Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC2970

Also known as: energy industries, Temp.Hermit, TOUCHSHIFT, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, BURNBOOK, TEARPAGE, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code

Description

UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes, often utilizing fake LinkedIn accounts to engage victims. The group employs the PLANKWALK backdoor and other malware families, leveraging compromised WordPress sites for command and control. They have been observed using BYOVD techniques to exploit vulnerable drivers for evading detection. Mandiant has noted a shift in UNC2970's targeting strategy, including a focus on security researchers and advancements in their operational capabilities against EDR tools.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Media
Energy
Healthcare
Education
Manufacturing
Aerospace
Non profit
Critical infrastructure
Transportation
Information technology
Pharmaceutical
Aviation
Hospitality
Retail
Chemical
Think tank
Gaming
Entertainment
Mining
Legal services
Nuclear
Maritime
Oil gas
Construction
Utilities

Targeted Countries / Regions

US
CN
KP
KR
RU
IR
JP
GB
IL
VN
AU
SG
SA
PK
TW
AE
UA
IN
DE
BY
TR
MX
ES
PL
CA
NL
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

· 1 week ago

Executive Summary

UNC2970 is a North Korean threat actor known for sophisticated cyber operations, primarily involving spear-phishing campaigns with job recruitment themes. The group leverages fake LinkedIn accounts and malware like PLANKWALK to compromise targets, often using compromised WordPress sites for command and control. Recent activity indicates an increased focus on targeting security researchers and enhanced capabilities against EDR tools.

Goals & Targeting

UNC2970 likely operates under the strategic goals of a North Korean state-sponsored entity, possibly with objectives aimed at espionage, disruption, or financial gain. The group's targeting has evolved to focus on individuals within security firms and research organizations, which could be linked to efforts to compromise cybersecurity defenses or gather intelligence on Western defense mechanisms. Their choice of sectors suggests a desire to target high-value assets with significant intellectual property or sensitive data.

Enhanced Description

UNC2970 operates as a North Korean state-affiliated threat actor group that primarily employs phishing-based attacks to target individuals within organizations. The group is known to utilize fake LinkedIn profiles to reach victims, sending emails that appear to be job offers or related business communications. These emails often contain malicious links or attachments, which, when clicked, deploy payloads such as the PLANKWALK backdoor or other malware families. Once established on a victim's system, these backdoors allow UNC2970 operators to maintain persistence and exfiltrate data or perform further malicious activities. The group has been observed using compromised third-party sites, like WordPress platforms, to host their command-and-control (C2) infrastructure. Additionally, UNC2970 employs BYOVD (Bring Your Own Vulnerable Driver) techniques to exploit vulnerabilities in system drivers for persistence and lateral movement within networks. This approach helps the group evade detection by security tools that may not monitor driver-related activities closely. Recent reports indicate a shift in UNC2970's targeting strategy, particularly focusing on security researchers and organizations with robust endpoint detection and response (EDR) capabilities. This suggests an ongoing effort to disrupt critical sectors and gain access to sensitive information or intelligence.

Key Capabilities

  • Spear-phishing campaigns using job recruitment themes
  • Deployment ofPLANKWALKbackdoor and other malware families
  • Compromise of third-party WordPress sites for C2 infrastructure
  • Use of BYOVD techniques for driver exploitation
  • Enhanced capabilities to evade EDR tools

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Lateral Movement
Exfiltration/Collection

ATT&CK Techniques

T1059.003
T1041
T1566.001
T1206

Software / Tooling

PLANKWALKbackdoor
Other Malware Families
Compromised WordPress Sites
BYOVD Tools

Campaigns & Victims

UNC2970 has demonstrated a shift in targeting, with increased focus on individuals within cybersecurity firms and research organizations. This suggests an operational strategy to disrupt or gather intelligence from those who protect critical systems. The group's ability to evolve, particularly in evading EDR tools, highlights its growing sophistication as a threat actor. Notable past operations include campaigns that have compromised high-value targets across industries and geographies with significant defense and technology footprints.

IOC Patterns

  • Spear-phishing emails themed around job offers or recruitment
  • Distribution of malicious links via fake LinkedIn profiles
  • Use of PLANKWALK backdoor for persistence
  • Network traffic originating from compromised WordPress sites

Recommended Actions

  • Implement rigorous phishing training programs for employees and third parties
  • Enhance email filtering to detect malicious attachments and suspicious domains
  • Monitor for unusual activity in system drivers and implement driver exploitation detection mechanisms
  • Establish strong EDR capabilities to detect and respond to UNC2970's evolving tactics

Suggested Tags

State-sponsored
Cyber espionage
APT group
Spear_phishing
Malware campaigns

Confidence Assessment

High confidence in UNC2970's North Korean origin, based on available intelligence and the nature of its operations. While specifics about their exact goals remain uncertain, the group's operational Tactics, Techniques, and Procedures (TTPs) are well-documented, allowing for detailed analysis and recommendations to mitigate their activities.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 6 Filename 12 URL 1 MD5 Hash 1

References

  1. cloud.google.com — Cited by web research for: Temp.Hermit
  2. attack.mitre.org — Cited by web research for: Sandworm Team
  3. cloud.google.com — Cited by web research for: BURNBOOK
  4. attack.mitre.org — Cited by web research for: services
  5. www.microsoft.com — Cited by web research for: Microsoft Defender XDR
  6. apt.etda.or.th — Cited by web research for: WannaCry

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Phishing
Backdoor / C2
State-sponsored
Cyber espionage
APT group
Spear_phishing
Malware campaigns

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.