logo

UAT-8302 Deploys Custom Malware Against Government Networks

ID: 63df47d0-4fb1-51ca-8b66-1a7e9c17e691

STIX ID: report--63df47d0-4fb1-51ca-8b66-1a7e9c17e691

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-08

Date Updated: 2026-05-22

Author: Varshini

...
...

UAT-8302, a China-linked APT active since late 2024, has been targeting government infrastructures in South America and southeastern Europe; researchers report the group uses custom backdoors (NetDraft, CloudSorcerer, FringePorch), PowerShell and Python reconnaissance tools (whatpc, Impacket), open-source scanners, credential theft from Active Directory/Microsoft Entra ID, DLL sideloading, and hidden proxy tunnels to maintain long-term clandestine access and exfiltrate intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.