logo

UAT-8302 and its box full of malware

ID: e4d00106-cc6d-5e94-87b2-a3ffe019d4bb

STIX ID: report--e4d00106-cc6d-5e94-87b2-a3ffe019d4bb

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Jungsoo An

...
...

UAT-8302 is a China-nexus APT targeting government and related entities since at least late 2024; the Talos report details how the group gains access (exploits and red-team tooling), performs reconnaissance and lateral movement, and deploys multiple custom and reused malware families (NetDraft/FringePorch, CloudSorcerer v3, VSHELL with SNOWLIGHT/SNOWRUST, SNAPPYBEE/DeedRAT, ZingDoor) — the report includes comprehensive TTPs and IOCs (hashes, domains, IPs) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.