logo

UNG0002: Regional Threat Operations Tracked Across Multiple Asian Jurisdictions

ID: 22844967-9ccb-564d-8eed-c39660b3afb4

STIX ID: report--22844967-9ccb-564d-8eed-c39660b3afb4

Feed Name: Seqrite Blog

Threat Score
85/100

Date Published: 2025-07-16

Date Updated: 2026-04-30

Author: Subhajeet Singha

...
...

Seqrite Labs APT-Team tracks UNG0002, an espionage-focused threat cluster active since at least May 2024 that targets organizations across China, Hong Kong, Pakistan and other Asian jurisdictions. The group uses multi-stage infection chains (malicious LNKs, VBScript, batch, PowerShell), social engineering (fake CAPTCHA 'ClickFix'), DLL sideloading of legitimate binaries (rasphone, node-webkit), and custom implants (Shadow RAT, INET RAT, Blister DLL). Two major campaigns—Operation Cobalt Whisper and Operation AmberMist—show evolution from commodity frameworks (Cobalt Strike, Metasploit) to lightweight custom loaders and RATs, with numerous IOCs and MITRE ATT&CK mappings provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.