Mandiant's Advanced Practices team identifies UNC1130 as a North Korean state-sponsored threat cluster. Using a document-clustering technique built around embedded-file hashes in Office Open XML files, Mandiant found a specific embedded image reused across multiple malicious documents associated with separate activity clusters that drop the LATEOP malware family, attributing that set of documents to UNC1130 alongside two related, uncategorized clusters, UNC1837 and UNC1965. This embedded-image method grouped malicious documents despite other file changes and exposed recurring construction artifacts, indicating shared document-building tooling or infrastructure among these North Korea-linked activity sets.
Actors
249 actors
UNC1720 is an uncategorized cluster designation used by Mandiant that corresponds to the publicly reported AppleJeus activity, assessed to have been active since at least 2018. The group primarily targets the cryptocurrency industry, using spear-phishing emails and fake cryptocurrency trading software to infiltrate victim systems and steal digital assets intended to fund the North Korean regime's priorities. Mandiant assesses that this crypto-focused activity emerged after the notoriety surrounding the Bangladesh Bank heist exposed the difficulty of stealing and laundering traditional currency at scale, prompting a shift toward direct theft of cryptocurrency. The group's tooling overlaps with that used by TEMP.Hermit, though the two clusters are not focused on the same targeting profiles, which Mandiant suggests may indicate the sharing of development resources between otherwise distinct North Korean cyber operators rather than a single unified group.
UNC2970 is Mandiant’s designation for a suspected North Korean espionage actor assessed with high confidence to overlap UNC577, also known as TEMP.Hermit. Mandiant began tracking the cluster in June 2022 after intrusions against Western technology and media companies, including suspected targeting of security researchers. The actor uses Operation Dream Job-style recruitment lures, polished fake recruiter profiles on LinkedIn, and extended conversations over WhatsApp before delivering tailored job descriptions or skills tests. Payloads have included malicious Word templates, ISO files, trojanized TightVNC software, and custom families such as LIDSHIFT, LIDSHOT, PLANKWALK, TOUCHSHIFT, TOUCHKEY, TOUCHSHOT, and HOOKSHOT. UNC2970 compromises legitimate WordPress sites for command-and-control, performs system reconnaissance, steals keystrokes and screenshots, tunnels traffic, and deploys layered in-memory payloads. Its campaigns show careful target research and persistent social engagement designed to penetrate strategically valuable organizations in the United States and Europe.
UNC3782 is an uncategorized threat cluster tracked by Mandiant, first surfacing in Mandiant's April 2023 analysis of the 3CX software supply chain compromise, where researchers identified weak infrastructure overlap between UNC3782 and suspected activity from North Korea's APT43, alongside a related cluster, UNC4469. A later independent research write-up, published in November 2025, elaborated on UNC3782's activity, describing extensive use of typosquatted domains impersonating the South Korean web portal Naver Corp for phishing operations that ran from 2021 through the end of 2022. In late 2022 the group began registering cryptocurrency-themed domains for the first time, a shift from its prior pattern, with the new infrastructure believed to target holders of NFTs and cryptocurrency. The researcher noted the overlap Mandiant had identified between UNC3782 and North Korea's APT43, also known as Kimsuky, but stated it remains unclear whether UNC3782 and APT43 are the same actor.
Mandiant Managed Defense identified the threat cluster it tracks as UNC4034 during proactive threat hunting in July 2022, assessing several overlaps with other activity suspected to have a North Korea nexus. UNC4034 established contact with a media-industry employee by offering a fake Amazon job opportunity, then moved communication to WhatsApp, where it shared a malicious ISO disk image disguised as an assessment file. The ISO contained a trojanized, unsigned build of the open-source PuTTY utility that, once the victim attempted an SSH connection, wrote a legitimate Windows executable and a companion malicious DLL to disk, using DLL search-order hijacking and scheduled-task persistence to deploy the AIRDRY.V2 backdoor, an evolution of malware Mandiant had previously tracked, also known publicly as BLINDINGCAN. Mandiant found a near-identical second ISO on VirusTotal using a different code-insertion location but the same payload-dropping mechanism and backdoor, indicating a repeatable operational toolkit rather than a one-off intrusion.
UNC4469 is a suspected APT43-related activity cluster. Mandiant identified weak infrastructure overlap between UNC4469, UNC4736, and another suspected APT43 cluster, while assessing the broader overlapping activity as linked to North Korean operations targeting cryptocurrency users and services.
Mandiant assigned the cluster designator UNC4736 during its 2023 response to the 3CX Desktop App supply-chain compromise, assessing with high confidence a North Korean nexus and, with moderate confidence, overlap with financially motivated AppleJeus activity, also tracked as Citrine Sleet. Mandiant traced the intrusion to an earlier compromise of Trading Technologies' X_TRADER installer, trojanized with the VEILEDSIGNAL backdoor, which let the actor steal an employee's corporate credentials, move laterally using a renamed Fast Reverse Proxy tool, and compromise 3CX's Windows and macOS build environments using TAXHAUL/COLDCAT and the POOLRAT backdoor, ultimately trojanizing the 3CX app with a SUDDENICON downloader and ICONICSTEALER data miner. Mandiant later attributed the October 2024 theft of roughly $50 million from DeFi platform Radiant Capital to the cluster after developers were lured via Telegram into opening a fake PDF report that deployed the INLETDRIFT macOS backdoor and enabled manipulation of signed transactions. Subsequent researchers linked the April 2026 Drift Protocol exploit and a memory-resident RemotePE malware chain used in financial-espionage intrusions to the same cluster, described as aligned with North Korea's Reconnaissance General Bureau.
UNC4899 is a designation Mandiant uses for a Democratic People's Republic of Korea-nexus threat actor that Mandiant assesses, with high confidence, functions as a cryptocurrency-focused element within North Korea's Reconnaissance General Bureau, and which Mandiant believes likely corresponds to the actor publicly reported as TraderTraitor. Mandiant first disclosed the designation in connection with a July 2023 supply-chain compromise in which the actor gained initial access to a software solutions company by compromising the JumpCloud identity and access management platform, deploying a malicious Ruby script through JumpCloud's agent to reach downstream customer systems. The intrusion involved macOS backdoors that Mandiant named FULLHOUSE.DOORED and STRATOFEAR, deployed within 24 hours of initial access and disguised as legitimate applications such as Docker and Zoom components. In subsequent reporting, Mandiant grouped UNC4899 with a related cluster, UNC4736, behind the 3CX and Trading Technologies supply-chain attacks, describing both as sophisticated, consistent operations that use trusted software providers to gain broad downstream network access.
UNC5267 is Mandiant’s designation for North Korean government-directed IT-worker operations observed across victim environments. Mandiant has tracked the activity since 2022, while some reporting places its origins around 2018. UNC5267 is not a centralized intrusion group but a dispersed workforce based primarily in China and Russia, with smaller populations elsewhere, whose members use stolen or fabricated identities to obtain remote employment at Western companies. Operators apply for multiple jobs, reuse resumes and personas, rely on facilitators and laptop farms, and remotely control corporate devices through KVM hardware, virtual-private networks, and commercial administration tools. Their primary objective is illicit salary generation for the North Korean regime, but their legitimate workplace access creates opportunities for source-code theft, espionage, extortion, and future intrusion. The activity combines identity fraud, sanctions evasion, insider access, remote infrastructure, and long-term presence inside technology-sector organizations.