UNC3782 is a suspected North Korean threat actor active since at least 2022 that conducts both financially motivated cryptocurrency crime and espionage activity. The cluster has been associated with large-scale phishing infrastructure, initially centered on impersonation of Naver and later expanding into cryptocurrency- and NFT-themed lures. Activity attributed to UNC3782 includes extensive typosquatting and phishing against South Korean targets, as well as wallet-phishing operations aimed at cryptocurrency users across multiple blockchain ecosystems. UNC3782 has targeted South Korean organizations, including entities involved in combating cryptocurrency-related crime such as law firms, government-related organizations, and media organizations. It has also targeted users of major cryptocurrency platforms and ecosystems including Ethereum, Bitcoin, Arbitrum, Binance Smart Chain, Cronos, Polygon, TRON, and Solana. Reported operations indicate a shift from brand impersonation and credential-focused phishing toward crypto theft workflows designed to induce victims to connect wallets and disclose seed phrases, enabling theft of cryptocurrency and NFTs. Observed tradecraft includes phishing, spoofing through typosquat infrastructure, reconnaissance and infrastructure development at scale, credential theft, crypto theft, and exfiltration of sensitive wallet secrets. UNC3782 has operated hundreds of phishing domains and a large supporting infrastructure footprint over multiple years. Its campaigns have used themed websites impersonating legitimate services or reward opportunities in order to socially engineer victims into surrendering access to accounts or wallets. UNC3782 is assessed as DPRK-linked at a suspected level. Reporting notes overlap with APT43, also known as Kimsuky, but available information does not support treating UNC3782 and APT43 as definitively the same cluster. UNC3782 is best characterized as a North Korea-linked phishing and cryptocurrency theft actor that also supports espionage objectives, particularly against South Korean organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.