UNC1130

2022-08-18 • MandiantDetecting Embedded Content in OOXML Documents

Mandiant's Advanced Practices team identifies UNC1130 as a North Korean state-sponsored threat cluster. Using a document-clustering technique built around embedded-file hashes in Office Open XML files, Mandiant found a specific embedded image reused across multiple malicious documents associated with separate activity clusters that drop the LATEOP malware family, attributing that set of documents to UNC1130 alongside two related, uncategorized clusters, UNC1837 and UNC1965. This embedded-image method grouped malicious documents despite other file changes and exposed recurring construction artifacts, indicating shared document-building tooling or infrastructure among these North Korea-linked activity sets.

Related Actors

Related Reports in This Cluster

Top Authors

View UNC1130 reports only

View UNC1130 reports only