Also known as: energy industries, Temp.Hermit, TOUCHSHIFT, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, BURNBOOK, TEARPAGE, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code
UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes, often utilizing fake LinkedIn accounts to engage victims. The group employs the PLANKWALK backdoor and other malware families, leveraging compromised WordPress sites for command and control. They have been observed using BYOVD techniques to exploit vulnerable drivers for evading detection. Mandiant has noted a shift in UNC2970's targeting strategy, including a focus on security researchers and advancements in their operational capabilities against EDR tools.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC2970 is a North Korean threat actor known for sophisticated cyber operations, primarily involving spear-phishing campaigns with job recruitment themes. The group leverages fake LinkedIn accounts and malware like PLANKWALK to compromise targets, often using compromised WordPress sites for command and control. Recent activity indicates an increased focus on targeting security researchers and enhanced capabilities against EDR tools.
Goals & Targeting
UNC2970 likely operates under the strategic goals of a North Korean state-sponsored entity, possibly with objectives aimed at espionage, disruption, or financial gain. The group's targeting has evolved to focus on individuals within security firms and research organizations, which could be linked to efforts to compromise cybersecurity defenses or gather intelligence on Western defense mechanisms. Their choice of sectors suggests a desire to target high-value assets with significant intellectual property or sensitive data.
Enhanced Description
UNC2970 operates as a North Korean state-affiliated threat actor group that primarily employs phishing-based attacks to target individuals within organizations. The group is known to utilize fake LinkedIn profiles to reach victims, sending emails that appear to be job offers or related business communications. These emails often contain malicious links or attachments, which, when clicked, deploy payloads such as the PLANKWALK backdoor or other malware families. Once established on a victim's system, these backdoors allow UNC2970 operators to maintain persistence and exfiltrate data or perform further malicious activities. The group has been observed using compromised third-party sites, like WordPress platforms, to host their command-and-control (C2) infrastructure. Additionally, UNC2970 employs BYOVD (Bring Your Own Vulnerable Driver) techniques to exploit vulnerabilities in system drivers for persistence and lateral movement within networks. This approach helps the group evade detection by security tools that may not monitor driver-related activities closely. Recent reports indicate a shift in UNC2970's targeting strategy, particularly focusing on security researchers and organizations with robust endpoint detection and response (EDR) capabilities. This suggests an ongoing effort to disrupt critical sectors and gain access to sensitive information or intelligence.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC2970 has demonstrated a shift in targeting, with increased focus on individuals within cybersecurity firms and research organizations. This suggests an operational strategy to disrupt or gather intelligence from those who protect critical systems. The group's ability to evolve, particularly in evading EDR tools, highlights its growing sophistication as a threat actor. Notable past operations include campaigns that have compromised high-value targets across industries and geographies with significant defense and technology footprints.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in UNC2970's North Korean origin, based on available intelligence and the nature of its operations. While specifics about their exact goals remain uncertain, the group's operational Tactics, Techniques, and Procedures (TTPs) are well-documented, allowing for detailed analysis and recommendations to mitigate their activities.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics