← Threat Actors / North Korea / UNC2970
DOSSIER // UNC2970

UNC2970

▲ High Threat North Korea
Primary Aliases: APT38 APT45 Citrine Sleet DEV-0139
Confidence Rating 70% (Grounded)

UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes, often utilizing fake LinkedIn accounts to engage victims. The group employs the PLANKWALK backdoor and other malware families, leveraging compromised WordPress sites for command and control. They have been observed using BYOVD techniques to exploit vulnerable drivers for evading detection. Mandiant has noted a shift in UNC2970's targeting strategy, including a focus on security researchers and advancements in their operational capabilities against EDR tools.

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (8 TTPs)

📥 Download Navigator JSON
Copied to clipboard

LINK COPIED TO CLIPBOARD