UNC6229
UNC6229 is a Vietnam-linked, financially motivated cybercriminal threat cluster. Google tracks the group as UNC6229. Reporting describes the group running fake job and "Fake Career" campaigns, including fake job postings and job-themed lures disguised as employment application forms or skill assessment tests, to target job seekers, students, digital marketers, and advertising/marketing professionals, including on LinkedIn. The group has been reported targeting and hacking advertising accounts and capturing corporate credentials. UNC6229 has been linked to campaigns involving the Noodlophile stealer and PXA Stealer. Observed tradecraft includes phishing links and malicious ZIP attachments, delivery of multi-stage stealers and remote access trojans, DLL sideloading, and use of Telegram bots for command-and-control or data exfiltration in Noodlophile-related activity. Recent reporting also notes evolved malware protections in associated Noodlophile variants, including djb2-based dynamic API resolution, XOR-encoded strings, RC4 protection of a command file, and anti-tampering checks.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- advertising
- marketing
Tradecraft
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential theft/espionage-style activity using social engineering (fake job postings) to deliver multi-stage information stealers and RATs, leveraging DLL sideloading and adding anti-analysis/obfuscation (djb2 hashing, XOR encoding).
Vietnam-linked cybercriminal activity cluster referenced in connection with info-stealer campaigns (mentioned alongside Noodlophile/PXA Stealer).
Linked to campaigns delivering the Noodlophile information stealer via fake job postings and phishing lures (employment application forms/skill tests), using multi-stage stealers and RATs delivered through DLL sideloading; uses Telegram bots for exfiltration/C2 and employs anti-analysis/obfuscation (file bloat to crash Python disassembly tooling, dynamic API resolution via djb2 hashing, signature self-check, RC4/XOR).
A campaign attributed to UNC6229 using fake job/career lures to compromise and hack advertising accounts.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.