Operation Cobalt Whisper — APT Profile
Operation Cobalt Whisper is a cyber espionage campaign attributed to UNG0002, a threat cluster assessed with high confidence to originate from Southeast Asia. Active May–September 2024, it targeted defense, electrotechnical engineering, energy, and civil aviation organizations in China, Hong Kong, and Pakistan via spear-phishing using Cobalt Strike and malicious LNK files.Also tracked as
UNG0002, Unknown Group 0002
Tools & malware
- Blister Loader
- Cobalt Strike Post-exploitation framework
- INET RAT Remote access trojan
- Metasploit Post-exploitation framework
- Shadow RAT Remote access trojan
Vendor research
- Recent malicious activities attributed to the UNG0002 threat group (Protection Bulletin, 23 Jul 2025) Symantec (Broadcom)
- Operation Cobalt Whisper: Threat Actor Targets Multiple Industries Across Hong Kong and Pakistan Seqrite Labs
- UNG0002: Regional Threat Operations Tracked Across Multiple Asian Jurisdictions Seqrite Labs