O-UNC-036 is an infrastructure cluster associated with a Vietnam-rooted cybercrime ecosystem focused on large-scale fraudulent account registration and the industrialized creation of fake digital identities. The cluster uses disposable email services and automated bots to mass-produce synthetic accounts for abuse across online platforms and service providers worldwide. Activity linked to O-UNC-036 has been tied to a broader cybercrime-as-a-service marketplace that supports the sale of hijacked accounts, synthetically created accounts, session tokens, residential proxy access, anti-detect tooling, and related fraud-enablement services. The ecosystem enables downstream criminal activity including spam, phishing, review manipulation, free-trial abuse, and interpersonal fraud such as pig-butchering schemes. It has also been associated with SMS pumping, also known as International Revenue Sharing Fraud, in which large volumes of fraudulent registrations trigger premium-rate SMS messages and impose direct costs on providers that rely on SMS for verification or multifactor authentication. O-UNC-036 has been linked to dozens of storefronts built on common infrastructure and templates associated with a Vietnam-based web design operation. These storefronts advertise compromised social media accounts, session artifacts that permit account access without passwords, phone-farm services, and social-media engagement inflation. Available reporting indicates that some compromised accounts sold through this ecosystem are sourced from brute-force activity and infostealer-derived logs. The actor’s observed tradecraft includes automated account creation, abuse of disposable email infrastructure, use of bots to scale registrations, acquisition and resale of hijacked accounts, sale of session tokens, and support for fraud operations that rely on anonymity and evasion tooling. O-UNC-036 is best characterized as a financially motivated cybercrime facilitator and operator within a broader Southeast Asian fraud ecosystem rather than a state-sponsored intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.