Also known as: tracked as, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, manufacturing, the custom Voldemort ba, Store.vbs, TA415, UNC2596, Scattered Spider, ScrambleCross, HealthKick
UNK_DropPitch emerged in early 2025 from the Proofpoint threat landscape as an actor focused on infiltrating the semiconductor value chain in Taiwan. The adversary delivers malicious payloads through spear‑phishing emails that embed WinRAR archives containing hidden files accessed via Windows Alternate Data Streams (ADS). When the victim extracts the archive, PowerShell scripts or rundll32.exe execute embedded .lnk or .desktop shortcuts to drop lightweight backdoors such as MiniJunk and MiniBrowse on Windows and Linux hosts. Additionally, UNK_DropPitch extends its foothold by exploiting a public‑facing firmware vulnerability in Cisco IOS Smart Install (CVE-2018‑0171). This flaw allows the attacker to install a low‑profile implant that survives reboots and provides persistent access while stealing configuration data. The group’s toolkit includes multiple backdoors—SnipBot, RustyClaw, Mythic agent, EAGLET, Poseidon—as well as remote access tools like PureHVNC, DCRat, and Babylon RAT. Execution tactics are supported by PowerShell scripting, rundll32.exe invocation, DLL injection/hijacking (e.g., the Windows Defender executable), and manipulation of DllPath via NT API calls. Persistent footholds are achieved through scheduled tasks or cron jobs, SNMP‑based utilities, and the exploitation of CVE-2025-29824 in PipeMagic modules. The adversary often signs malware with legitimate SSL.com certificates to evade detection. Phishing emails also mimic HR recruiters or career portals, targeting sensitive positions within investment analysis teams of semiconductor firms, which facilitates credential theft from Chrome and Edge browsers and grants additional lateral movement capabilities.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNK_DropPitch, a China‑aligned threat actor, conducts sophisticated spear‑phishing campaigns against Taiwanese semiconductor and investment analysis firms, leveraging newly discovered WinRAR zero‑day vulnerabilities to deliver backdoors such as MiniJunk and Poseidon. The group also exploits older Cisco Smart Install flaws for initial access and persistence, while deploying a varied toolkit of custom malware and well‑known RATs across finance, manufacturing and defense sectors worldwide.
Goals & Targeting
The primary objective of UNK_DropPitch is financial gain through targeted data exfiltration and ransomware‑style threats against high‑value assets in the semiconductor ecosystem. By harvesting investment analysis data, the actor enhances its competitive intelligence and may sell or leverage insights for market manipulation. The targeting profile spans a broad spectrum of industries, including finance, manufacturing, defense, telecommunications, and aviation, with a geographic focus on China, Taiwan, US, UK, Canada, and several Middle East and South Asian countries.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNK_DropPitch operates with a high operational tempo, frequently deploying new spear‑phishing campaigns that target both corporate and investment analysis entities within the semiconductor value chain. The actor blends early exploitation of zero‑day vulnerabilities with well‑known delivery vectors to maintain resilience against defensive measures. Victim types range from Fortune‑500 corporate IT teams to smaller research organizations. Similar tactics have been observed in related campaigns such as Nimbus Manticore, which used HR recruiter impersonation to drop MiniJunk on the UK and Canadian market, underscoring a common operational framework that emphasizes credential theft and low‑profile persistence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provide a reasonably clear picture of UNK_DropPitch’s tactics, tools, and targeted sectors with moderate confidence. The evidence largely comes from threat intelligence feeds (Proofpoint) and secondary analyses (Tom's Hardware), which confirm the use of specific zero‑days and backdoors but lack detailed internal attribution or definitive dates for first/last activity. Gaps remain regarding the actor’s long‑term strategic goals beyond financial gain, the full geographical reach outside the listed countries, and whether there is a distinct campaign hierarchy linked to larger geopolitical objectives.
No campaigns linked yet.
No observed data linked yet.
5
Techniques
50
Tools
0
Campaigns
40
IOCs
0
Observed Data
4
Tactics