UNC3524

MISP
Type:
Nation-state
Country:
Unknown
First seen:
Unknown
Details:

Mandiant observed this group operating since December 2019. Its techniques partially overlap with multiple Russian-based espionage actors (APT28 and APT29). They are described as having a high level of operational security, low malware footprint, adept evasive skills, and a large Internet of Things (IoT) device botnet at their disposal.

Metadata
ID: 358
Created: 13/01/2026 17:48
Updated: 09/03/2026 16:00