A Chinese state-sponsored APT group targeting network infrastructure by exploiting Cisco AsyncOS flaws for espionage.
Analyst brief
UAT-9686 is a Chinese state-sponsored APT group that targets networking infrastructure and edge appliances through a sophisticated espionage campaign. They exploit a critical flaw in the Cisco AsyncOS Spam Quarantine interface to gain root access and deploy custom malware such as AquaShell along with native Python scripts. Their TTPs include reverse tunneling and log purging, demonstrating a methodical approach, while Talos has observed overlaps with other Chinese-nexus threat actors. Defenders should prioritize patching Cisco AsyncOS vulnerabilities, monitoring the Spam Quarantine interface for suspicious access, and detecting unusual reverse connection attempts.
UAT-9686
unknown
UAT-9686 is a Chinese state-sponsored APT known for targeting networking infrastructure and edge appliances through a sophisticated espionage campaign. They exploit a critical flaw in the Cisco AsyncOS Spam Quarantine interface to gain root access and deploy custom malware, including AquaShell, along with Python scripts that execute natively. Their operations involve reverse tunneling and log purging, demonstrating a methodical approach to compromising communication infrastructure. Talos has observed overlaps in TTPs and tooling with other Chinese-nexus threat actors, indicating a consistent operational pattern.