UNG0002 deploys ClickFix and custom RATs (Shadow RAT, Inet RAT) across the Cobalt Whisper and AmberMist campaigns. Matanbuchus 3.0 abuses Microsoft Teams for initial access. Chinese APTs, including APT41-linked TA415, target Taiwan semiconductor firms.