UNK_SparkyCarp is a China-aligned espionage threat cluster tracked for targeted credential-phishing operations against Taiwan’s semiconductor sector. The actor has been observed targeting at least one Taiwanese semiconductor company and is associated with broader campaigns against chip manufacturers and related organizations in Taiwan’s semiconductor ecosystem. Reporting places its activity in late 2024 and again in March 2025, indicating repeated interest in the same strategic sector. The cluster is characterized by adversary-in-the-middle phishing designed to harvest account credentials. Its lures have impersonated account or login security alerts and directed victims to counterfeit authentication portals operated by the attackers. This tradecraft is consistent with credential interception rather than malware-heavy intrusion chains, and reflects a focused collection objective against personnel in strategically important semiconductor organizations. UNK_SparkyCarp has been assessed as part of a wider set of China-aligned operations targeting Taiwan’s chip industry alongside other clusters such as UNK_FistBump and UNK_DropPitch. The broader targeting pattern has included semiconductor manufacturers, designers, testing and packaging firms, suppliers, and sector-focused analysts, and has been linked to intelligence collection priorities aligned with China’s strategic interest in semiconductor self-sufficiency and supply-chain insight. Based on the observed victimology and tradecraft, UNK_SparkyCarp is best understood as an espionage-oriented credential-harvesting cluster focused on access to semiconductor-sector accounts and information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UNK_SparkyCarp is a Chinese APT that has repeatedly targeted Taiwan's semiconductor industry using phishing emails disguised as Microsoft account security notices.
UNK_SparkyCarp is a suspected Chinese espionage group targeting Taiwan's semiconductor industry.
UNK_SparkyCarp is a China-aligned espionage group targeting Taiwan's semiconductor industry with phishing and social engineering campaigns.
Credential phishing attacks against Taiwanese semiconductor companies using adversary-in-the-middle kits.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.