UAT-5918 targets critical infrastructure entities in Taiwan
ID: b76e81ff-dc76-5096-b043-1e540353a687
STIX ID: report--b76e81ff-dc76-5096-b043-1e540353a687
Feed Name: Cisco Talos
**Cisco Talos** details UAT-5918, an APT campaign active since at least 2023 targeting Taiwanese telecommunications, healthcare, IT and critical infrastructure: actors exploit N-day/unpatched internet-facing servers to deploy web shells and open-source tools (FRPC/FRP, Neo-reGeorg, In-Swor, FScan, Impacket, Mimikatz, LaZagne, BrowserDataLite, JuicyPotato, Meterpreter, etc.) to harvest credentials, create backdoor accounts, move laterally, stage and exfiltrate data; the report maps substantial TTP/tooling overlap with Volt Typhoon, Flax Typhoon, Earth Estries, Dalbit and provides detection guidance and a GitHub-hosted IOC set.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
