Also known as: Unknown Group 0002, tracked as, Hong Kong, Pakistan, BURNBOOK, TEARPAGE, SkyCloak
UNG0002 is a malicious actor that operates on multiple fronts, executing both immediate financial theft and sustained intelligence gathering. In recent May 2026 reports, the group demonstrated its capacity to infiltrate high‑value targets such as Chinese universities by leveraging spear‑phishing emails containing malicious LNK shortcuts or VBScript files. Once inside an organization, UNG0002 deploys a blend of publicly available commercial malware—most notably Cobalt Strike—and custom payloads designed for in‑memory injection and reflective code loading. The actor’s toolset includes advanced Remote Access Trojans like Shadow RAT to maintain persistence, exfiltrate data, and conduct credential theft across disparate attack surfaces. Techniques such as DLL sideloading and search‑order hijacking are routinely employed to bypass endpoint defenses, while system checks, virtualization/sandbox evasion, and masquerading help the malware remain stealthy. Operationally, UNG0002 is known for rapid pivoting between sectors, swift lateral movement once a foothold is established, and likely collaboration with state‑level actors or malware‑as‑a‑service operators. The dual focus on long‑term espionage objectives—particularly harvesting research intellectual property—and short‑term financial gain makes it a complex adversary that merges sophisticated persistence mechanisms with opportunistic asset acquisition.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNG0002, also known as BURNBOOK or TEARPAGE, is a high‑sophistication threat actor that blends opportunistic financial theft with long‑term espionage. The group targets a broad range of sectors across dozens of countries, mounting rapid, highly coordinated campaigns especially against Chinese academic institutions using spear‑phishing and sophisticated post‑exploitation techniques.
Goals & Targeting
The group’s strategic objective appears to satisfy both economic and geopolitical aims: monetize compromised systems while extracting valuable data from key industries worldwide. By targeting financial services, government, healthcare, education, defense, energy, critical infrastructure, hospitality, telecommunications, aviation, gaming, media, pharmaceutical, manufacturing, nuclear, retail, non‑profit, maritime, aerospace, legal services, mining, utilities, construction and IT sectors across China, Iran, Pakistan, the UK, Ukraine, India, Singapore, Japan, Poland, Italy, Canada, South Korea, Romania, Taiwan, the US, Turkey, Spain, North Korea, Mexico, France, Russia, Brazil, Germany, the Netherlands and Australia, UNG0002 seeks to capture diverse financial gains while seizing politically sensitive or commercially valuable intellectual property. Its preference for academic institutions, especially in China, underscores a focus on research IP theft. Typical victims are mid‑to‑large organizations with substantial cyber defenses but also high-value data assets—often institutions that can provide strategic advantage to the actor’s home country or affiliated state sponsors.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNG0002’s campaigns are characterized by a swift, high‑tempo approach that often spans multiple sectors in rapid succession. The actor has been observed targeting Chinese universities with Cobalt Strike in May 2026, using the same spear‑phishing delivery chain against other industry groups worldwide. Victims range from academic research labs to large financial and infrastructure firms. Notably, the group’s operations blend long‑term espionage—such as harvesting proprietary research—with immediate theft of credentials or banking data that can be monetized quickly. Observations point to possible coordination with state actors or use of malware‑as‑a‑service platforms. Historically the actor has maintained a consistent presence across Asian, European, and North American targets, shifting focus between economic sectors as new vulnerabilities arise. The combination of publicly available commercial tools with custom payloads makes it difficult to attribute individual incidents without thorough attribution studies.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
26
Techniques
48
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics