logo

China-linked hackers exploited Sitecore zero-day for initial access

ID: ca47e9d7-10d6-5e29-a8e7-e3b93411b2d3

STIX ID: report--ca47e9d7-10d6-5e29-a8e7-e3b93411b2d3

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

UAT-8837, a China-linked actor active since at least 2025, has targeted North American critical infrastructure to gain initial access via compromised credentials and server vulnerabilities, including the Sitecore ViewState deserialization zero-day (CVE-2025-53690). Cisco Talos reports hands-on-keyboard post-exploitation focused on credential theft and AD reconnaissance using living-off-the-land and open-source tools, observed deployment of a reconnaissance backdoor (WeepSteel), DLL exfiltration that could enable supply-chain trojanization, and provides IOCs and example commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.