UNC4736 is a financially motivated North Korean group known for supply chain attacks.
Analyst brief
UNC4736 is a financially motivated North Korean threat actor involved in supply chain attacks targeting software vendors like 3CX and X_TRADER. They focus on cryptocurrency and fintech-related services. Their TTPs include deploying malware strains such as TAXHAUL, Coldcat, and VEILEDSIGNAL to compromise both Windows and macOS systems, with observed infrastructure overlap with APT43. Defenders should prioritize software update integrity verification, network monitoring for related IOCs, and anti-phishing training.
UNC4736
unknown
UNC4736 is a North Korean threat actor that has been involved in supply chain attacks targeting software chains of 3CX and X_TRADER. They have used malware strains such as TAXHAUL, Coldcat, and VEILEDSIGNAL to compromise Windows and macOS systems. UNC4736 has been linked to financially motivated cybercrime operations, particularly focused on cryptocurrency and fintech-related services. They have also demonstrated infrastructure overlap with other North Korean and APT43 activity.
Who is UNC4736 and what are their primary target sectors?+
UNC4736 is a financially motivated North Korean threat actor. They primarily target the cryptocurrency sector, fintech companies, and their service providers.
What malware strains are associated with UNC4736?+
Malware strains used by UNC4736 include TAXHAUL, Coldcat, and VEILEDSIGNAL.