logo

UAT-8837 targets critical infrastructure sectors in North America

ID: 8f46245e-864d-5adf-bd30-0f074a99dfb4

STIX ID: report--8f46245e-864d-5adf-bd30-0f074a99dfb4

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2026-01-15

Date Updated: 2026-04-27

Author: Asheer Malhotra

...
...

Cisco Talos assesses with medium confidence that UAT-8837 is a China-nexus APT actor conducting hands-on-keyboard intrusions against critical infrastructure in North America since at least 2025; they exploit both n-day and zero‑day vulnerabilities (notably CVE-2025-53690) to gain initial access, then deploy open-source tooling (Earthworm, SharpHound, Certipy, GoTokenTheft, GoExec, Rubeus, DWAgent, etc.) for AD reconnaissance, credential/token theft, tunneling, lateral movement, and persistence. The report includes detailed observed commands, staging locations, post-compromise behaviors, and a set of IOCs (file hashes and IP addresses) to detect and block the actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.