CN

UTA0388UTA0388

Also known as: UTA0388

Origin
CN
Known aliases
1

Profile

UTA0388 is a China-aligned APT known for spear-phishing campaigns targeting organizations in North America, Asia, and Europe, primarily to deliver a Go-based implant called GOVERSHELL. The group employs "rapport-building phishing" tactics, engaging targets in benign conversations before sending malicious links, and has been linked to the use of Large Language Models for crafting phishing emails in multiple languages. Technical analysis indicates that UTA0388 operates in the interests of the Chinese state, with a focus on Asian geopolitical issues, as evidenced by the use of Simplified Chinese in its development environment. Volexity assesses that UTA0388's operations reflect a sophisticated blend of traditional phishing techniques and modern automation.

Aliases· 1

UTA0388

References

  1. https://www.volexity.com/blog/2025/10/08/apt-meets-gpt-targeted-operations-with-untamed-llms/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UAT-8302
Actor
UTG-Q-008
Actor
UAT-8099
Actor
UAT-9686
Actor
UTA0355
Group
admin@338
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.