Also known as: EXOTIC LILY, one private, tracked as, services, other system resources, public key cryptography, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
UNC2529 is a well‑resourced cybercrime group whose operations revolve around sophisticated spearphishing campaigns that leverage compromised legitimate domains and custom, highly personalized email content. The actors’ most widely reported activity is the "Triple Double" phishing operation launched in late 2020, which involved more than 50 malicious domains, targeted multiple industries such as procurement, HR and legal, and delivered a three‑stage malware ecosystem: 1) **DOUBLEDRAG**, a heavily obfuscated JavaScript downloader that infects victims with ZIP attachments containing corrupted PDFs. 2) **DOUBLEDROP**, a memory‑only PowerShell dropper that decrypts and injects a payload in RAM without touching disk. 3) **DOUBLEBACK**, an in‑memory backdoor written in C++ that persists through registry CLSID/COM registration, scheduled‑task creation, and conditional msiexec injection while evading antivirus scanners. The actors routinely use RC4‑style encryption for configuration blobs stored in the Windows Registry, employ XOR‑encoded launchers, create Global{GUID} mutexes to enforce single instances, and manipulate shell processes via dynamic API resolution. They also target known security products (Kaspersky, BitDefender) to bypass analysis, abuse UAC bypass techniques, setuid/gid bits on Linux/macOS, manipulate macOS TCC and Service classes, inject into PowerShell.exe or msiexec.exe for privilege escalation and persistence, and maintain a large C2 infrastructure that includes serverless functions (Google Apps Scripts, AWS Lambda, Cloudflare Workers). Their tactics span almost every ATT&CK domain, from initial spearphishing through credential theft, data exfiltration, sabotage of cloud configurations, to defensive evasion. UNC2529’s threat profile is therefore indicative of a financially focused, highly technical cyber‐criminal organization that blends social engineering with zero‑day‑style persistence and fileless execution to conduct data theft and potentially extortion.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC2529 is a financially‑motivated threat actor that executed a global spearphishing operation known as the "Triple Double" campaign, delivering three fileless malware families—DOUBLEDRAG, DOUBLEDROP and DOUBLEBACK—to dozens of organizations worldwide. The actors employ heavily obfuscated JavaScript and PowerShell download chains, register in-memory backdoors through clever persistence mechanisms, and target a wide range of sectors via tailored lures.
Goals & Targeting
The group clearly pursues financial gains by targeting procurement, HR, legal and other high‑value business units. Their tailored lures reference roles such as "worker" or "candidate," suggesting a focus on extracting monetary data (e.g., invoicing software manipulation) or exploiting privileged accounts for further lateral movement and credential theft. The use of compromised legitimate domains indicates an intent to bypass email filtering while maintaining a global reach across multiple countries.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
40
Techniques
60
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics