UAT-8616 is a high-caliber threat actor targeting critical infrastructure through network edge device exploitation.
Analyst brief
UAT-8616 is a highly sophisticated cyber threat actor tracked by Cisco Talos, active since at least 2023. They target high-value organizations in Critical Infrastructure sectors, with a focus on network edge devices to establish persistent footholds. Key TTPs include exploiting CVE-2026-20127 in the wild and escalating to root access via CVE-2022-20775 through software version downgrades. Defenders should prioritize patching these vulnerabilities, enforce strict version control policies, and monitor network edge devices for anomalous privilege escalation activities.
UAT-8616
unknown
UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.
What are the primary vulnerabilities exploited by the UAT-8616 actor?+
The primary vulnerabilities exploited by UAT-8616 are CVE-2026-20127 and CVE-2022-20775, through which the actor gains root access by downgrading the software version.
Which sectors do UAT-8616's primary targets belong to?+
UAT-8616 targets high-value organizations, particularly those in Critical Infrastructure sectors, focusing on establishing persistent footholds on network edge devices.