iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The North Korean-linked operation that most closely matches this headline is UNC2970, which Mandiant said it suspected had specifically targeted security researchers. Mandiant detected the activity in June 2022 and later observed intrusions involving U.S. and European media organizations. The recruiter-and-job-lure pattern has appeared in separate reports since then, but those reports do not establish that UNC2970 itself is still active.
How did the UNC2970 approach work?
Mandiant described a sequence built around plausible professional contact rather than an obviously malicious first message. The suspected group used carefully curated fake LinkedIn recruiter accounts modeled on legitimate people, built rapport with targets, and attempted to move conversations to WhatsApp. It then sent a phishing payload by email or WhatsApp, often disguised as a job description tailored to the recipient. Mandiant’s UNC2970 report says that in at least one reported case, the actor kept communicating after the victim’s security software detected the payload and asked for screenshots.
The observed Word lure documents used macros and remote-template injection to retrieve and execute a payload. Mandiant connected the resulting activity to the PLANKWALK backdoor and described other tooling, including Microsoft Intune being used to deploy a shellcode downloader. The practical lesson is that a tailored job description or interview attachment is still an untrusted file; professional context does not make it safe to open or run.
Mandiant assessed UNC2970 with high confidence as suspected to be UNC577, also known as Temp.Hermit. It also noted malware and resource overlaps with other North Korean operators. These labels are vendor tracking clusters, and shared tools or techniques alone do not prove that two clusters are the same group.
#1 Best Overall
Are the later recruiter and developer campaigns the same operation?
No. The reports describe related social-engineering patterns, but track distinct campaigns or actor clusters. Keeping their names, targets, and attribution language separate avoids turning a recurring tactic into a claim of one continuous operation.
| Reporting context | Target and lure | Reported delivery or tooling | Attribution and scope |
|---|---|---|---|
| UNC2970, Mandiant | Security researchers; recruiter identity, LinkedIn-to-WhatsApp contact, tailored job lure | Word macros and remote-template injection; PLANKWALK and other tooling, including Intune deployment of a shellcode downloader | Mandiant suspected a North Korean espionage group; assessed UNC2970 with high confidence as suspected to be UNC577/Temp.Hermit. Activity detected in June 2022, with later intrusions against U.S. and European media organizations. |
| Contagious Interview, Unit 42 | Software developers; fictitious job interviews and malicious developer workflows | BeaverTail malware hidden in npm packages and the Python-based InvisibleFerret backdoor | Unit 42 tracked it as CL-STA-0240 and assessed North Korean state-sponsored attribution with moderate confidence. It separately tracks fraudulent job-seeking activity as Wagemole. |
| KONNI, Check Point Research | Software developers and engineering teams, especially those with access to blockchain resources; project-document lures | PowerShell backdoor that Check Point said showed signs of AI generation | Check Point’s January 2026 report described samples submitted from Japan, Australia, and India. It is a separate reporting context, not proof UNC2970 is active. |
| UNC1069, Mandiant | Cryptocurrency-sector personnel; compromised Telegram account, fake Zoom meeting, and ClickFix instructions | User-run troubleshooting commands; investigation found seven malware families and credential, browser-data, and session-token harvesting | A separate 2026 intrusion. The victim reported a CEO video that appeared to be a deepfake, but Mandiant said it could not independently verify AI-model use in the incident. |
| Moonstone Sleet, Microsoft | Developer-targeting context involving fake companies, job opportunities, and trojanized tools | Not stated in Microsoft’s cited report summary | A distinct North Korean-linked actor cluster; not evidence it conducted the UNC2970 campaign. |
Sources: Mandiant on UNC2970, Unit 42 on Contagious Interview and Wagemole, Check Point Research on KONNI, Mandiant on UNC1069, and Microsoft on Moonstone Sleet.
How can you assess a recruiter or interview offer?
Use checks that do not depend on information supplied in the suspicious message. Unit 42 recommends confirming that a prospective employer is real, treating GitHub accounts with few repositories or updates cautiously, avoiding personal activity on company-issued computers, and thoroughly vetting applicants. Applied to the UNC2970 sequence, researchers and job seekers can:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute- Look up the company and recruiter independently, then verify the opportunity through contact details found through an established official channel.
- Do not treat a move from LinkedIn to WhatsApp or another private channel as proof of identity. A persuasive profile and tailored job description can be part of the lure.
- Do not enable macros or run files, packages, scripts, or code supplied for a job description or interview task merely to view or complete it.
- For developer tests, check the account and repository history, inspect the proposed workflow, and use an isolated environment approved by your organization rather than a personal or company device containing sensitive data.
- Employers should independently verify applicant identities and carefully review work artifacts before running them.
These are cautious precautions drawn from the reported tactics, not a replacement for an organization’s incident-response or account-security procedures.
Rank #3
Does “again” mean the 2022 UNC2970 operation is active now?
The later reports show that developer-focused social engineering and job or project lures continued to appear in North Korean-linked reporting, including KONNI in 2026. They do not establish that the specific UNC2970 operation described by Mandiant remains active. Likewise, UNC1069’s cryptocurrency-sector intrusion and Moonstone Sleet’s developer-targeting activity are separate contexts, not extensions proven to belong to UNC2970.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

