Also known as: manufacturing, YoroTrooper, SturgeonPhisher, Silent Lynx, tracked as, Sodinokibi, TA428, known, APT28, Pawn Storm, Fancy Bear, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, the custom Voldemort ba, Store.vbs, TA415, Sednit, UNC2596, Scattered Spider, ScrambleCross
UNK_FistBump operates with an economic incentive while maintaining a broad geographic focus that spans Taiwan, mainland China, the United States, Russia, Canada, Brazil, Australia, and several Asian economies. The group’s campaigns use tailored spear‑phishing emails that embed malicious compressed archives or web shells, exploiting recent path‑traversal vulnerabilities in WinRAR (CVE‑2025‑8088/6218) to achieve initial access without requiring user interaction beyond opening an attachment. Once inside, they deploy a modular arsenal of backdoors: Cobalt Strike beacons for pivoting, the custom Voldemort RAT for data gathering, and Mythic‑structured agents (Poseidon, RustyClaw, SnipBot) written in Go that provide lateral movement via DLL hijacking, PowerShell scripting, and kernel‑mode hooking. The actor also exploits legacy Cisco IOS Smart Install (CVE‑2018‑0171) and firmware implants such as SYNful Knock to maintain long‑term persistence. To hide activity, UNK_FistBump makes extensive use of alternate data streams in ZIP files, DLLPath manipulation to inject code into Windows Defender, and digitally signed binaries with SSL.com certificates. Credential theft is achieved through MiniBrowse stealer modules targeting Chrome/Edge credentials. Exfiltration paths commonly involve encrypted RAR archives routed to attacker-controlled domains. The group’s operational tempo has shown a shift from pure initial access exploitation toward more sophisticated social‑engineering, including fake ChatGPT client downloads and trojanized Rufus installers, enabling broader reach across manufacturing supply chains, financial services, and critical infrastructure. Their campaigns remain opportunistic, targeting high‑value corporate entities that provide insider or process knowledge in the semiconductor value chain.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNK_FistBump, a China‑aligned actor with a strong financial focus, has been conducting spear‑phishing campaigns against semiconductor and adjacent sectors across Asia, the Americas, and Europe since early 2025. The group leverages zero‑day archive exploits—winrar CVE‑2025‑8088 and CVE‑2025‑6218—to drop diversified backdoors such as Cobalt Strike, Voldemort, Mythic, and a custom "UpCrypter" RAT bundle while also exploiting legacy Cisco firmware for persistence. Their tactics blend phishing, privilege escalation, and sophisticated post‑exploitation capabilities designed to exfiltrate data from manufacturing, finance, defense, and logistics targets.
Goals & Targeting
UNK_FistBump seeks to monetize its capabilities by infiltrating organizations whose intellectual property and operational data can be leveraged for economic gain, primarily within the semiconductor sector but also extending to finance, defense, logistics, and healthcare. The actor’s geography of interest suggests a focus on entities with geopolitical significance, especially those linked to Taiwan and mainland China. By acquiring credentials through phishing and exploiting software vulnerabilities, the group enables long‑term presence for data exfiltration, lateral movement through network segments, and potential sabotage or intelligence gathering if aligned with state objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The actor’s campaigns display a mix of opportunistic phishing and technical exploitation, with early focus on WinRAR CVE‑2025 exploits to insert backdoors silently. Recent operations illustrate an evolving threat model that also includes social engineering through fake ChatGPT clients and trojanized installers, expanding their reach beyond purely software vulnerabilities. Victim profiles are diverse but skew toward high‑value industrial supply chain partners in the semiconductor and financial sectors; the group appears capable of sustained presence via firmware implants, enabling repeated data exfiltration cycles. Operational tempo is moderate, deploying new payload variants every few weeks, often reusing modules like Mythic or PlugX under different names to evade detection.
IOC Patterns
Recommended Actions
Suggested Tags
No campaigns linked yet.
No observed data linked yet.
10
Techniques
56
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics