UNC6032 is a Vietnam-linked cybercriminal threat actor active since at least mid-2024 that conducts financially motivated malware distribution campaigns centered on impersonation of popular AI tools and AI video-generation services. The group is known for large-scale social-media malvertising, particularly on Facebook and LinkedIn, where it has promoted fake versions of services such as Luma AI, Canva Dream Lab, and Kling AI to drive victims to fraudulent download sites. UNC6032 primarily targets users seeking AI-related software and services, with observed victimology including marketing agencies, media organizations, and small businesses. Its operations are designed to obtain initial access through deceptive advertisements and spoofed websites, then deliver infostealers and remote-access malware. Reported tooling associated with the actor includes the Rust-based STARKVEIL dropper and payloads such as GRIMPULL, XWORM, and FROSTRIFT. The actor has been tied to campaigns distributing infostealers via fake AI video-generator websites and broader AI-brand impersonation activity. Operationally, UNC6032 relies on spoofing, social-engineering-driven initial access, malware staging, and post-compromise data theft. Its campaigns demonstrate defense-evasion tradecraft through the use of convincing brand impersonation and ad-platform abuse to blend malicious delivery into normal user acquisition channels. UNC6032 is not described as a state-sponsored espionage actor; available reporting instead aligns it with Vietnamese cybercrime focused on credential and information theft for profit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operated fake AI-themed websites promoted via Facebook and LinkedIn ads to impersonate AI video tools and deliver malware at scale.
UNC6032 is a threat actor group with a Vietnam nexus, active since mid-2024, distributing infostealers via fake AI video generator websites promoted on social media.
UNC6032 is a Vietnamese cybercriminal group distributing Rust-based malware via fake AI video generator ads on social media, targeting marketing agencies, media outlets, and small businesses to steal credentials and crypto assets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.