Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNK_DropPitch

Also known as: tracked as, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, manufacturing, the custom Voldemort ba, Store.vbs, TA415, UNC2596, Scattered Spider, ScrambleCross, HealthKick

Description

UNK_DropPitch emerged in early 2025 from the Proofpoint threat landscape as an actor focused on infiltrating the semiconductor value chain in Taiwan. The adversary delivers malicious payloads through spear‑phishing emails that embed WinRAR archives containing hidden files accessed via Windows Alternate Data Streams (ADS). When the victim extracts the archive, PowerShell scripts or rundll32.exe execute embedded .lnk or .desktop shortcuts to drop lightweight backdoors such as MiniJunk and MiniBrowse on Windows and Linux hosts. Additionally, UNK_DropPitch extends its foothold by exploiting a public‑facing firmware vulnerability in Cisco IOS Smart Install (CVE-2018‑0171). This flaw allows the attacker to install a low‑profile implant that survives reboots and provides persistent access while stealing configuration data. The group’s toolkit includes multiple backdoors—SnipBot, RustyClaw, Mythic agent, EAGLET, Poseidon—as well as remote access tools like PureHVNC, DCRat, and Babylon RAT. Execution tactics are supported by PowerShell scripting, rundll32.exe invocation, DLL injection/hijacking (e.g., the Windows Defender executable), and manipulation of DllPath via NT API calls. Persistent footholds are achieved through scheduled tasks or cron jobs, SNMP‑based utilities, and the exploitation of CVE-2025-29824 in PipeMagic modules. The adversary often signs malware with legitimate SSL.com certificates to evade detection. Phishing emails also mimic HR recruiters or career portals, targeting sensitive positions within investment analysis teams of semiconductor firms, which facilitates credential theft from Chrome and Edge browsers and grants additional lateral movement capabilities.

Goals & Targeting

Targeted Sectors

Financial services
Manufacturing
Telecommunications
Defense
Government
Education
Transportation
Healthcare
Aerospace
Retail
Critical infrastructure
Aviation
Energy
Food agriculture
Construction
Oil gas
Media
Mining
Entertainment
Think tank
Nuclear
Legal services
Utilities
Hospitality

Targeted Countries / Regions

CN
TW
US
RU
IR
BY
SG
KZ
BR
CA
VN
TR
IL
JP
GB
AU
EG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 6 hours ago

Executive Summary

UNK_DropPitch, a China‑aligned threat actor, conducts sophisticated spear‑phishing campaigns against Taiwanese semiconductor and investment analysis firms, leveraging newly discovered WinRAR zero‑day vulnerabilities to deliver backdoors such as MiniJunk and Poseidon. The group also exploits older Cisco Smart Install flaws for initial access and persistence, while deploying a varied toolkit of custom malware and well‑known RATs across finance, manufacturing and defense sectors worldwide.

Goals & Targeting

The primary objective of UNK_DropPitch is financial gain through targeted data exfiltration and ransomware‑style threats against high‑value assets in the semiconductor ecosystem. By harvesting investment analysis data, the actor enhances its competitive intelligence and may sell or leverage insights for market manipulation. The targeting profile spans a broad spectrum of industries, including finance, manufacturing, defense, telecommunications, and aviation, with a geographic focus on China, Taiwan, US, UK, Canada, and several Middle East and South Asian countries.

Enhanced Description

Key Capabilities

  • Spear‑phishing emails with malicious attachments (.zip, .lnk)
  • Exploitation of WinRAR zero‑day vulnerabilities (CVE-2025-8088 & CVE-2025-6218) using ADS
  • Use of Cisco Smart Install vulnerability (CVE-2018-0171) for firmware implants
  • Deployment of backdoors: SnipBot, RustyClaw, Mythic agent, EAGLET, Poseidon, MiniJunk, MiniBrowse, UpCrypter, PureHVNC, DCRat, Babylon RAT
  • Execution via PowerShell scripts and rundll32.exe
  • Disguised .desktop files masquerading as PDFs on Linux for code execution
  • Scheduled task or cron job creation and modification
  • SNMP‑based tooling for lateral movement
  • DLL injection/hijacking to load malicious DLLs into Windows Defender and other binaries
  • Credential theft from Chrome and Edge browsers
  • Digital signing of malware with legitimate SSL.com certificates
  • Exploitation of CVE-2025-29824 via PipeMagic modules

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Defense Evasion

ATT&CK Techniques

T1566.001
T1086
T1053.004
T1055
T1531

Software / Tooling

SnipBot
RustyClaw
Mythic agent
EAGLET backdoor
Poseidon backdoor
MiniJunk
MiniBrowse
UpCrypter
PureHVNC
DCRat
Babylon RAT
PipeMagic

Campaigns & Victims

UNK_DropPitch operates with a high operational tempo, frequently deploying new spear‑phishing campaigns that target both corporate and investment analysis entities within the semiconductor value chain. The actor blends early exploitation of zero‑day vulnerabilities with well‑known delivery vectors to maintain resilience against defensive measures. Victim types range from Fortune‑500 corporate IT teams to smaller research organizations. Similar tactics have been observed in related campaigns such as Nimbus Manticore, which used HR recruiter impersonation to drop MiniJunk on the UK and Canadian market, underscoring a common operational framework that emphasizes credential theft and low‑profile persistence.

IOC Patterns

  • CVE-2025-8088
  • CVE-2025-6218
  • CVE-2018-0171
  • WinRAR archive with hidden ADS files
  • .zip attachment containing .lnk that launches PowerShell or rundll32.exe
  • Linux .desktop file disguised as a PDF for execution
  • Malware signed with SSL.com certificates
  • DLL hijacking of local binaries such as the Chrome update executable
  • Exploitation of CVE-2025-29824 in PipeMagic modules
  • Spearphishing hyperlinks pointing to fake career portal URLs

Recommended Actions

  • Apply the latest WinRAR patches to close CVE-2025-8088 and CVE-2025-6218.
  • Disable or patch Cisco IOS Smart Install (CVE-2018-0171) on all network devices.
  • Block inbound traffic related to PowerShell scripts and rundll32.exe usage where unnecessary.
  • Configure EDR solutions to detect execution of hidden files, ADS exploitation, and DLL hijacking patterns.
  • Monitor for the creation or modification of scheduled tasks and cron jobs that appear suspicious.
  • Segment network segments containing Cisco devices and restrict SNMP traffic to authorized management systems.
  • Validate TLS certificate chains to detect malicious use of legitimate SSL.com signatures.
  • Educate users on recognizing HR‑imitation spearphishing emails and vetting career portal links.
  • Deploy threat-detection controls geared toward MiniJunk, UpCrypter, PureHVNC, DCRat, Babylon RAT, and related backdoors.

Suggested Tags

APT-COM
WinRAR zero‑day
Cisco Smart Install CVE
Spearphishing Attachment
Backdoor
Mythic
SnipBot
RustyClaw
EAGLET
Poseidon
Nimbus Manticore
UNC1549
Smoke Sandstorm
Iranian Dream Job
MiniJunk
Minibike
MiniBrowse
UpCrypter
PureHVNC
DCRat
Babylon RAT
PipeMagic
CVE-2025-29824
Spearphishing
Credential Theft
DLL Hijacking

Confidence Assessment

The available data provide a reasonably clear picture of UNK_DropPitch’s tactics, tools, and targeted sectors with moderate confidence. The evidence largely comes from threat intelligence feeds (Proofpoint) and secondary analyses (Tom's Hardware), which confirm the use of specific zero‑days and backdoors but lack detailed internal attribution or definitive dates for first/last activity. Gaps remain regarding the actor’s long‑term strategic goals beyond financial gain, the full geographical reach outside the listed countries, and whether there is a distinct campaign hierarchy linked to larger geopolitical objectives.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 7 Email Address 3 SHA-256 Hash 2 Filename 2 IPv4 Address 5 URL 1

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. www.proofpoint.com — Cited by web research for: manufacturing
  3. www.volexity.com — Cited by web research for: Explorer
  4. www.proofpoint.com — Cited by web research for: Nuclear
  5. https://www.tomshardware.com/tech-industry/cyber-security/c — Cited by AI analysis.

Intel Summary

5

Techniques

50

Tools

0

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

Supply Chain Attack
Phishing
Backdoor / C2
APT
China-aligned
espionage
financial-sector
semiconductor
APT-COM
WinRAR zero‑day
Cisco Smart Install CVE
Spearphishing Attachment
Backdoor
Mythic
SnipBot
RustyClaw
EAGLET
Poseidon
Nimbus Manticore
UNC1549
Smoke Sandstorm
Iranian Dream Job
MiniJunk
Minibike
MiniBrowse
UpCrypter
PureHVNC
DCRat
Babylon RAT
PipeMagic
CVE-2025-29824
Spearphishing
Credential Theft
DLL Hijacking

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.