logo

UTG-Q-015 Exploits 0-Days for Espionage in Asia (Campaign)

ID: 49870976-90dc-5f46-8fcf-65fed4db65b2

STIX ID: report--49870976-90dc-5f46-8fcf-65fed4db65b2

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-05-19

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

UTG-Q-015, a Southeast Asia–based threat actor, escalated activity in early 2025 by exploiting 0-day and N-day vulnerabilities (including CVE-2023-48022) and misconfigured AI tooling to target government, enterprise, financial, blockchain/Web3 and AI research systems. The group conducted large-scale scanning and brute-force attacks, compromised over 100 websites in watering-hole operations, and used phishing and web exploitation to deliver .NET and Linux backdoors (Cobalt Strike, Vshell, Xnote), enabling lateral movement and persistent C2 access across high-value targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.