UNG0902 is a threat cluster associated with Operation DupeHike, a spearphishing campaign targeting Russian corporate employees, particularly human resources, payroll, and internal administrative personnel. The activity has been observed since at least November 2025 and uses socially engineered lures themed around employee bonuses and internal financial policies to induce execution of malicious shortcut files embedded in archive attachments. The cluster’s intrusion chain relies on phishing for initial access, followed by PowerShell-based payload retrieval and deployment of a C++ implant known as DUPERUNNER. DUPERUNNER downloads and displays decoy documents, retrieves additional payloads, and injects shellcode into legitimate Windows processes using remote-thread injection. The injected payload is AdaptixC2, an open-source command-and-control framework used as a beacon or stager. Reported tradecraft includes process injection, dynamic API resolution, in-memory payload location and loading, and HTTP-based command-and-control communications. UNG0902 has been linked to campaigns against Russian corporate entities and overlaps in targeting with broader activity directed at organizations connected to Russia’s wartime industrial and administrative ecosystem. Possible nation-state sponsorship has been considered, but no high-confidence country attribution is established. No confirmed sub-groups or widely used aliases beyond UNG0902 are established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 malware families attributed to this actor across reporting.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster reported targeting Russian employees using the DUPERUNNER malware and AdaptixC2 infrastructure/tooling.
UNG0902 is responsible for spear-phishing campaigns targeting Russian organizations, especially human resources and payroll departments, using lures related to bonuses or internal financial policies to deploy the DUPERUNNER implant and AdaptixC2 framework.
Clustered activity targeting Russian corporate entities (notably HR, payroll, and internal administrative departments) using spear-phishing ZIPs containing PDF-themed LNK lures that execute PowerShell to download a custom implant (DUPERUNNER), which then injects/loads an AdaptixC2 beacon for HTTP-based C2.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.