Also known as: UNK_FistBump, UNK_DropPitch, tracked as, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, manufacturing, the custom Voldemort ba, Store.vbs, TA415, UNC2596, Scattered Spider, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, ScrambleCross, BERSERK BEAR, ALLANITE, CASTLE, DYMALLOY, TG-4192, Group 24, Havex, Koala Team, IRON LIBERTY, G0035, ATK6, ITG15, BROMINE, Blue Kraken, Ghost Blizzard, Palmetto Fusion, Allanite, IMPERIAL KITTEN, Yellow Liderc, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM
Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor industry. This included a China-aligned threat actor tracked as UNK_FistBump targeting semiconductor design, manufacturing, and supply chain organizations in employment-themed phishing campaigns resulting in the delivery of Cobalt Strike or the custom Voldemort backdoor. Additionally, Proofpoint observed another China-aligned threat actor tracked as UNK_DropPitch targeting individuals in multiple major investment firms who specialize in investment analysis specifically within the Taiwanese semiconductor industry. This UNK_DropPitch targeting is exemplary of intelligence collection priorities spanning less obvious areas of the semiconductor ecosystem beyond just design and manufacturing entities. Finally, we also observed an actor tracked as UNK_SparkyCarp conducting credential phishing activity against a Taiwanese semiconductor company using a custom Adversary in the Middle (AiTM) phishing kit.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The threat actor UNK_SparkyCarp has been observed conducting credential phishing campaigns against Taiwanese semiconductor organizations using a custom Adversary in the Middle (AiTM) phishing kit. This actor is part of a broader pattern of China-aligned threats targeting the semiconductor industry, with specific focus on intelligence collection and potential economic espionage.
Goals & Targeting
The strategic objectives of these actors appear to focus on collecting sensitive technical, business, and operational intelligence from the semiconductor industry. Their focus on Taiwanese organizations likely stems from Taiwan's prominence in semiconductor manufacturing and its geopolitical significance. The targeting of specific sectors suggests a long-term goal of economic or technological advantage for China.
Enhanced Description
Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor industry. These included UNK_FistBump and UNK_DropPitch, which utilized employment-themed phishing campaigns and custom tools like Cobalt Strike or Voldemort backdoor to compromise targets. UNK_SparkyCarp stands out as another actor in this cluster, employing credential phishing against individuals within Taiwanese semiconductor companies through acustom AiTM phishing kit. This activity aligns with broader Chinese-state aligned efforts to gather sensitive information from the global semiconductor supply chain, particularly targeting less obvious areas beyond traditional manufacturing and design entities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNK_SparkyCarp's campaigns exhibit a high degree of operational sophistication, with tailored phishing attempts and use of custom tools. The actor has demonstrated persistence in targeting the semiconductor sector, suggesting long-term goals. Past operations include credential harvesting to enable further access to sensitive networks and information.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the actor's targeting patterns and TTPs, based on consistent observational data from Proofpoint. However, specific details about the actor's full capabilities and long-term objectives remain speculative.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics