Also known as: tracked as, UNC6032 by Mandiant, STARKVEIL
UNC6032’s approach relies on striking fear in users with the promise of free AI video generation tools while delivering malicious code. Victims are redirected from carefully crafted ads to counterfeit web pages hosting a Rust‑written STARKVEIL dropper, which immediately deploys a Python loader that fetches additional modules. The primary payloads include XWORM (a modular .NET backdoor), FROSTRIFT (Tor‑based command and control) and GRIMPULL (downloader). They use DLL side‑loading and process injection for persistence, writing an AutoRun registry key under HKCU\Software\<victim_id> and embedding loader bytes in HKCU\Software\<victim_id>\registry_val. Anti‑VM checks, keylogging, screen capture, command execution, and USB plugin management create broad system coverage. Data exfiltration flows through the Telegram API for credentials and payment card details, and via encrypted GZIP/protobuf streams that tunnel to a Tor exit node or an SSH‑style C2 channel. The actor also leverages domain rotation, fast‑registration strategies, and compromised social media accounts to evade detection while scaling attacks. The overall strategy showcases sophisticated social engineering coupled with advanced persistence techniques, reflecting a highly organized threat actor focused on financial gain across multiple sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6032 is a Vietnam‑based threat actor that monetizes by distributing Python‑based infostealers and backdoors through fake AI video generator websites lured via malicious social media advertising on platforms such as Facebook and LinkedIn. The malware pipeline centers around the Rust dropper STARKVEIL, which delivers modular payloads—including XWORM, FROSTRIFT, and GRIMPULL—using DLL side‑loading, process injection, and registry persistence. Exfiltration is carried out primarily through encrypted GZIP‑compressed protobuf traffic over TCP/SSL to a Telegram API or Tor‑based command‑and‑control backdrops.
Goals & Targeting
UNC6032’s strategic objectives are predominantly financially motivated; they aim to harvest credentials, credit card data, and other sensitive information from a wide range of industries—defense, media, manufacturing, government, utilities, telecommunications, non‑profit, finance, healthcare, IT, education, and transportation. By leveraging AI‑generated deception, the actor broadens their reach to lower‑security environments, exploiting social media platforms where users frequently seek AI tools. This targeting approach also reflects an intent to maximize exposure while minimizing discovery by concentrating on user‑involved compromise rather than high‑profile network intrusions.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6032 employs a repeatable, high‑volume campaign model that launches thousands of Facebook and LinkedIn ad campaigns each month. The actor leverages rapid domain registration, fast rotating URL patterns, and a modular dropper architecture to scale attacks across global markets—including Vietnam, the United States, Australia, and Russia—while targeting sectors with high monetary value. Victim types range from individual users to enterprise endpoints, exploiting trust in AI services. Past operations have demonstrated a preference for low‑effort social engineering combined with stealthy persistence mechanisms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is drawn from multiple public intelligence reports and corroborated IOC signatures that collectively point to a well‑organized, financially driven threat actor originating in Vietnam. Confidence on the core TTPs—using fake AI sites for initial access, STARKVEIL dropper mechanics, and Telegram/Tor exfiltration—is high due to repeated patterns across separate sources. Knowledge gaps remain regarding exact attribution methods, full scope of target sectors, precise timelines, and whether other undisclosed payload families are in use.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
50
Tools
0
Campaigns
39
IOCs
0
Observed Data
9
Tactics