UNC3524
- First seen
- 2019-12-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 12:01:40
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Mandiant observed this group operating since December 2019. Its techniques partially overlap with multiple Russian-based espionage actors (APT28 and APT29). They are described as having a high level of operational security, low malware footprint, adept evasive skills, and a large Internet of Things (IoT) device botnet at their disposal.
Reports & references
- Mandiant — Unc3524 Eye Spy Email (report)