Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6384

Also known as: Vertigo Panda, Mustang Panda, RedDelta, tracked as, Red Lich, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, PlugX, CANONSTAGER, SOGU.SEC, BRONZE PRESIDENT, Luminous Moth, Earth Preta, Camaro Dragon, Stately Tarurus

Description

UNC6384 (also tracked as Vertigo Panda) is a Chinese-affiliated APT that conducts targeted espionage campaigns primarily against diplomatic entities in Southeast Asia and Europe, specifically Belgium and Hungary. The group exploits the ZDI-CAN-25373 Windows shortcut vulnerability to gain initial code execution via malicious .LNK files, deploying the PlugX RAT through sophisticated delivery mechanisms, including DLL side-loading and adversary-in-the-middle attacks. Their operations involve social engineering tactics, such as spear-phishing emails themed around diplomatic events, to entice victims into executing malicious payloads. UNC6384's use of valid code signing and HTTPS hosting enhances their evasion of detection and increases the likelihood of user interaction.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Healthcare
Education
Manufacturing
Non profit
Critical infrastructure
Energy
Media
Pharmaceutical
Aviation
Hospitality
Aerospace
Think tank
Retail
Information technology
Transportation
Mining
Chemical
Gaming
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

CN
US
RU
VN
IR
PK
TW
AU
JP
IL
UA
IN
GB
SA
AE
SG
KR
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

· 1 week ago

ATT&CK Techniques

Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv6 Address 1 Domain 8 IPv4 Address 1 SHA-256 Hash 2 Filename 8

References

  1. cloud.google.com — Cited by web research for: Mustang Panda
  2. attack.mitre.org — Cited by web research for: Sandworm Team
  3. unit42.paloaltonetworks.com — Cited by web research for: BRONZE PRESIDENT
  4. attack.mitre.org — Cited by web research for: T1087

Intel Summary

40

Techniques

44

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Government Targeting

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.