UNC2529 is a financially motivated cyber threat actor associated with the "Triple DOUBLE" malware ecosystem, comprising the DOUBLEDRAG downloader, DOUBLEDROP dropper, and DOUBLEBACK backdoor. The actor has been assessed as capable, professional, and well resourced, with operations showing broad cross-industry and global targeting. UNC2529 has used phishing as its primary initial access vector, including messages that deliver an obfuscated JavaScript downloader or malicious Excel macro content. The infection chain relies heavily on PowerShell for in-memory execution and staging. DOUBLEDROP installs DOUBLEBACK in a largely fileless manner by storing encrypted payloads and loader components in the Windows registry, reducing reliance on disk artifacts and complicating detection. Persistence has been achieved through registry-based storage combined with COM hijacking and, when privileges permit, scheduled-task-based COM handler execution. DOUBLEBACK is a plugin-based backdoor whose modules are also stored in the registry. The malware can inject into other processes, including migration from PowerShell into msiexec.exe, and includes logic to adapt behavior based on the presence of certain security products. Command-and-control communications use encoded configuration data and web-based protocols. Observed tradecraft includes phishing, malicious scripting, registry modification, fileless persistence, process injection, and defense evasion. Available reporting did not establish direct evidence of UNC2529’s ultimate objectives, but the breadth of targeting and operational pattern are consistent with financially motivated intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.