| SYMBOL | COMMON_NAME | aka. SYNONYMS |
UNC2529 is a well-resourced threat actor that conducted a global phishing campaign targeting various industries, utilizing tailored lures and sophisticated malware, including DOUBLEDRAG, DOUBLEDROP, and DOUBLEBACK. They compromised a legitimate domain to enhance their phishing efforts and employed at least 50 domains throughout the campaign. The actor demonstrated target research through personalized email addresses and subject lines, indicating a non-native English speaker. Their activities suggest a financial crime motive, with extensive use of obfuscation and fileless malware to evade detection.
There are currently no families associated with this actor.
| 2021-05-04
⋅
FireEye
⋅
The UNC2529 Triple Double: A Trifecta Phishing Campaign DOUBLEBACK UNC2529 |