Threat actor
UNC3524
Last fetched
UNC3524 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 66 techniques.
Description
Mandiant observed this group operating since December 2019. Its techniques partially overlap with multiple Russian-based espionage actors (APT28 and APT29). They are described as having a high level of operational security, low malware footprint, adept evasive skills, and a large Internet of Things (IoT) device botnet at their disposal.
Techniques by tactic
Persistence
- T1037 · Boot or Logon Initialization Scripts
- T1037.004 · RC Scripts
- T1053.005 · Scheduled Task
- T1078 · Valid Accounts
- T1078.003 · Local Accounts
- T1078.004 · Cloud Accounts
- T1098.002 · Additional Email Delegate Permissions
- T1098.005 · Device Registration
- T1133 · External Remote Services
- T1136.003 · Cloud Account
- T1505.003 · Web Shell
- T1546.003 · Windows Management Instrumentation Event Subscription
- T1546.008 · Accessibility Features
- T1547.001 · Registry Run Keys / Startup Folder
- T1556.007 · Hybrid Identity
Privilege Escalation
- T1037 · Boot or Logon Initialization Scripts
- T1037.004 · RC Scripts
- T1053.005 · Scheduled Task
- T1068 · Exploitation for Privilege Escalation
- T1078 · Valid Accounts
- T1078.003 · Local Accounts
- T1078.004 · Cloud Accounts
- T1098.002 · Additional Email Delegate Permissions
- T1098.005 · Device Registration
- T1546.003 · Windows Management Instrumentation Event Subscription
- T1546.008 · Accessibility Features
- T1547.001 · Registry Run Keys / Startup Folder
- T1548.002 · Bypass User Account Control
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to UNC3524 today — this states the absence of a published link, not that UNC3524 has no infrastructure.
References
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from UNC3524 into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.