logo

UAT-5918 targets critical infrastructure entities in Taiwan

ID: b76e81ff-dc76-5096-b043-1e540353a687

STIX ID: report--b76e81ff-dc76-5096-b043-1e540353a687

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2025-03-20

Date Updated: 2026-04-27

Author: Jungsoo An

...
...

**Cisco Talos** details UAT-5918, an APT campaign active since at least 2023 targeting Taiwanese telecommunications, healthcare, IT and critical infrastructure: actors exploit N-day/unpatched internet-facing servers to deploy web shells and open-source tools (FRPC/FRP, Neo-reGeorg, In-Swor, FScan, Impacket, Mimikatz, LaZagne, BrowserDataLite, JuicyPotato, Meterpreter, etc.) to harvest credentials, create backdoor accounts, move laterally, stage and exfiltrate data; the report maps substantial TTP/tooling overlap with Volt Typhoon, Flax Typhoon, Earth Estries, Dalbit and provides detection guidance and a GitHub-hosted IOC set.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.