China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
ID: eeb1815b-d149-54b9-87d2-36bba29e7e1a
STIX ID: report--eeb1815b-d149-54b9-87d2-36bba29e7e1a
Feed Name: The Hacker News
Cisco Talos attributes a China‑nexus APT tracked as UAT-8302 to targeted intrusions against government entities in South America (since late 2024) and southeastern Europe (2025). The group deploys custom .NET backdoors (NetDraft/NosyDoor), VShell, SNOWRUST and CloudSorcerer, leverages proxy/VPN tools (Stowaway, SoftEther), conducts extensive reconnaissance and lateral movement, and appears to share tooling and access with other China-aligned groups under evolving models such as a reported "Premier Pass-as-a-Service."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
