Operation Cobalt Whisper — APT Profile

Operation Cobalt Whisper is a cyber espionage campaign attributed to UNG0002, a threat cluster assessed with high confidence to originate from Southeast Asia. Active May–September 2024, it targeted defense, electrotechnical engineering, energy, and civil aviation organizations in China, Hong Kong, and Pakistan via spear-phishing using Cobalt Strike and malicious LNK files.

Also tracked as

UNG0002, Unknown Group 0002

Tools & malware

Vendor research

Read the full analysis on IntelFusions