logo

Cisco Talos Unmasks UAT-8302’s Global Government Espionage Network

ID: 01b478a1-bf3a-57f4-a4a4-501f2318fd81

STIX ID: report--01b478a1-bf3a-57f4-a4a4-501f2318fd81

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Ddos

...
...

Cisco Talos attributes a China-linked APT cluster dubbed UAT-8302 with systematic intrusions against government entities in South America and southeastern Europe since late 2024. The report details deployment of backdoors (NetDraft/Nosy Door, CloudSorcerer v3, VSHELL and Rust-based SNOWRUST), use of legitimate services for C2 (Microsoft Graph/OneDrive, GitHub, GameSpot), post-compromise activities (credential extraction, network lateral movement via Impacket/WMI, covert tunneling with Stowaway/SoftEther), and evidence of tool-sharing and code reuse across multiple China-aligned threat clusters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.