Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNK_SparkyCarp

Also known as: UNK_FistBump, UNK_DropPitch, tracked as, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, manufacturing, the custom Voldemort ba, Store.vbs, TA415, UNC2596, Scattered Spider, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, ScrambleCross, BERSERK BEAR, ALLANITE, CASTLE, DYMALLOY, TG-4192, Group 24, Havex, Koala Team, IRON LIBERTY, G0035, ATK6, ITG15, BROMINE, Blue Kraken, Ghost Blizzard, Palmetto Fusion, Allanite, IMPERIAL KITTEN, Yellow Liderc, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM

Description

Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor industry. This included a China-aligned threat actor tracked as UNK_FistBump targeting semiconductor design, manufacturing, and supply chain organizations in employment-themed phishing campaigns resulting in the delivery of Cobalt Strike or the custom Voldemort backdoor. Additionally, Proofpoint observed another China-aligned threat actor tracked as UNK_DropPitch targeting individuals in multiple major investment firms who specialize in investment analysis specifically within the Taiwanese semiconductor industry. This UNK_DropPitch targeting is exemplary of intelligence collection priorities spanning less obvious areas of the semiconductor ecosystem beyond just design and manufacturing entities. Finally, we also observed an actor tracked as UNK_SparkyCarp conducting credential phishing activity against a Taiwanese semiconductor company using a custom Adversary in the Middle (AiTM) phishing kit.

Goals & Targeting

Targeted Sectors

Financial services
Government
Manufacturing
Telecommunications
Defense
Education
Media
Transportation
Healthcare
Aerospace
Retail
Critical infrastructure
Aviation
Energy
Oil gas
Food agriculture
Construction
Mining
Entertainment
Think tank
Nuclear
Legal services
Utilities
Hospitality
Information technology
Pharmaceutical
Non profit

Targeted Countries / Regions

TW
CN
US
RU
IR
BY
SG
KZ
BR
CA
VN
TR
IL
JP
GB
AU
EG

AI Analysis

· 1 week ago

Executive Summary

The threat actor UNK_SparkyCarp has been observed conducting credential phishing campaigns against Taiwanese semiconductor organizations using a custom Adversary in the Middle (AiTM) phishing kit. This actor is part of a broader pattern of China-aligned threats targeting the semiconductor industry, with specific focus on intelligence collection and potential economic espionage.

Goals & Targeting

The strategic objectives of these actors appear to focus on collecting sensitive technical, business, and operational intelligence from the semiconductor industry. Their focus on Taiwanese organizations likely stems from Taiwan's prominence in semiconductor manufacturing and its geopolitical significance. The targeting of specific sectors suggests a long-term goal of economic or technological advantage for China.

Enhanced Description

Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor industry. These included UNK_FistBump and UNK_DropPitch, which utilized employment-themed phishing campaigns and custom tools like Cobalt Strike or Voldemort backdoor to compromise targets. UNK_SparkyCarp stands out as another actor in this cluster, employing credential phishing against individuals within Taiwanese semiconductor companies through acustom AiTM phishing kit. This activity aligns with broader Chinese-state aligned efforts to gather sensitive information from the global semiconductor supply chain, particularly targeting less obvious areas beyond traditional manufacturing and design entities.

Key Capabilities

  • Credential phishing attacks
  • Custom Adversary-in-the-Middle (AiTM) kits
  • Employment-themed social engineering
  • Use of Cobalt Strike and custom backdoors like Voldemort

MITRE ATT&CK Tactics

Espionage/Malevolent spying
Credential access

ATT&CK Techniques

T1059.003
T1027
T1070
T1685
T1566

Software / Tooling

Cobalt Strike
Voldemort backdoor
AiTM phishing kit

Campaigns & Victims

UNK_SparkyCarp's campaigns exhibit a high degree of operational sophistication, with tailored phishing attempts and use of custom tools. The actor has demonstrated persistence in targeting the semiconductor sector, suggesting long-term goals. Past operations include credential harvesting to enable further access to sensitive networks and information.

IOC Patterns

  • Custom AiTM phishing kits
  • Credential phishing emails impersonating trusted entities
  • Use of Cobalt Strike and Voldemort backdoors for post-exploitation

Recommended Actions

  • Implement robust email security measures, including SPF/DKIM/DMARC records.
  • Monitor network traffic for known TTPs associated with Chinese-state aligned actors.
  • Educate employees on advanced phishing techniques and social engineering tactics.
  • Conduct regular audits of supply chain partners and implement zero-trust principles.

Suggested Tags

China-aligned
Cyber espionage
Semiconductor sector
Credential theft

Confidence Assessment

High confidence in the actor's targeting patterns and TTPs, based on consistent observational data from Proofpoint. However, specific details about the actor's full capabilities and long-term objectives remain speculative.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 8 Email Address 3 SHA-256 Hash 2 IPv4 Address 5 URL 1 Filename 1

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. attack.mitre.org — Cited by web research for: services
  3. www.proofpoint.com — Cited by web research for: manufacturing
  4. www.proofpoint.com — Cited by web research for: Nuclear

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Supply Chain Attack
Phishing
Backdoor / C2
China-aligned
Cyber espionage
Semiconductor sector
Credential theft

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Taiwan (TW)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.