UNG0002: Regional Threat Operations Tracked Across Multiple Asian Jurisdictions
ID: 22844967-9ccb-564d-8eed-c39660b3afb4
STIX ID: report--22844967-9ccb-564d-8eed-c39660b3afb4
Feed Name: Seqrite Blog
Seqrite Labs APT-Team tracks UNG0002, an espionage-focused threat cluster active since at least May 2024 that targets organizations across China, Hong Kong, Pakistan and other Asian jurisdictions. The group uses multi-stage infection chains (malicious LNKs, VBScript, batch, PowerShell), social engineering (fake CAPTCHA 'ClickFix'), DLL sideloading of legitimate binaries (rasphone, node-webkit), and custom implants (Shadow RAT, INET RAT, Blister DLL). Two major campaigns—Operation Cobalt Whisper and Operation AmberMist—show evolution from commodity frameworks (Cobalt Strike, Metasploit) to lightweight custom loaders and RATs, with numerous IOCs and MITRE ATT&CK mappings provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
