UAT-6382UAT-6382

Also known as: UAT-6382

Known aliases
1

Profile

UAT-6382 is a Chinese-speaking threat actor that exploits CVE-2025-0944 to gain access to enterprise networks, particularly targeting local governing bodies in the U.S. They deploy web shells like AntSword and chinatso/Chopper on IIS web servers and utilize Rust-based loaders to implement Cobalt Strike and VSHell for persistent access. UAT-6382 employs custom tooling, such as TetraLoader, and conducts reconnaissance to identify and exfiltrate files of interest. Their VShell stager connects to a hardcoded C2 server and executes payloads in memory, indicating modifications made by the actor.

Aliases· 1

UAT-6382

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UAT-8302
Actor
UAC-0063
Actor
UAT-7237
Actor
UAT-8099
Actor
UAT-10362
Actor
UAT-8616
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.