UNC2970 is a North Korean threat actor known for job-themed spear-phishing, fake LinkedIn personas, and aggressive EDR evasion tactics.
Analyst brief
UNC2970 is a North Korean threat actor using job-themed spear-phishing emails and fake LinkedIn personas. It targets organizations, with a noted shift toward security researchers and aggressive focus on EDR evasion. Key TTPs include the PLANKWALK backdoor, BYOVD technique exploiting vulnerable drivers, and compromised WordPress sites for C2. Defenders should watch for recruitment-themed phishing, suspicious LinkedIn outreach, and anomalous driver loading activity.
UNC2970
unknown
UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes, often utilizing fake LinkedIn accounts to engage victims. The group employs the PLANKWALK backdoor and other malware families, leveraging compromised WordPress sites for command and control. They have been observed using BYOVD techniques to exploit vulnerable drivers for evading detection. Mandiant has noted a shift in UNC2970's targeting strategy, including a focus on security researchers and advancements in their operational capabilities against EDR tools.