ProBackend
ai cybersecurity threats nation state actors
5 hours ago6 min read

AI Cybersecurity Threats 2026: Inside UNC2970's Kernel-Level LinkedIn Malware Arsenal

North Korean-linked UNC2970 deployed custom malware families and a zero-day BYOVD driver against security researchers recruited through fake LinkedIn job offers. Mandiant's technical teardown reveals the full attack chain from social engineering to EDR-kernel patching.

The Campaign That Crossed a Line

A suspected North Korean threat actor has been running one of the most technically layered social-engineering operations targeting the security research community directly. UNC2970 — tracked by Mandiant — spent months building fake recruiter personas on LinkedIn, grooming security researchers and media professionals across the U.S. and Europe, then delivering a chain of custom malware that escalated all the way to kernel-level EDR disabling via a BYOVD (Bring Your Own Vulnerable Driver) technique.

What separates this from your average spearphishing campaign isn't the lure. Fake job offers are tired tradecraft. What's notable is the engineering effort: multiple distinct malware components, each with a narrow role, chained together through a carefully sequenced infection pipeline that culminates in tampering with endpoint detection drivers at ring zero. This isn't a script kiddie grabbing a commodity RAT. This is a development team with compiler toolchains, custom packers, and enough kernel knowledge to identify and exploit a vulnerable ASUS driver for EDR neutralization.

How the LinkedIn Lure Works

The approach is straightforward in concept but sophisticated in execution. UNC2970 operators created recruiter profiles on LinkedIn, then reached out to security researchers and journalists with what appeared to be legitimate job opportunities. The conversation would build rapport over days or weeks before a "technical assessment" was introduced — a document or software package the target was asked to run.

These weren't mass-spam messages. The outreach was targeted, personalized, and patient. The attacker needed the target to trust the persona enough to download and execute something on a production research machine. That's not trivial when your audience makes a living spotting suspicious code. The same trust-exploitation principle shows up elsewhere in the ecosystem: large-scale fake GitHub repos distributing infostealers weaponize the assumption that a familiar-looking deliverable is a safe one — UNC2970 simply personalized that assumption for an audience of experts.

The initial delivery mechanism used a dropper — Mandiant called it "Bercthook", that unpacked additional stages only after confirming the environment wasn't sandboxed. Classic anti-analysis tradecraft, but applied here specifically against an audience that builds sandboxes for a living.

The Malware Families in Detail

The campaign deployed at least three novel malware families beyond the initial dropper, each serving a distinct role in the kill chain.

Bercthook served as the first-stage loader. It performed environment checks, looking for debugging artifacts, virtual machine signatures, and automated analysis frameworks, before unpacking the next component. This wasn't a simple XOR-encoded dropper; it used polymorphic packing that changed its binary signature between samples.

The second stage was a backdoor that established command-and-control over HTTPS, blending its traffic with legitimate-looking connections. C2 domains were registered with WHOIS privacy and cycled frequently, a pattern consistent with other DPRK-linked clusters Mandiant has tracked over years.

The third family is the one that got the most attention from the DFIR community: a kernel-mode component that loaded a vulnerable ASUS driver (eubcakts.sys or similar) to disable EDR callbacks. This is a BYOVD technique, the attacker isn't exploiting a vulnerability in Windows itself, they're loading a legitimately signed but functionally dangerous driver and then abusing its capabilities to zero out kernel callbacks that endpoint agents rely on for process monitoring.

Why Kernel-Level EDR Disabling Matters

Let me be blunt about what this means for defenders. If an attacker can patch your EDR kernel driver's callback list from ring zero, your endpoint agent becomes a blind observer. It still loads. It still hooks. But it sees nothing. The process is running; the telemetry just stops flowing.

This isn't theoretical. EDR bypass via BYOVD drivers has been trending across the threat landscape for the past two years, our breakdown of how security software gets subverted into high-privilege weapons covers the mechanics of this class of abuse in depth, but seeing it deployed in a targeted campaign against the very people who build detection logic is a significant escalation. These are researchers at firms that publish the detection rules. They're journalists who write the coverage. UNC2970 apparently wanted to understand exactly what the defense community could and couldn't see.

The AI and agentic security angle here is more than academic. As AI-powered threat detection tools and agent-based security practices become more common in SOC environments, the techniques used to blind traditional EDR will inevitably adapt toward those new attack surfaces. Defending against these AI cybersecurity threats in 2026 means understanding both the kernel-level bypasses that exist today and the new vectors that autonomous agent architectures will introduce.

Attribution and Strategic Context

Mandiant attributes this campaign to UNC2970, which they assess with moderate confidence is a North Korean state-sponsored cluster. The targeting pattern, security researchers at competing threat intel firms and journalists covering North Korean cyber operations, is consistent with intelligence-collection objectives rather than financial ones.

This fits a broader pattern. North Korean actors have been aggressively targeting the tech industry for years. CrowdStrike reported that North Koreans are behind nearly half of U.S. tech industry hacks, often using the "fake IT worker" scheme to infiltrate companies for ransom rather than espionage. UNC2970 appears to be a different sub-cluster with different priorities: intelligence about the offensive and defensive capabilities of the security community itself.

The financial motivation isn't absent from the broader DPRK ecosystem, the same state that funds these operations is under severe sanctions pressure and the cyber program is a revenue source. But this specific campaign's targeting of researchers and journalists points to reconnaissance: understanding who's watching, what they know, and how to avoid detection.

Practical Defenses and What This Means for Teams

The attack chain exploited a known-vulnerable driver that Microsoft has had to block via HVCI (Hypervisor-Protected Code Integrity) and the vulnerable driver blocklist. If your fleet hasn't deployed HVCI or hasn't enabled Windows Defender Application Control with the Microsoft-recommended blocklist, you're leaving a well-documented door open.

For security teams specifically targeted by this kind of social engineering, the lesson isn't just "don't run files from strangers." These targets knew better than that. The lesson is that patience beats suspicion, a persona maintained over weeks with organic-looking profile activity, genuine engagement with posts, and a plausible hiring narrative can defeat even well-trained eyes.

The broader industry takeaway touches on cybersecurity best practices that CISA and other agencies have pushed for years: least privilege at the kernel level, application allowlisting, and monitoring for unsigned or known-vulnerable driver loads. The challenge is that these practices conflict with the operational needs of malware researchers who routinely run suspicious binaries.

As the landscape shifts toward AI-assisted detection and agentic security workflows that promise to augment human analysts, campaigns like UNC2970 remind us that adversaries don't wait for the new tool to mature before they figure out how to turn it off. Securing these new systems means auditing their kernel-level assumptions first, not after deployment. The AI agent security conversation needs to include the reality that any system requiring deep OS integration for visibility inherits every bypass technique already proven against that integration point.

Closing Thoughts

UNC2970 isn't a story about North Korean hackers being clever. It's a story about what happens when a nation-state actor decides that the security research community itself is the target, and invests in purpose-built tooling with enough engineering depth to reach kernel-level persistence. The fake job offer is just the handshake. What comes after is the real payload.

Watch for this pattern to repeat. The playbook is proven: patient social engineering on a platform where targets expect professional contact, multi-stage delivery that evades sandboxing, and a kernel-level component that blunts your detection before your analyst ever gets an alert. If you haven't hardened driver loading policies yet, this is the campaign that makes that argument concrete.

the campaign that crossed a line

More blogs