UNC2529 is a financially motivated threat actor known for global personalized phishing and DOUBLEDRAG fileless malware.
Analyst brief
UNC2529 is a financially motivated threat actor running global phishing campaigns across diverse industries. They use highly personalized lures and target research, with TTPs including the DOUBLEDRAG, DOUBLEDROP, and DOUBLEBACK fileless malware family, leveraging over 50 domains and at least one compromised legitimate domain. Defenders should focus on behavioral detection for fileless malware, scrutinize highly personalized suspicious emails, and monitor for unusual macro-enabled document execution and anomalous network connections.
UNC2529
unknown
UNC2529 is a well-resourced threat actor that conducted a global phishing campaign targeting various industries, utilizing tailored lures and sophisticated malware, including DOUBLEDRAG, DOUBLEDROP, and DOUBLEBACK. They compromised a legitimate domain to enhance their phishing efforts and employed at least 50 domains throughout the campaign. The actor demonstrated target research through personalized email addresses and subject lines, indicating a non-native English speaker. Their activities suggest a financial crime motive, with extensive use of obfuscation and fileless malware to evade detection.
What are the main malware families used by UNC2529?+
The main TTPs of UNC2529 include the fileless malware family consisting of DOUBLEDRAG, DOUBLEDROP, and DOUBLEBACK.
What distinguishes UNC2529's personalized phishing approach?+
They conduct target research to craft personalized email addresses and subject lines, leveraging over 50 domains and at least one compromised legitimate domain in their campaigns.