APT / THREAT GROUP
Unidentified 066
2
aliases
Last seen:Mar 17, 2026
Intelligence Profile
This .net executable can receive commands from c2 sever, upload and download files according to the returned content, perform an uninstall, or modify the registry to achieve persistence across reboots. At the end, it downloads a Python-based RAT, called PeppyRAT.
Threat Analysis
Unidentified 066 is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
External References
Quick Facts
TypeAPT / Threat Group
Aliases2
Also Known As
Unidentified 066win.unidentified_066
External Intelligence
Malpedia: win.unidentified_066Research Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.