logo

UAT-8302 Targets Government Agencies With Custom Malware and Open-Source Tools

ID: 5a95668b-4135-5862-84d6-b271055af061

STIX ID: report--5a95668b-4135-5862-84d6-b271055af061

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Mayura Kathir

...
...

UAT-8302 is a China-linked APT conducting stealthy, long-term espionage against government organizations in South America and southeastern Europe using custom implants (NetDraft/FringePorch, CloudSorcerer, VSHELL/SNOWRUST), DLL side-loading, cloud-based C2, extensive AD and credential theft, and open-source tunneling and reconnaissance tools; defenders should prioritize behavior-based detection, robust logging, and signatures for known components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.