Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DarkUniverse

Also known as: DarkUniverse, SIG27

Description

**Targets:** Tibet and Uyghur activists, Syria, Iran, Afghanistan, Tanzania, Ethiopia, Sudan, Russia, Belarus and the United Arab Emirates **Toolset/Malware:** ItaDuke **Modus Operandi:** Spearphishing w/CVE-2013-0640 weaponized PDF

TTP Summary

Spearphishing w/CVE-2013-0640 weaponized PDF

Goals & Targeting

Targeted Countries / Regions

RU
IR

AI Analysis

· 2 months ago

Executive Summary

DarkUniverse is a nation-state threat actor primarily motivated by espionage, targeting various sectors and countries including Tibet and Uyghur activists, Syria, Iran, and others. They utilize spearphishing attacks with weaponized PDFs exploiting CVE-2013-0640. The group's activities have been observed targeting multiple regions, indicating a wide-ranging intelligence gathering effort.

Goals & Targeting

DarkUniverse's strategic objectives appear to be centered on gathering intelligence from a wide array of sources, including but not limited to geopolitical, social, and potentially economic targets. Their targeting profile suggests an interest in both regional stability and the activities of specific ethnic and national groups. The actor seeks to achieve a deep understanding of the political, social, and military landscapes of their targets, which could be used to inform decision-making at a national level. Typical victims of DarkUniverse include political activists, government entities, and potentially organizations involved in international relations or strategic industries.

Enhanced Description

The employment of ItaDuke malware within their toolset further underscores the actor's focus on advanced, potentially customized capabilities for espionage. Given the diversity of their targets, it is reasonable to infer that DarkUniverse operates with a significant degree of autonomy in selecting and engaging targets, possibly based on evolving strategic objectives. The fact that they have been active in numerous regions, targeting both specific groups and countries, implies a well-resourced and adaptive threat actor.

Key Capabilities

  • Spearphishing with exploit kits
  • Use of customized malware (ItaDuke)
  • Social engineering
  • Exploitation of known vulnerabilities
  • Advanced persistent threat (APT) operations

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access

ATT&CK Techniques

T1566.001
T1059.003
T1055
T1204

Software / Tooling

ItaDuke
CVE-2013-0640 exploit kit

Campaigns & Victims

DarkUniverse's campaign patterns indicate a consistent focus on espionage, with operations potentially triggered by geopolitical events or shifts in international relations. Their operational tempo seems to be steady, with a continuous effort to compromise targets across various sectors and regions. Notable past operations include spearphishing campaigns targeting Tibet and Uyghur activists, as well as governmental and diplomatic entities in multiple countries. The actor's ability to adapt and evolve their tactics, particularly in the use of social engineering and exploit kits, suggests a mature and well-resourced campaign structure.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • Use of weaponized PDFs exploiting known vulnerabilities like CVE-2013-0640
  • Command and Control (C2) communications over HTTP or DNS

Recommended Actions

  • Implement robust email filtering and inspection to detect spearphishing attempts
  • Regularly update and patch software to prevent exploitation of known vulnerabilities
  • Conduct user awareness training on social engineering tactics
  • Deploy advanced threat detection systems capable of identifying customized malware

Suggested Tags

APT
Espionage
Nation-state
Spearphishing

Confidence Assessment

The confidence level in the available data regarding DarkUniverse is moderate to high, given the specific details on their modus operandi, toolset, and targeting profile. However, there are information gaps regarding the actor's full range of capabilities, the exact nature of their command structure, and the scope of their operations beyond the identified targets and sectors. Further intelligence gathering is necessary to fully understand the threat posed by DarkUniverse and to develop comprehensive defensive strategies.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Phishing

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.