Threat actor
UNC6384
Last fetched
UNC6384 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 85 techniques and also known as 1 other name.
Also known as
Vertigo Panda
Description
UNC6384 (also tracked as Vertigo Panda) is a Chinese-affiliated APT that conducts targeted espionage campaigns primarily against diplomatic entities in Southeast Asia and Europe, specifically Belgium and Hungary. The group exploits the ZDI-CAN-25373 Windows shortcut vulnerability to gain initial code execution via malicious .LNK files, deploying the PlugX RAT through sophisticated delivery mechanisms, including DLL side-loading and adversary-in-the-middle attacks. Their operations involve social engineering tactics, such as spear-phishing emails themed around diplomatic events, to entice victims into executing malicious payloads. UNC6384's use of valid code signing and HTTPS hosting enhances their evasion of detection and increases the likelihood of user interaction.
Techniques by tactic
Command and Control
- T1001.003 · Protocol or Service Impersonation
- T1071.001 · Web Protocols
- T1095 · Non-Application Layer Protocol
- T1102 · Web Service
- T1105 · Ingress Tool Transfer
- T1205 · Traffic Signaling
- T1219.001 · IDE Tunneling
- T1219.002 · Remote Desktop Software
- T1572 · Protocol Tunneling
- T1573.001 · Symmetric Cryptography
Discovery
- T1016 · System Network Configuration Discovery
- T1018 · Remote System Discovery
- T1046 · Network Service Discovery
- T1049 · System Network Connections Discovery
- T1057 · Process Discovery
- T1069.002 · Domain Groups
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1087.002 · Domain Account
- T1518 · Software Discovery
- T1622 · Debugger Evasion
- T1654 · Log Enumeration
Execution
- T1047 · Windows Management Instrumentation
- T1053.005 · Scheduled Task
- T1059 · Command and Scripting Interpreter
- T1059.001 · PowerShell
- T1059.003 · Windows Command Shell
- T1059.005 · Visual Basic
- T1059.007 · JavaScript
- T1072 · Software Deployment Tools
- T1106 · Native API
- T1129 · Shared Modules
- T1203 · Exploitation for Client Execution
- T1204.001 · Malicious Link
- T1204.002 · Malicious File
- T1574.001 · DLL
- T1574.005 · Executable Installer File Permissions Weakness
Stealth
- T1027 · Obfuscated Files or Information
- T1027.007 · Dynamic API Resolution
- T1027.012 · LNK Icon Smuggling
- T1027.016 · Junk Code Insertion
- T1036.005 · Match Legitimate Resource Name or Location
- T1036.007 · Double File Extension
- T1036.008 · Masquerade File Type
- T1070 · Indicator Removal
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1140 · Deobfuscate/Decode Files or Information
- T1205 · Traffic Signaling
- T1218.004 · InstallUtil
- T1218.005 · Mshta
- T1564.001 · Hidden Files and Directories
- T1574.001 · DLL
- T1574.005 · Executable Installer File Permissions Weakness
- T1622 · Debugger Evasion
- T1678 · Delay Execution
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to UNC6384 today — this states the absence of a published link, not that UNC6384 has no infrastructure.
References
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from UNC6384 into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.