UTG-Q-010 is a financially motivated APT group known for targeting pharma and crypto via DLL sideloading.
Analyst brief
UTG-Q-010 is a financially motivated APT group of likely East Asian origin active since late 2022. It primarily targets the pharmaceutical industry and cryptocurrency enthusiasts, with a focus on HR departments. Their TTPs include DLL sideloading using legitimate Windows processes like "WerFault.exe" to load malicious "faultrep.dll," deploying Pupy RAT, and using in-memory execution for defense evasion. Defenders should monitor for anomalous DLL sideloading, phishing campaigns targeting pharmaceutical firms, and suspicious in-memory process behaviors.
UTG-Q-010
unknown
UTG-Q-010 is a financially motivated APT group from East Asia that has been active since late 2022, primarily targeting the pharmaceutical industry and cryptocurrency enthusiasts. They exploit legitimate Windows processes, such as "WerFault.exe," to sideload malicious DLLs like "faultrep.dll" and employ sophisticated phishing campaigns to deliver malware disguised as enticing content. Their recent campaigns have involved the use of the Pupy RAT and advanced defense evasion techniques, including in-memory execution and reflective DLL loading. UTG-Q-010's strategic focus on HR departments and the cryptocurrency sector highlights their understanding of target vulnerabilities and their ability to evade detection.
What is the primary malicious tool used by the UTG-Q-010 group?+
The group primarily uses Pupy RAT.
What specific DLL sideloading behavior should defenders monitor to detect UTG-Q-010 activity?+
Defenders should monitor for anomalous DLL sideloading, such as legitimate Windows processes like "WerFault.exe" loading malicious DLLs like "faultrep.dll".