logo

China-linked APT UAT-8837 targets North American critical infrastructure

ID: efa61915-3b5f-5077-a700-7be8c18044b5

STIX ID: report--efa61915-3b5f-5077-a700-7be8c18044b5

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-01-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco Talos reports that UAT-8837, assessed with medium confidence as a China-nexus APT, has targeted North American critical infrastructure since at least 2025 using exploits (including evidence of a SiteCore ViewState deserialization zero-day), stolen credentials, and a suite of open-source and custom tools (e.g., GoTokenTheft, EarthWorm, SharpHound, Rubeus, Certipy) to perform AD reconnaissance, credential theft, persistence, lateral movement, and exfiltration — with published Snort rules and IOCs to detect the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.