UNC1130
2022-08-18 • Mandiant • Detecting Embedded Content in OOXML Documents
Mandiant's Advanced Practices team identifies UNC1130 as a North Korean state-sponsored threat cluster. Using a document-clustering technique built around embedded-file hashes in Office Open XML files, Mandiant found a specific embedded image reused across multiple malicious documents associated with separate activity clusters that drop the LATEOP malware family, attributing that set of documents to UNC1130 alongside two related, uncategorized clusters, UNC1837 and UNC1965. This embedded-image method grouped malicious documents despite other file changes and exposed recurring construction artifacts, indicating shared document-building tooling or infrastructure among these North Korea-linked activity sets.
-
43
Related Actors
-
799
Related Reports