UAT-8302 Deploys Custom Malware Against Government Networks
ID: 63df47d0-4fb1-51ca-8b66-1a7e9c17e691
STIX ID: report--63df47d0-4fb1-51ca-8b66-1a7e9c17e691
Feed Name: Cyber Press
Threat Score
UAT-8302, a China-linked APT active since late 2024, has been targeting government infrastructures in South America and southeastern Europe; researchers report the group uses custom backdoors (NetDraft, CloudSorcerer, FringePorch), PowerShell and Python reconnaissance tools (whatpc, Impacket), open-source scanners, credential theft from Active Directory/Microsoft Entra ID, DLL sideloading, and hidden proxy tunnels to maintain long-term clandestine access and exfiltrate intelligence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
