UNC2970

First seen
2021-06-01 00:00:00
Origin
KP
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:17:18

Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:kr country_code:jp

Context

UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes, often utilizing fake LinkedIn accounts to engage victims. The group employs the PLANKWALK backdoor and other malware families, leveraging compromised WordPress sites for command and control. They have been observed using BYOVD techniques to exploit vulnerable drivers for evading detection. Mandiant has noted a shift in UNC2970's targeting strategy, including a focus on security researchers and advancements in their operational capabilities against EDR tools.

Reports & references

  • Mandiant — Lightshow North Korea Unc2970 (report)

External references