logo

UAT-8302 Uses Custom Malware and Open-Source Tools to Steal Data From Government Agencies

ID: 148d5317-9fe9-5262-8798-53610c3cef21

STIX ID: report--148d5317-9fe9-5262-8798-53610c3cef21

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Tushar Subhra Dutta

...
...

This report details UAT-8302, a China-linked APT that has targeted government agencies since late 2024 using a mix of custom malware (NetDraft, CloudSorcerer, VSHELL, SNAPPYBEE, ZingDoor), open-source reconnaissance tools, and cloud-based C2 channels (OneDrive, GitHub, Cloudflare Workers) to maintain stealthy, long-term access and exfiltrate sensitive data; the document provides observed tactics, techniques, procedures and a comprehensive set of IoCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.