UNC3524 is an espionage group active since 2019, known for high operational security and targeting email servers.
Analyst brief
UNC3524 is an espionage actor active since December 2019, known for high operational security and techniques partially overlapping with Russia-based APT28 and APT29. It primarily targets corporate networks, focusing on email servers, while maintaining a low malware footprint and leveraging a large IoT botnet. Defenders should monitor for anomalies in IoT devices, unauthorized email server access attempts, and subtle lateral movement within the network.
UNC3524
unknown
Mandiant observed this group operating since December 2019. Its techniques partially overlap with multiple Russian-based espionage actors (APT28 and APT29). They are described as having a high level of operational security, low malware footprint, adept evasive skills, and a large Internet of Things (IoT) device botnet at their disposal.