UTA0218 is a state-backed threat actor exploiting firewall vulnerabilities to steal critical credentials via the UPSTYLE backdoor.
Analyst brief
UTA0218 is a likely state-backed threat actor with advanced capabilities, focusing on exploiting firewall device vulnerabilities to move laterally within victim networks. The actor aims to obtain domain backup keys and Active Directory credentials, deploying a custom Python backdoor named 'UPSTYLE' to execute commands, download additional tools, and utilizing infrastructure including VPNs and compromised routers to host malicious files. Defenders should prioritize patching firewall vulnerabilities, monitoring lateral movement attempts, and inspecting traffic related to custom Python-based backdoors targeting critical credentials.
UTA0218
unknown
UTA0218 is a threat actor with advanced capabilities, targeting organizations to establish a reverse shell, acquire tools, and extract data. They exploit vulnerabilities in firewall devices to move laterally within victim networks, focusing on obtaining domain backup keys and active directory credentials. The actor deploys a custom Python backdoor named UPSTYLE to execute commands and download additional tools. UTA0218 is likely state-backed, utilizing a mix of infrastructure including VPNs and compromised routers to store malicious files.