Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin Campaigns

UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin Campaigns

Posted on July 18, 2025July 18, 2025 By CWS

Jul 18, 2025Ravie LakshmananCyber Espionage / Malware
A number of sectors in China, Hong Kong, and Pakistan have develop into the goal of a menace exercise cluster tracked as UNG0002 (aka Unknown Group 0002) as a part of a broader cyber espionage marketing campaign.
“This menace entity demonstrates a powerful choice for utilizing shortcut information (LNK), VBScript, and post-exploitation instruments corresponding to Cobalt Strike and Metasploit, whereas persistently deploying CV-themed decoy paperwork to lure victims,” Seqrite Labs researcher Subhajeet Singha stated in a report revealed this week.
The exercise encompasses two main campaigns, one referred to as Operation Cobalt Whisper which occurred between Could and September 2024, and Operation AmberMist that occurred between January and Could 2025.

Targets of those campaigns embody protection, electrotechnical engineering, vitality, civil aviation, academia, medical establishments, cybersecurity, gaming, and software program improvement sectors.
Operation Cobalt Whisper was first documented by Seqrite Labs in late October 2024, detailing using ZIP archives propagated by way of spear-phishing assaults to ship Cobalt Strike beacons, a post-exploitation framework, utilizing LNK and Visible Primary Scripts as interim payloads.
“The scope and complexity of the marketing campaign, coupled with the tailor-made lures, strongly counsel a focused effort by an APT group to compromise delicate analysis and mental property in these industries,” the corporate famous on the time.

The AmberMist assault chains have been discovered to leverage spear-phishing emails as a place to begin to ship LNK information masquerading as curriculum vitae and resumes to unleash a multi-stage an infection course of that ends in the deployment of INET RAT and Blister DLL loader.
Alternate assault sequences detected in January 2025 have been discovered to redirect e mail recipients to faux touchdown pages spoofing Pakistan’s Ministry of Maritime Affairs (MoMA) web site to serve faux CAPTCHA verification checks that make use of ClickFix techniques to launch PowerShell instructions, that are used to execute Shadow RAT.

Shadow RAT, launched by way of DLL side-loading, is able to establishing contact with a distant server to await additional instructions. INET RAT is assessed to be a modified model of Shadow RAT, whereas the Blister DLL implant features as a shellcode loader, ultimately paving the way in which for a reverse-shell primarily based implant.
The precise origins of the menace actor stay unclear, however proof factors to it being an espionage-focused group from Southeast Asia.
“UNG0002 represents a classy and protracted menace entity from South Asia that has maintained constant operations focusing on a number of Asian jurisdictions since at the very least Could 2024,” Singha stated. “The group demonstrates excessive adaptability and technical proficiency, constantly evolving their toolset whereas sustaining constant techniques, methods, and procedures.”

The Hacker News Tags:Campaigns, China, Files, Group, Hits, Hong, Kong, LNK, Pakistan, RATs, Twin, UNG0002

Post navigation

Previous Post: Ivanti Zero-Days Exploited to Drop MDifyLoader and Launch In-Memory Cobalt Strike Attacks
Next Post: China’s Massistant Tool Secretly Extracts SMS, GPS Data, and Images From Confiscated Phones

Related Posts

Google Halts Major Cyber Espionage Campaign Targeting 53 Entities Google Halts Major Cyber Espionage Campaign Targeting 53 Entities The Hacker News
Soco404 and Koske Malware Target Cloud Services with Cross-Platform Cryptomining Attacks Soco404 and Koske Malware Target Cloud Services with Cross-Platform Cryptomining Attacks The Hacker News
ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices The Hacker News
Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access The Hacker News
Your Digital Footprint Can Lead Right to Your Front Door Your Digital Footprint Can Lead Right to Your Front Door The Hacker News
DarkSword iOS Kit Exploits Multiple Flaws for Device Control DarkSword iOS Kit Exploits Multiple Flaws for Device Control The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark