UNC2970UNC2970

Also known as: UNC2970

Known aliases
1

Profile

UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes, often utilizing fake LinkedIn accounts to engage victims. The group employs the PLANKWALK backdoor and other malware families, leveraging compromised WordPress sites for command and control. They have been observed using BYOVD techniques to exploit vulnerable drivers for evading detection. Mandiant has noted a shift in UNC2970's targeting strategy, including a focus on security researchers and advancements in their operational capabilities against EDR tools.

Aliases· 1

UNC2970

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC2717
Actor
UNC1069
Actor
UNC2630
Actor
UNC4990
Actor
UNC2659
Actor
UNC3524
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.