Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC2529

Also known as: EXOTIC LILY, one private, tracked as, services, other system resources, public key cryptography, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

UNC2529 is a well‑resourced cybercrime group whose operations revolve around sophisticated spearphishing campaigns that leverage compromised legitimate domains and custom, highly personalized email content. The actors’ most widely reported activity is the "Triple Double" phishing operation launched in late 2020, which involved more than 50 malicious domains, targeted multiple industries such as procurement, HR and legal, and delivered a three‑stage malware ecosystem: 1) **DOUBLEDRAG**, a heavily obfuscated JavaScript downloader that infects victims with ZIP attachments containing corrupted PDFs. 2) **DOUBLEDROP**, a memory‑only PowerShell dropper that decrypts and injects a payload in RAM without touching disk. 3) **DOUBLEBACK**, an in‑memory backdoor written in C++ that persists through registry CLSID/COM registration, scheduled‑task creation, and conditional msiexec injection while evading antivirus scanners. The actors routinely use RC4‑style encryption for configuration blobs stored in the Windows Registry, employ XOR‑encoded launchers, create Global{GUID} mutexes to enforce single instances, and manipulate shell processes via dynamic API resolution. They also target known security products (Kaspersky, BitDefender) to bypass analysis, abuse UAC bypass techniques, setuid/gid bits on Linux/macOS, manipulate macOS TCC and Service classes, inject into PowerShell.exe or msiexec.exe for privilege escalation and persistence, and maintain a large C2 infrastructure that includes serverless functions (Google Apps Scripts, AWS Lambda, Cloudflare Workers). Their tactics span almost every ATT&CK domain, from initial spearphishing through credential theft, data exfiltration, sabotage of cloud configurations, to defensive evasion. UNC2529’s threat profile is therefore indicative of a financially focused, highly technical cyber‐criminal organization that blends social engineering with zero‑day‑style persistence and fileless execution to conduct data theft and potentially extortion.

Goals & Targeting

Targeted Sectors

Defense
Financial services
Media
Government
Healthcare
Manufacturing
Information technology
Aerospace
Energy
Education

Targeted Countries / Regions

US
SA
AU

AI Analysis

Grounded in web research
· analyzed in 91 chunks · 5 days ago

Executive Summary

UNC2529 is a financially‑motivated threat actor that executed a global spearphishing operation known as the "Triple Double" campaign, delivering three fileless malware families—DOUBLEDRAG, DOUBLEDROP and DOUBLEBACK—to dozens of organizations worldwide. The actors employ heavily obfuscated JavaScript and PowerShell download chains, register in-memory backdoors through clever persistence mechanisms, and target a wide range of sectors via tailored lures.

Goals & Targeting

The group clearly pursues financial gains by targeting procurement, HR, legal and other high‑value business units. Their tailored lures reference roles such as "worker" or "candidate," suggesting a focus on extracting monetary data (e.g., invoicing software manipulation) or exploiting privileged accounts for further lateral movement and credential theft. The use of compromised legitimate domains indicates an intent to bypass email filtering while maintaining a global reach across multiple countries.

Enhanced Description

Key Capabilities

  • Spearphishing via attachment and link
  • JavaScript downloader (DOUBLEDRAG)
  • PowerShell memory‑only dropper (DOUBLEDROP)
  • In‑memory backdoor persistence (DOUBLEBACK)
  • RC4/xor obfuscated payload storage in registry
  • Registry CLSID/COM persistence
  • Scheduled task creation for elevated execution
  • msiexec injection with conditional AV bypass
  • Process injection into PowerShell.exe and msiexec.exe
  • Anti‑AV / anti‑sandbox techniques
  • UAC bypass and setuid/setgid abuse
  • MacOS TCC manipulation
  • Account discovery, acquisition and privilege escalation
  • Credential dumping (LSASS/Keychain/SAM)
  • Data collection (screenshots, clipboard, audio capture)
  • Cloud infrastructure exploitation for staging and C2
  • Domain hijacking and DNS manipulation
  • Fileless execution via compressed archives
  • Custom lure and subject line personalization

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 19 Filename 1

References

  1. attack.mitre.org — Cited by web research for: one private
  2. cloud.google.com — Cited by web research for: T1055
  3. www.recordedfuture.com — Cited by web research for: T1497
  4. attack.mitre.org — Cited by web research for: STOP
  5. cloud.google.com — Cited by web research for: CALENDAR
  6. www.infosecurity-magazine.com — Cited by web research for: US

Intel Summary

40

Techniques

60

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

APT
Phishing
Fileless Malware
Financial Crime
Global Threat Actor

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
Jul 27, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.