Also known as: PlugX, tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, CANONSTAGER, SOGU.SEC, Mustang Panda, Volt Typhoon, contr, Scattered Spider, IT Workers, internet-of-things assets
o-unc-038 operates as a highly skilled advanced persistent threat (APT) linked to Chinese state interests, employing a multi‑stage campaign that began in early 2025. Their phishing infrastructure comprises over two hundred legitimate‑looking domains and utilizes popular SaaS platforms such as Salesforce, SendGrid and Zoho for email delivery. Victims are redirected to faux Calendly interview pages that clone Google sign‑in or HR portals, enabling credential harvesting—including MFA token leakage—through browser‑in‑the‑box techniques. Beyond phishing, the group recently leveraged the zero‑day CVE-2024‑39717 in Versa Director SD‑WAN appliances. By targeting managed and internet service providers they gain privileged access to large segments of enterprise networks, then deploy the VersaMem web shell for persistence and lateral movement. The actor also uses traditional tools such as PlugX, Pikabot, and Machete for lateral exploitation, while maintaining a diverse malware portfolio that includes CANONSTAGER, REPTILE, Akira and Carbanak. All exfiltration is routed through Render‑hosted servers or Telegram bots, underscoring their use of public cloud resources as command‑and‑control infrastructure. Their broad sector coverage—encompassing aerospace, finance, energy, healthcare, defense, telecommunications and more—demonstrates a focused intent on intelligence gathering of strategic value.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
o-unc-038 is an advanced state‑backed threat actor whose operations combine sophisticated phishing campaigns with zero‑day exploitation of cloud and SD‑WAN infrastructure. They have targeted a broad spectrum of global enterprises using legitimate SaaS services for delivery, credential harvesting via AITM techniques, and a recent CVE-2024-39717 exploit in Versa Director to plant persistent web shells. The actor’s goal is to conduct widespread espionage across critical sectors while leveraging trusted relationships with managed service providers.
Goals & Targeting
o-unc-038 seeks to acquire actionable intelligence by infiltrating high‑value targets across numerous critical sectors worldwide. They exploit the trust placed in managed service providers, cloud services, and legitimate SaaS platforms to gain footholds early in the attack lifecycle. Their targeting profile spans both geographically diverse countries (from China, United States, Russia, Ukraine to many others) and mission‑critical industries such as defense, energy, government, telecommunications and pharmaceuticals, reflecting a classic state‑supported information‑warfare agenda directed at global influence and geopolitical advantage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The actor consistently employs a two‑phase strategy: initial compromise via phishing that leverages legitimate SaaS services for delivery and user trust, followed by exploitation of known or zero‑day vulnerabilities to attain privileged state access. Their campaigns show high operational tempo—deploying hundreds of domains in short periods—and they prioritize global enterprise sectors with strategic importance. While there is evidence of cross‑sector targeting in previous operations (e.g., PRC-Nexus and Volt Typhoon), recent activity remains focused on large managed service provider networks, a move that expands their internal foothold across multiple organizations simultaneously.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core technical attribution—phishing via SaaS, exploitation of CVE-2024-39717, and use of VersaMem web shell—is high due to multiple independent reports. However, full attribution certainty remains moderate because alias overlap (o‑unc‑038 with other identified groups like Volt Typhoon) introduces ambiguity. Gaps exist in the precise duration of each campaign phase, scalability across all targeted sectors, and persistence mechanisms beyond the web shell.
Phishing Domains
Imported from MISP event #1366 (5b16dc9e-eb88-47b0-8ccd-fbae0acd0835).
Jun 5, 2018
TLP:CLEARNo observed data linked yet.
21
Techniques
47
Tools
1
Campaigns
40
IOCs
0
Observed Data
12
Tactics