China-linked hackers exploited Sitecore zero-day for initial access
ID: ca47e9d7-10d6-5e29-a8e7-e3b93411b2d3
STIX ID: report--ca47e9d7-10d6-5e29-a8e7-e3b93411b2d3
Feed Name: Bleeping Computer
UAT-8837, a China-linked actor active since at least 2025, has targeted North American critical infrastructure to gain initial access via compromised credentials and server vulnerabilities, including the Sitecore ViewState deserialization zero-day (CVE-2025-53690). Cisco Talos reports hands-on-keyboard post-exploitation focused on credential theft and AD reconnaissance using living-off-the-land and open-source tools, observed deployment of a reconnaissance backdoor (WeepSteel), DLL exfiltration that could enable supply-chain trojanization, and provides IOCs and example commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
