UAT-8302 Uses Custom Malware and Open-Source Tools to Steal Data From Government Agencies
ID: 148d5317-9fe9-5262-8798-53610c3cef21
STIX ID: report--148d5317-9fe9-5262-8798-53610c3cef21
Feed Name: cybersecurityNews.com
This report details UAT-8302, a China-linked APT that has targeted government agencies since late 2024 using a mix of custom malware (NetDraft, CloudSorcerer, VSHELL, SNAPPYBEE, ZingDoor), open-source reconnaissance tools, and cloud-based C2 channels (OneDrive, GitHub, Cloudflare Workers) to maintain stealthy, long-term access and exfiltrate sensitive data; the document provides observed tactics, techniques, procedures and a comprehensive set of IoCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
