China-linked APT UAT-8837 targets North American critical infrastructure
ID: efa61915-3b5f-5077-a700-7be8c18044b5
STIX ID: report--efa61915-3b5f-5077-a700-7be8c18044b5
Feed Name: Security Affairs
Cisco Talos reports that UAT-8837, assessed with medium confidence as a China-nexus APT, has targeted North American critical infrastructure since at least 2025 using exploits (including evidence of a SiteCore ViewState deserialization zero-day), stolen credentials, and a suite of open-source and custom tools (e.g., GoTokenTheft, EarthWorm, SharpHound, Rubeus, Certipy) to perform AD reconnaissance, credential theft, persistence, lateral movement, and exfiltration — with published Snort rules and IOCs to detect the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
