Cyber Security News

UNG0002 Actors Deploys Weaponize LNK Files Using ClickFix Fake CAPTCHA Verification Pages

A sophisticated espionage campaign targeting multiple Asian jurisdictions has emerged, utilizing weaponized shortcut files and deceptive social engineering techniques to infiltrate high-value targets across China, Hong Kong, and Pakistan.

The threat actor, designated UNG0002 (Unknown Group 0002), has demonstrated remarkable persistence and technical evolution throughout two major operational phases spanning from May 2024 to the present.

The malicious campaign employs a multi-stage infection chain beginning with weaponized LNK files embedded within CV-themed decoy documents, progressing through VBScript execution, batch processing, and culminating in PowerShell-based payload deployment.

This sophisticated approach allows the threat actors to bypass traditional security measures while maintaining a low detection profile throughout the infection process.

Seqrite analysts identified that UNG0002 has significantly evolved their tactics during Operation AmberMist, their most recent campaign running from January 2025 to May 2025.

The threat group has expanded their targeting beyond traditional defense and civil aviation sectors to include gaming companies, software development firms, and academic institutions, indicating a broader intelligence collection mandate.

Attack chain (Source – Seqrite)

The campaign’s most notable innovation involves the abuse of the ClickFix technique, a social engineering method that presents victims with fake CAPTCHA verification pages designed to trick them into executing malicious PowerShell scripts.

Security researchers have observed instances where the threat actors specifically spoofed Pakistan’s Ministry of Maritime Affairs website to enhance the legitimacy of their deceptive pages.

Advanced Infection Mechanism and Persistence Tactics

The infection mechanism demonstrates remarkable sophistication through its multi-layered approach to system compromise.

The attack begins when victims receive CV-themed ZIP archives containing malicious LNK files disguised as legitimate PDF documents. Upon execution, these shortcut files initiate a complex chain involving VBScript interpretation, batch script processing, and PowerShell execution.

Persistent Infrastructure (Source – Seqrite)

Technical analysis reveals that UNG0002 employs DLL sideloading techniques, particularly targeting legitimate Windows applications such as Rasphone.exe and Node-Webkit binaries.

The malware leverages these trusted processes to execute malicious payloads while evading detection mechanisms.

Program Database (PDB) paths discovered during analysis indicate internal code names “Mustang” and “ShockWave,” suggesting organized development practices with C:\Users\The Freelancer\source\repos\JAN25\mustang\x64\Release\mustang.pdb and C:\Users\Shockwave\source\repos\memcom\x64\Release\memcom.pdb paths embedded within Shadow RAT and INET RAT respectively.

The persistent infrastructure maintains consistent command and control operations, deploying custom implants including Shadow RAT, INET RAT, and Blister DLL loaders.

These tools provide comprehensive system access, enabling data exfiltration, remote command execution, and lateral movement capabilities across compromised networks, establishing UNG0002 as a formidable threat to regional cybersecurity.

Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -> Try ANY.RUN Now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

9 minutes ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

13 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

19 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

25 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

35 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago