Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors o-unc-038

Also known as: PlugX, tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, CANONSTAGER, SOGU.SEC, Mustang Panda, Volt Typhoon, contr, Scattered Spider, IT Workers, internet-of-things assets

Description

o-unc-038 operates as a highly skilled advanced persistent threat (APT) linked to Chinese state interests, employing a multi‑stage campaign that began in early 2025. Their phishing infrastructure comprises over two hundred legitimate‑looking domains and utilizes popular SaaS platforms such as Salesforce, SendGrid and Zoho for email delivery. Victims are redirected to faux Calendly interview pages that clone Google sign‑in or HR portals, enabling credential harvesting—including MFA token leakage—through browser‑in‑the‑box techniques. Beyond phishing, the group recently leveraged the zero‑day CVE-2024‑39717 in Versa Director SD‑WAN appliances. By targeting managed and internet service providers they gain privileged access to large segments of enterprise networks, then deploy the VersaMem web shell for persistence and lateral movement. The actor also uses traditional tools such as PlugX, Pikabot, and Machete for lateral exploitation, while maintaining a diverse malware portfolio that includes CANONSTAGER, REPTILE, Akira and Carbanak. All exfiltration is routed through Render‑hosted servers or Telegram bots, underscoring their use of public cloud resources as command‑and‑control infrastructure. Their broad sector coverage—encompassing aerospace, finance, energy, healthcare, defense, telecommunications and more—demonstrates a focused intent on intelligence gathering of strategic value.

Goals & Targeting

Targeted Sectors

Aerospace
Financial services
Retail
Entertainment
Energy
Communications
Manufacturing
Healthcare
Information technology
Transportation
Construction
Education
Defense
Government
Telecommunications
Critical infrastructure
Media
Non profit
Aviation
Hospitality
Pharmaceutical
Think tank
Legal services
Chemical
Mining
Gaming
Maritime
Nuclear
Oil gas
Utilities

Targeted Countries / Regions

CN
US
RU
UA
JP
SG
IR
GB
VN
AU
IN
TW
IL
PK
KR
KP
SA
DE
AE
PL
CA
TR
MX
ES
BY
FR
IT
KZ
RO
NG
LB
AZ
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

o-unc-038 is an advanced state‑backed threat actor whose operations combine sophisticated phishing campaigns with zero‑day exploitation of cloud and SD‑WAN infrastructure. They have targeted a broad spectrum of global enterprises using legitimate SaaS services for delivery, credential harvesting via AITM techniques, and a recent CVE-2024-39717 exploit in Versa Director to plant persistent web shells. The actor’s goal is to conduct widespread espionage across critical sectors while leveraging trusted relationships with managed service providers.

Goals & Targeting

o-unc-038 seeks to acquire actionable intelligence by infiltrating high‑value targets across numerous critical sectors worldwide. They exploit the trust placed in managed service providers, cloud services, and legitimate SaaS platforms to gain footholds early in the attack lifecycle. Their targeting profile spans both geographically diverse countries (from China, United States, Russia, Ukraine to many others) and mission‑critical industries such as defense, energy, government, telecommunications and pharmaceuticals, reflecting a classic state‑supported information‑warfare agenda directed at global influence and geopolitical advantage.

Enhanced Description

Key Capabilities

  • Multi‑stage phishing with legitimate SaaS delivery
  • Artificial ID theft via browser-in-the-box AITM
  • Zero‑day exploitation of CVE-2024-39717 in Versa Director SD-WAN
  • Persistent web shell deployment (VersaMem)
  • Credential harvesting from email MFA tokens
  • Command-and-control over Render/Telegram
  • Trusted‑relationship compromise with MSPs and ISPs
  • Exploitation of cloud compute infrastructure
  • Malleable malware portfolio including PlugX, Pikabot, Machete

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Privilege Escalation
Defense Evasion
Persistence
Command and Control
Exfiltration
Impact

ATT&CK Techniques

T1133
T1578
T1204.002
T1543.003
T1190
T1567
T1021
T1059
T1584
T1552.001
T1496.004
T1199
T1098
T1110
T1078
T1068
T1567.002
T1484
T1078.004
T1562

Software / Tooling

PlugX
Pikabot
STATICPLUGIN
Machete
CANONSTAGER
REPTILE
Akira
Carbanak
MOPSLED
RIFLESPINE
VIRTUALPITA
AppleJeus
Nmap
Triton
Winnti
Cobalt
SOGU
Dark
Medusa
Nexus
Conti
BlackByte
Confucius
Global
Kimsuky
Naikon
Void
Backdoors
Custom Malware
SolarWinds
OilRig
VersaMem
VersaDirector
REPTILE.CMD

Campaigns & Victims

The actor consistently employs a two‑phase strategy: initial compromise via phishing that leverages legitimate SaaS services for delivery and user trust, followed by exploitation of known or zero‑day vulnerabilities to attain privileged state access. Their campaigns show high operational tempo—deploying hundreds of domains in short periods—and they prioritize global enterprise sectors with strategic importance. While there is evidence of cross‑sector targeting in previous operations (e.g., PRC-Nexus and Volt Typhoon), recent activity remains focused on large managed service provider networks, a move that expands their internal foothold across multiple organizations simultaneously.

IOC Patterns

  • Domain spoofing via fake HR or Calendly domains
  • Embedded malicious Excel payloads such as enterprise-attack-v18.1-analytics.xlsx
  • Zero‑day exploitation indicator CVE-2024-39717 in Versa Director
  • VersaMem web shell signatures on servers
  • C2 traffic to Render-hosted sites and Telegram channels
  • Malleable AITM sign‑in page artifacts

Recommended Actions

  • Immediately patch all Versa Director SD‑WAN appliances against CVE-2024-39717 and related vulnerabilities.
  • Implement strict segmentation between customer networks and MSP/ISP infrastructure; isolate critical assets from externally managed segments.
  • Deploy endpoint detection and response (EDR) capable of detecting AITM activity, such as duplicate sign‑in pages or suspicious credential requests.
  • Configure MFA with additional verification methods that are not reliant on SMS/email alone; enforce enforcement across all cloud identities.
  • Continuously monitor DNS and network traffic for anomalous outbound connections to Render or Telegram bots and quarantine them.
  • Conduct regular threat hunting for the VersaMem web shell signature, phishing domain suffixes used by o-unc-038, and CVE‑specific exploitation patterns.
  • Apply multi‑layered defenses against SSO hijacking; flag repeated authentication failures that may indicate brute‑force attempts with T1110.
  • Educate users on recognizing fake HR or recruiter emails and provide clear reporting channels for suspicious messages.

Suggested Tags

Advanced Persistent Threat
Chinese State Actor
Zero-Day Exploit
CVE-2024-39717
Credential Theft
Phishing Campaign
Browser‑in‑the‑Box
AITM
Web Shell Deployment
SD‑WAN Vulnerability
Managed Service Provider Targeting
Internet Service Provider Targeting
Cloud Infrastructure Compromise
Mail-Based Delivery
Phonetic Spoofing

Confidence Assessment

The confidence in the core technical attribution—phishing via SaaS, exploitation of CVE-2024-39717, and use of VersaMem web shel­l—is high due to multiple independent reports. However, full attribution certainty remains moderate because alias overlap (o‑unc‑038 with other identified groups like Volt Typhoon) introduces ambiguity. Gaps exist in the precise duration of each campaign phase, scalability across all targeted sectors, and persistence mechanisms beyond the web shell.

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 IPv4 Address 2 Filename 5 SHA-256 Hash 2

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  3. cloud.google.com — Cited by web research for: CANONSTAGER
  4. www.paloaltonetworks.com — Cited by web research for: Volt Typhoon
  5. cloud.google.com — Cited by web research for: REPTILE
  6. https://www.okta.com/blog/threat-intelligence/jobseekers-exploited-in-fake-recruiter-phishing-campaigns/ — Cited by AI analysis.

Intel Summary

21

Techniques

47

Tools

1

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

APT
Phishing
Data Exfiltration
apt
phishing
espionage
credential-theft
Advanced Persistent Threat
Chinese State Actor
Zero-Day Exploit
CVE-2024-39717
Credential Theft
Phishing Campaign
Browser‑in‑the‑Box
AITM
Web Shell Deployment
SD‑WAN Vulnerability
Managed Service Provider Targeting
Internet Service Provider Targeting
Cloud Infrastructure Compromise
Mail-Based Delivery
Phonetic Spoofing

Details

Type
Nation-State
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
55%
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.