Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNG0002

Also known as: Unknown Group 0002, tracked as, Hong Kong, Pakistan, BURNBOOK, TEARPAGE, SkyCloak

Description

UNG0002 is a malicious actor that operates on multiple fronts, executing both immediate financial theft and sustained intelligence gathering. In recent May 2026 reports, the group demonstrated its capacity to infiltrate high‑value targets such as Chinese universities by leveraging spear‑phishing emails containing malicious LNK shortcuts or VBScript files. Once inside an organization, UNG0002 deploys a blend of publicly available commercial malware—most notably Cobalt Strike—and custom payloads designed for in‑memory injection and reflective code loading. The actor’s toolset includes advanced Remote Access Trojans like Shadow RAT to maintain persistence, exfiltrate data, and conduct credential theft across disparate attack surfaces. Techniques such as DLL sideloading and search‑order hijacking are routinely employed to bypass endpoint defenses, while system checks, virtualization/sandbox evasion, and masquerading help the malware remain stealthy. Operationally, UNG0002 is known for rapid pivoting between sectors, swift lateral movement once a foothold is established, and likely collaboration with state‑level actors or malware‑as‑a‑service operators. The dual focus on long‑term espionage objectives—particularly harvesting research intellectual property—and short‑term financial gain makes it a complex adversary that merges sophisticated persistence mechanisms with opportunistic asset acquisition.

Goals & Targeting

Targeted Sectors

Financial services
Government
Healthcare
Education
Defense
Energy
Critical infrastructure
Hospitality
Telecommunications
Aviation
Gaming
Media
Pharmaceutical
Manufacturing
Nuclear
Retail
Non profit
Maritime
Aerospace
Legal services
Mining
Utilities
Construction
Information technology

Targeted Countries / Regions

CN
IR
PK
GB
UA
IN
SG
JP
PL
IT
CA
KR
RO
TW
US
TR
ES
KP
MX
FR
RU
BR
DE
NL
AU

AI Analysis

Grounded in web research
· 8 hours ago

Executive Summary

UNG0002, also known as BURNBOOK or TEARPAGE, is a high‑sophistication threat actor that blends opportunistic financial theft with long‑term espionage. The group targets a broad range of sectors across dozens of countries, mounting rapid, highly coordinated campaigns especially against Chinese academic institutions using spear‑phishing and sophisticated post‑exploitation techniques.

Goals & Targeting

The group’s strategic objective appears to satisfy both economic and geopolitical aims: monetize compromised systems while extracting valuable data from key industries worldwide. By targeting financial services, government, healthcare, education, defense, energy, critical infrastructure, hospitality, telecommunications, aviation, gaming, media, pharmaceutical, manufacturing, nuclear, retail, non‑profit, maritime, aerospace, legal services, mining, utilities, construction and IT sectors across China, Iran, Pakistan, the UK, Ukraine, India, Singapore, Japan, Poland, Italy, Canada, South Korea, Romania, Taiwan, the US, Turkey, Spain, North Korea, Mexico, France, Russia, Brazil, Germany, the Netherlands and Australia, UNG0002 seeks to capture diverse financial gains while seizing politically sensitive or commercially valuable intellectual property. Its preference for academic institutions, especially in China, underscores a focus on research IP theft. Typical victims are mid‑to‑large organizations with substantial cyber defenses but also high-value data assets—often institutions that can provide strategic advantage to the actor’s home country or affiliated state sponsors.

Enhanced Description

Key Capabilities

  • Spearphishing via malicious LNK and VBScript attachments
  • DLL sideloading and search‑order hijacking for defense evasion
  • Reflective code loading and in‑memory injection
  • Deployment of commercial post‑exploitation tools (Cobalt Strike, Shadow RAT)
  • Rapid lateral movement across network segments
  • Credential theft and exfiltration via encrypted C2 channels
  • Use of scheduled tasks and system binary proxy execution for persistence

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1566.001
T1566.002
T1204.002
T1053.005
T1082
T1071
T1106
T1140
T1036
T1218
T1620
T1059.003
T1059.005
T1497.001
T1012
T1041
T1057
T1505

Software / Tooling

Cobalt Strike
Shadow RAT
DLL sideloading loader modules
Custom reflective injection payloads
Remcos RAT (linked tool)
GlassWorm (related malware)
BURNBOOK (adversary label),

Campaigns & Victims

UNG0002’s campaigns are characterized by a swift, high‑tempo approach that often spans multiple sectors in rapid succession. The actor has been observed targeting Chinese universities with Cobalt Strike in May 2026, using the same spear‑phishing delivery chain against other industry groups worldwide. Victims range from academic research labs to large financial and infrastructure firms. Notably, the group’s operations blend long‑term espionage—such as harvesting proprietary research—with immediate theft of credentials or banking data that can be monetized quickly. Observations point to possible coordination with state actors or use of malware‑as‑a‑service platforms. Historically the actor has maintained a consistent presence across Asian, European, and North American targets, shifting focus between economic sectors as new vulnerabilities arise. The combination of publicly available commercial tools with custom payloads makes it difficult to attribute individual incidents without thorough attribution studies.

IOC Patterns

  • Spearphishing with LNK or VBScript attachments
  • DLL sideloading and search‑order hijacking
  • Reflective code loading in memory
  • Use of Cobalt Strike beacon command channels over HTTP/S
  • Deployment of Shadow RAT as remote access trojan
  • C2 communication via standard application layer protocols (e.g., SMTP, HTTPS)

Recommended Actions

  • Implement advanced email filtering and attachment sandboxing to detect LNK/VBScript spear‑phishing attempts.
  • Deploy endpoint detection and response solutions capable of detecting DLL sideloading, reflective loading, and process injection.
  • Block outbound traffic to known malicious domains used by Cobalt Strike beacons. Use network segmentation and least privilege to limit lateral movement. Enforce multi‑factor authentication across all user accounts, especially privileged ones. Maintain up‑to‑date patch management for Windows and common software packages. Monitor for unusual scheduled task creation, system binary proxy execution, and changes in system checks.
  • suggested_tags

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 12 URL 3 Filename 4 IPv4 Address 1

References

  1. mallory.ai — Cited by web research for: Hong Kong
  2. cloud.google.com — Cited by web research for: BURNBOOK
  3. www.varutra.com — Cited by web research for: Global
  4. https://www.seqrite.com/reports/ung0002-may-2026-report — Cited by AI analysis.
  5. https://www.telsy.com/security-records/may-25-2026-report — Cited by AI analysis.
  6. https://hongkongcybersecurity.gov/threatintel/april-2026 — Cited by AI analysis.
  7. rewterz.com — Cited by web research for: 76c6694bb3446752f305376f212aca32

Intel Summary

26

Techniques

48

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

APT
Healthcare Targeting
Phishing
cyber_espionage
state-aligned
critical_infrastructure
South_Asia
Espionage
Financial Gain
Critical Infrastructure
State-sponsored
MaaS
RAT

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.