UAT-8302 is a China-nexus APT group targeting government entities in South America and southeastern Europe with custom malware.
Analyst brief
UAT-8302 is a sophisticated China-nexus APT group targeting government entities in South America and southeastern Europe. The group uses custom malware such as NetDraft, CloudSorcerer version 3, and VSHELL, along with SNOWLIGHT and SNOWRUST for initial access and reconnaissance. Their TTPs include PowerShell scripts, SMB share discovery, and establishing backdoor access via proxy servers with tools like Stowaway for tunneling traffic. Defenders should focus on monitoring PowerShell activity, detecting anomalous SMB share enumeration, and inspecting proxy and tunnel traffic associated with the mentioned malware families.
UAT-8302
unknown
UAT-8302 is a sophisticated China-nexus APT group targeting government entities in South America and southeastern Europe, deploying custom-made malware such as NetDraft, CloudSorcerer version 3, and VSHELL. They utilize tools like SNOWLIGHT and SNOWRUST for initial access and reconnaissance, employing techniques such as PowerShell scripts and SMB share discovery. UAT-8302 also establishes backdoor access through proxy servers and uses tools like Stowaway for tunneling traffic. Their operations indicate a close relationship with other known China-nexus threat actors, leveraging shared malware families and TTPs.
What tools does UAT-8302 use for initial access and reconnaissance?+
UAT-8302 uses SNOWLIGHT and SNOWRUST tools for initial access and reconnaissance.
What activities should defenders focus on to detect UAT-8302's operations?+
Defenders should focus on monitoring PowerShell activity, detecting anomalous SMB share enumeration, and inspecting proxy and tunnel traffic associated with the mentioned malware families.