UCID902 is a threat cluster tracked since at least 2021 for sustained credential-phishing operations primarily targeting South Korean civil society organizations and individuals working on North Korean human rights, refugee support, journalism, and Korean unification issues. The cluster has been assessed as a likely nation-state-sponsored actor with targeting priorities and operational patterns that align closely with North Korean intelligence interests, although definitive attribution to a specific named North Korean group is not established. UCID902 is characterized by repeated use of spear-phishing campaigns themed as security notifications and account alerts, especially impersonating Naver-related security events and, in some cases, South Korean government themes such as the Ministry of Unification. Its operations focus on harvesting credentials rather than deploying destructive payloads. A notable tradecraft pattern is the compromise of legitimate South Korean organizational websites to host phishing pages, including sites belonging to law firms, educational organizations, and medical research institutions. Multiple campaigns have shown infrastructure and hosting correlations through shared web developers, hosting providers, and server environments. Observed phishing kits are relatively consistent across campaigns from 2021 through 2023. They reportedly include victim-validation logic that checks aspects of the incoming request and redirects non-targets to legitimate login pages, indicating selective targeting and defense evasion. Harvested credentials are transmitted back to the compromised hosting server. Campaign clustering has been supported by recurring lure themes, shared infrastructure patterns, common phishing-kit logic, and repeated encoding and request-handling behaviors. UCID902 has been repeatedly associated with credential-phishing against civil society organizations in South Korea. Reporting also notes overlap with ESTSecurity’s Kumsong 121 cluster and similarities in tactics, techniques, motivations, and modus operandi with Kimsuky, including correlations involving an early 2022 campaign using a malicious HWP document. However, the cluster is best treated as a distinct tracked activity set with North Korea-linked characteristics rather than conclusively synonymous with Kimsuky.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Persistent credential-harvesting and phishing campaigns targeting civil society organizations, activists, and human-rights groups in South Korea focused on North Korea-related issues.
Credential phishing and watering-hole campaigns targeting human rights groups, activists, North Korean refugee support NGOs, and Korea unification/human-rights communities, primarily via fake Naver login pages hosted on compromised legitimate South Korean websites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.