logo

China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions

ID: eeb1815b-d149-54b9-87d2-36bba29e7e1a

STIX ID: report--eeb1815b-d149-54b9-87d2-36bba29e7e1a

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cisco Talos attributes a China‑nexus APT tracked as UAT-8302 to targeted intrusions against government entities in South America (since late 2024) and southeastern Europe (2025). The group deploys custom .NET backdoors (NetDraft/NosyDoor), VShell, SNOWRUST and CloudSorcerer, leverages proxy/VPN tools (Stowaway, SoftEther), conducts extensive reconnaissance and lateral movement, and appears to share tooling and access with other China-aligned groups under evolving models such as a reported "Premier Pass-as-a-Service."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.