UNC3524

First seen
2019-12-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 12:01:40

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Mandiant observed this group operating since December 2019. Its techniques partially overlap with multiple Russian-based espionage actors (APT28 and APT29). They are described as having a high level of operational security, low malware footprint, adept evasive skills, and a large Internet of Things (IoT) device botnet at their disposal.

Reports & references

  • Mandiant — Unc3524 Eye Spy Email (report)

External references