UAT-8837 Launches Targeted Attacks to Steal Sensitive Organizational Data
ID: 7156aaa1-ac52-5352-9014-99863f90e4a0
STIX ID: report--7156aaa1-ac52-5352-9014-99863f90e4a0
Feed Name: GBHackers
**UAT-8837 (China-nexus APT)** is conducting sustained campaigns against North American critical infrastructure, leveraging a Sitecore ViewState deserialization zero-day (CVE-2025-53690) and a mix of open-source and custom tools (e.g., Earthworm, SharpHound, DWAgent, GoTokenTheft, Certipy, Impacket) to achieve initial access, AD enumeration, lateral movement, and exfiltration of proprietary DLLs; defenders are advised to monitor for RDP configuration changes, unusual AD enumeration, and administrative tool execution, apply rapid Sitecore patching, enforce MFA, and segment networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
