UNK_DropPitch, also tracked as UTA0388, is a China-aligned espionage threat cluster active in 2025 and focused heavily on Taiwan-related intelligence collection. The actor has targeted financial investment professionals, major investment banks, and analysts covering Taiwan’s semiconductor and technology sectors, and has also been linked to broader phishing activity affecting organizations and individuals in North America, Asia, and Europe. Targeting patterns are consistent with Chinese strategic interest in semiconductor supply chains, market intelligence, and geopolitical issues involving Taiwan. UNK_DropPitch is known for highly targeted spear-phishing and social-engineering operations. The group has impersonated fictitious investment firms, fabricated researchers and analysts, and used multilingual lures in English, Chinese, Japanese, French, and German. Campaigns have included both direct delivery phishing and rapport-building approaches in which trust is established over time before malicious content is sent. The actor has also been reported to use AI assistance to generate phishing content and support malicious workflows. A defining tradecraft element is delivery of malware through archives containing vulnerable legitimate executables and malicious DLLs, leading to DLL sideloading. Malware associated with the cluster includes HealthKick and the later Go-based GOVERSHELL family, which has been described as an actively developed successor to HealthKick. Reported variants include HealthKick, TE32, TE64, WebSocket, and Beacon. These implants support command execution, often through PowerShell, and some campaigns have also delivered a simple raw TCP reverse shell. Follow-on activity has included use of remote management tooling after initial victim triage. Observed capabilities include initial access via spear-phishing, persistence, command execution, post-compromise reconnaissance, and data theft. The actor has abused legitimate cloud and email services to stage payloads and send phishing messages. Multiple reporting streams assess overlap between UNK_DropPitch and UTA0388 at the infrastructure, malware, and targeting levels. The cluster is assessed as China-aligned and espionage-motivated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Actor observed by Proofpoint targeting Taiwan semiconductor entities with phishing emails delivering the HealthKick backdoor, apparently in parallel with GLITTER CARP activity.
UNK_DropPitch is a Chinese threat actor group known for leveraging AI tools to generate phishing content, automate routine attack tasks, and facilitate remote execution and traffic protection.
UNK_DROPPITCH is a Chinese state-sponsored threat actor using AI services to craft spear-phishing emails targeting high-value sectors and organizations.
An activity cluster (per Proofpoint) overlapping with the UTA0388 campaign activity delivering GOVERSHELL/HealthKick via phishing and DLL side-loading.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.