Cisco Talos Unmasks UAT-8302’s Global Government Espionage Network
ID: 01b478a1-bf3a-57f4-a4a4-501f2318fd81
STIX ID: report--01b478a1-bf3a-57f4-a4a4-501f2318fd81
Feed Name: securityonline.info
Cisco Talos attributes a China-linked APT cluster dubbed UAT-8302 with systematic intrusions against government entities in South America and southeastern Europe since late 2024. The report details deployment of backdoors (NetDraft/Nosy Door, CloudSorcerer v3, VSHELL and Rust-based SNOWRUST), use of legitimate services for C2 (Microsoft Graph/OneDrive, GitHub, GameSpot), post-compromise activities (credential extraction, network lateral movement via Impacket/WMI, covert tunneling with Stowaway/SoftEther), and evidence of tool-sharing and code reuse across multiple China-aligned threat clusters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
