled as such.
  • Technique → outcome heatmap is editorial alignment over ATT&CK tactic data, not a separately-sourced MITRE edge.
  • Activity bounds are a floor from attributed-campaign dates only — flagged approx., not a true active-since range.
  • ATT&CK has no first-class group→CVE relationship; this card asserts no specific CVE without a named advisory.
  • No techniques attributed to this group in ATT&CK — a real source coverage gap, surfaced honestly, never fabricated.
  • No attributed ATT&CK campaign object — activity bounds cannot be established.
  • Empty heatmap column(s): Front door, Keys to kingdom, Lateral reach, Data at risk, Lights out — consistent with this actor's nature, stated as a finding.