Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6032

Also known as: tracked as, UNC6032 by Mandiant, STARKVEIL

Description

UNC6032’s approach relies on striking fear in users with the promise of free AI video generation tools while delivering malicious code. Victims are redirected from carefully crafted ads to counterfeit web pages hosting a Rust‑written STARKVEIL dropper, which immediately deploys a Python loader that fetches additional modules. The primary payloads include XWORM (a modular .NET backdoor), FROSTRIFT (Tor‑based command and control) and GRIMPULL (downloader). They use DLL side‑loading and process injection for persistence, writing an AutoRun registry key under HKCU\Software\<victim_id> and embedding loader bytes in HKCU\Software\<victim_id>\registry_val. Anti‑VM checks, keylogging, screen capture, command execution, and USB plugin management create broad system coverage. Data exfiltration flows through the Telegram API for credentials and payment card details, and via encrypted GZIP/protobuf streams that tunnel to a Tor exit node or an SSH‑style C2 channel. The actor also leverages domain rotation, fast‑registration strategies, and compromised social media accounts to evade detection while scaling attacks. The overall strategy showcases sophisticated social engineering coupled with advanced persistence techniques, reflecting a highly organized threat actor focused on financial gain across multiple sectors.

Goals & Targeting

Targeted Sectors

Defense
Media
Manufacturing
Government
Utilities
Telecommunications
Non profit
Financial services
Healthcare
Information technology
Education
Transportation

Targeted Countries / Regions

VN
US
AU
RU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 19 hours ago

Executive Summary

UNC6032 is a Vietnam‑based threat actor that monetizes by distributing Python‑based infostealers and backdoors through fake AI video generator websites lured via malicious social media advertising on platforms such as Facebook and LinkedIn. The malware pipeline centers around the Rust dropper STARKVEIL, which delivers modular payloads—including XWORM, FROSTRIFT, and GRIMPULL—using DLL side‑loading, process injection, and registry persistence. Exfiltration is carried out primarily through encrypted GZIP‑compressed protobuf traffic over TCP/SSL to a Telegram API or Tor‑based command‑and‑control backdrops.

Goals & Targeting

UNC6032’s strategic objectives are predominantly financially motivated; they aim to harvest credentials, credit card data, and other sensitive information from a wide range of industries—defense, media, manufacturing, government, utilities, telecommunications, non‑profit, finance, healthcare, IT, education, and transportation. By leveraging AI‑generated deception, the actor broadens their reach to lower‑security environments, exploiting social media platforms where users frequently seek AI tools. This targeting approach also reflects an intent to maximize exposure while minimizing discovery by concentrating on user‑involved compromise rather than high‑profile network intrusions.

Enhanced Description

Key Capabilities

  • Deploy malware via fake AI video generator websites
  • Use Python-based infostealers and backdoors
  • Exfiltrate credentials and sensitive data through Telegram API
  • Target victims with malicious social media ads on Facebook and LinkedIn
  • Rotate domains quickly to evade detection
  • Employ attacker‑created or compromised social media accounts for ad distribution
  • DLL side‑loading, in‑memory dropping, process injection, PE hollowing
  • Anticipate anti‑VM checks
  • Keylogging, command execution, screen capture
  • USB drive spreading via plugin management
  • Collect system information, installed applications, crypto wallets
  • Decompress/decrypt payloads using TripleDES ECB, GZIP, MD5‑based key
  • Persist through Windows Registry (HKCU\Software\<victim_id>\registry_val)
  • Remote download/execution from hardcoded URLs
  • Deploy Rust dropper STARKVEIL to deliver GRIMPULL, XWORM, FROSTRIFT
  • Use Python loaders for further payload delivery
  • Tor‑based C2 with backdoor FROSTRIFT

MITRE ATT&CK Tactics

Initial Access
Execution
Exfiltration
Persistence
Defense Evasion
Privilege Escalation
Discovery
Collection
Command and Control

ATT&CK Techniques

T1001
T1055
T1059.006
T1082
T1090.003
T1105
T1119
T1189
T1204
T1363
T1547.001
T1566.001
T1041

Software / Tooling

HAVEX RAT
STARKVEIL dropper
XWORM .NET backdoor
FROSTRIFT .NET backdoor
GRIMPULL downloader
avcodec-61.dll side‑loaded DLL
C:\winsystem\heif\heif.exe launcher
Python loader

Campaigns & Victims

UNC6032 employs a repeatable, high‑volume campaign model that launches thousands of Facebook and LinkedIn ad campaigns each month. The actor leverages rapid domain registration, fast rotating URL patterns, and a modular dropper architecture to scale attacks across global markets—including Vietnam, the United States, Australia, and Russia—while targeting sectors with high monetary value. Victim types range from individual users to enterprise endpoints, exploiting trust in AI services. Past operations have demonstrated a preference for low‑effort social engineering combined with stealthy persistence mechanisms.

IOC Patterns

  • Domain names of fake AI generator sites advertised on social media
  • Rapid domain rotation patterns
  • Registry AutoRun key at %APPDATA%\Launcher\Launcher.exe
  • Mutex aff391c406ebc4c3
  • HKCU\Software\<victim_id>\<plugin_name> registry entries
  • Hardcoded URLs for downloading additional payloads
  • GZIP‑compressed protobuf C2 payloads
  • Base64‑encoded configuration strings
  • TripleDES ECB decryption with MD5 campaign key
  • Tor‑based C2 connections

Recommended Actions

  • Block or blacklist domains used in malicious AI generator ads and fake websites
  • Implement URL filtering to block AI-themed phishing sites and malicious download URLs
  • Enforce least privilege policies to mitigate DLL side‑loading risks
  • Monitor for unusual AutoRun registry entries in %APPDATA% and HKCU\Software paths
  • Detect process injection activities (PE hollowing, DLL side‑loading) via EDR solutions
  • Inspect network traffic for GZIP‑compressed protobufs over TLS directed at unknown hosts
  • Deploy EDR or XDR with visibility into .NET DLL execution and plugin download behaviors
  • Educate users on social engineering ads that masquerade as legitimate AI services
  • Verify legitimacy of AI tool domains before engagement
  • Block outbound traffic to known Tor exit nodes used for command & control
  • Use threat intelligence feeds to stay updated on new domain registrations associated with the campaign

Suggested Tags

VietnamNexus
FakeAIWebsite
SocialMediaAds
TelegramExfiltration
Infostealer
PythonMalware
MalwareDropper
DLLSideLoading
ProcessInjection
AutoRunPersistence
.NETBackdoor
Keylogging
CommandExecution
ScreenCapture
USBSpreading
AntiVM
PluginManagement
NetworkCompressionObfuscation
UNC6032
STARKVEIL
FROSTRIFT
XWORM
GRIMPULL
PythonLoader

Confidence Assessment

The analysis is drawn from multiple public intelligence reports and corroborated IOC signatures that collectively point to a well‑organized, financially driven threat actor originating in Vietnam. Confidence on the core TTPs—using fake AI sites for initial access, STARKVEIL dropper mechanics, and Telegram/Tor exfiltration—is high due to repeated patterns across separate sources. Knowledge gaps remain regarding exact attribution methods, full scope of target sectors, precise timelines, and whether other undisclosed payload families are in use.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 6 URL 4 Domain 4 SHA-256 Hash 6

References

  1. cyberpress.org — Cited by web research for: STARKVEIL
  2. cloud.google.com — Cited by web research for: Telegram
  3. www.tanium.com — Cited by web research for: TOUGHPROGRESS
  4. www.show.it — Cited by web research for: BANSHEE
  5. https://www.cyware.com/resources/threat-briefings/monthly-threat-intelligence-may-2025 — Cited by AI analysis.
  6. https://cyberint.com/news-feed/ — Cited by AI analysis.
  7. https://securityweek.com/vietnamese-hackers-distribute-m — Cited by AI analysis.
  8. https://cyberscoop.com/ai-video-generator-malware- — Cited by AI analysis.
  9. https://www.infosecurity-magazine.com/news/vietnam-hackers-malware-fake-ai/ — Cited by AI analysis.
  10. https://malpedia.caad.fkie.fraunhofer.de/details/win.conti — Cited by AI analysis.
  11. https://mallory.ai/malware/019abc51-3daf-7fd8-af91-cb39c5c1c99b — Cited by AI analysis.
  12. https://www.mishcon.com/news/fake-ai-tools-used-to-spread-information-stealing-malware — Cited by AI analysis.

Intel Summary

13

Techniques

50

Tools

0

Campaigns

39

IOCs

0

Observed Data

9

Tactics

Tags

Backdoor / C2
Data Exfiltration
VietnamNexus
FakeAIWebsite
SocialMediaAds
TelegramExfiltration
Infostealer
PythonMalware
MalwareDropper
DLLSideLoading
ProcessInjection
AutoRunPersistence
.NETBackdoor
Keylogging
CommandExecution
ScreenCapture
USBSpreading
AntiVM
PluginManagement
NetworkCompressionObfuscation
UNC6032
STARKVEIL
FROSTRIFT
XWORM
GRIMPULL
PythonLoader

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
V
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.