Skip to main content
Mallory
3 malware families

UNC3524

Also known asUNC3524

UNC3524 is an espionage-focused threat actor tracked by Mandiant, characterized by long dwell time (reported up to ~18 months) and strong operational security through operating from victim “blind spots,” including uncommon/unsupported Linux servers and opaque network appliances not covered by typical agent-based security tooling. For lateral movement, UNC3524 used a customized version of Impacket’s WMIEXEC, specifically modifying the default output file path/filename (e.g., changing from the default \127.0.0.1\ADMIN$\debug\DEBUG.LOG) to evade filename-based detections. The actor used built-in Windows utilities such as reg save to collect registry hives for offline extraction of LSA secrets. After obtaining privileged credentials in victim mail environments, UNC3524 used Exchange Web Services (EWS) against on-premises Microsoft Exchange and/or Microsoft 365 Exchange Online to enumerate and exfiltrate email. The actor targeted a subset of mailboxes, focusing on executive teams and personnel in corporate development/mergers & acquisitions and IT security (with an assessment that IT security staff were targeted to gauge detection status). Authentication to Exchange evolved over time and included use of targeted users’ usernames/passwords, accounts with ApplicationImpersonation rights, and Service Principal credentials. Tradecraft included EWS GetFolder/FindFolder for mailbox enumeration, FindItem queries filtered by DateTimeCreated since a last-access time (noted as similar to an approach previously observed by Mandiant with APT29), and GetItem retrieval with IncludeMimeContent=true to obtain full MIME content (body and attachments). For encrypted messages (e.g., PGP, S/MIME, OME), responses contained ciphertext or (for OME) an authentication link. For command-and-control and operational infrastructure, Mandiant identified UNC3524 C2 systems primarily as compromised, internet-exposed LifeSize conference room camera devices and, in one case, a D-Link IP camera, assessed as likely compromised via default credentials (rather than an exploit) and sometimes exposed due to misconfiguration such as UPnP and/or older firmware. UNC3524 used the QUIETEXIT tunneler to reduce tool footprint and support “living off the land.” Mandiant reported technique overlap with Russia-based espionage actors (including APT29 and APT28, e.g., similarities in date-range email collection and REGEORG-related tradecraft), but stated it could not conclusively link UNC3524 to an existing tracked group at the time of reporting.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics40 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
3 techniques
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
T1584
Compromise Infrastructure
T1608
Stage Capabilities
T1608.003
Install Digital Certificate
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
TA0003
Persistence
3 techniques
T1037
Boot or Logon Initialization Scripts
T1037.004
RC Scripts
T1098
Account Manipulation
T1098.001
Additional Cloud Credentials
T1505
Server Software Component
T1505.003
Web Shell
TA0004
Privilege Escalation
2 techniques
T1037
Boot or Logon Initialization Scripts
T1037.004
RC Scripts
T1098
Account Manipulation
T1098.001
Additional Cloud Credentials
TA0005
Stealth
1 technique
T1027
Obfuscated Files or Information
TA0006
Credential Access
2 techniques
T1003
OS Credential Dumping
T1003.004
LSA Secrets
T1003.006
DCSync
T1111
Multi-Factor Authentication Interception
TA0007
Discovery
5 techniques
T1012
Query Registry
T1016
System Network Configuration Discovery
T1049
System Network Connections Discovery
T1057
Process Discovery
T1518
Software Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.003
Distributed Component Object Model
T1021.004
SSH
TA0009
Collection
1 technique
T1114
Email Collection
T1114.002
Remote Email Collection
TA0011
Command and Control
5 techniques
T1071
Application Layer Protocol
T1090
Proxy
T1090.003
Multi-hop Proxy
T1095
Non-Application Layer Protocol
T1572
Protocol Tunneling
T1573
Encrypted Channel
T1573.002
Asymmetric Cryptography
ACTIVITY FEED

Recent activity

1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.

No news coverage yet. Advisories and community discussion only.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping26

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.