APT / THREAT GROUP

UNC2970

🇰🇵North Korea-attributed
1
campaigns
1
aliases
Last seen:Mar 17, 2026

Intelligence Profile

UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes, often utilizing fake LinkedIn accounts to engage victims. The group employs the PLANKWALK backdoor and other malware families, leveraging compromised WordPress sites for command and control. They have been observed using BYOVD techniques to exploit vulnerable drivers for evading detection. Mandiant has noted a shift in UNC2970's targeting strategy, including a focus on security researchers and advancements in their operational capabilities against EDR tools.

Threat Analysis

UNC2970 is a known-sophistication threat actor attributed to North Korea, engaged in cyber operations with a primary motivation of unknown activity patterns.

Known Campaigns

UNC2970 — Active Operations March 2026

UNC2970 is a unknown-motivation threat actor attributed to North Korea. UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes, often utilizing fake LinkedIn accounts to engage victims. The group employs the PLANKWALK backdoor and other malware families, leveraging comprom...

ACTIVEMEDIUM2026

Intelligence Reports Mentioning UNC2970

External References

Quick Facts

TypeAPT / Threat Group
Origin🇰🇵 North Korea
Aliases1
SourceMalpedia

Also Known As

UNC2970

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.