UAT-8837 targets critical infrastructure sectors in North America
ID: 8f46245e-864d-5adf-bd30-0f074a99dfb4
STIX ID: report--8f46245e-864d-5adf-bd30-0f074a99dfb4
Feed Name: Cisco Talos
Cisco Talos assesses with medium confidence that UAT-8837 is a China-nexus APT actor conducting hands-on-keyboard intrusions against critical infrastructure in North America since at least 2025; they exploit both n-day and zero‑day vulnerabilities (notably CVE-2025-53690) to gain initial access, then deploy open-source tooling (Earthworm, SharpHound, Certipy, GoTokenTheft, GoExec, Rubeus, DWAgent, etc.) for AD reconnaissance, credential/token theft, tunneling, lateral movement, and persistence. The report includes detailed observed commands, staging locations, post-compromise behaviors, and a set of IOCs (file hashes and IP addresses) to detect and block the actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
