UNC3782
2023-04-20 • Mandiant • 3CX Software Supply Chain Compromise Initiated by…
UNC3782 is an uncategorized threat cluster tracked by Mandiant, first surfacing in Mandiant's April 2023 analysis of the 3CX software supply chain compromise, where researchers identified weak infrastructure overlap between UNC3782 and suspected activity from North Korea's APT43, alongside a related cluster, UNC4469. A later independent research write-up, published in November 2025, elaborated on UNC3782's activity, describing extensive use of typosquatted domains impersonating the South Korean web portal Naver Corp for phishing operations that ran from 2021 through the end of 2022. In late 2022 the group began registering cryptocurrency-themed domains for the first time, a shift from its prior pattern, with the new infrastructure believed to target holders of NFTs and cryptocurrency. The researcher noted the overlap Mandiant had identified between UNC3782 and North Korea's APT43, also known as Kimsuky, but stated it remains unclear whether UNC3782 and APT43 are the same actor.
-
43
Related Actors
-
799
Related Reports