CN

UAT-7237UAT-7237

Also known as: UAT-7237

Origin
CN
Known aliases
1

Profile

UAT-7237 is a Chinese-speaking APT group that has been active since at least 2022, primarily targeting web infrastructure entities in Taiwan. They utilize a customized Shellcode loader known as “SoundBill” to execute shellcode, including Cobalt Strike payloads, and rely on SoftEther VPN clients and RDP for persistence and access. UAT-7237 employs techniques such as credential extraction using Mimikatz, reconnaissance with WMI-based tools, and selective deployment of web shells. Their operations indicate a focus on long-term persistence and stealth, with a preference for open-sourced and customized tooling.

Aliases· 1

UAT-7237

References

  1. https://blog.talosintelligence.com/uat-7237-targets-web-hosting-infra/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UAT-8837
Actor
UAT-6382
Actor
UAT-8302
Actor
APT37
Actor
UAT-5918
Actor
UAC-0063
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.