UAT-8302UAT-8302

Also known as: UAT-8302

Known aliases
1

Profile

UAT-8302 is a sophisticated China-nexus APT group targeting government entities in South America and southeastern Europe, deploying custom-made malware such as NetDraft, CloudSorcerer version 3, and VSHELL. They utilize tools like SNOWLIGHT and SNOWRUST for initial access and reconnaissance, employing techniques such as PowerShell scripts and SMB share discovery. UAT-8302 also establishes backdoor access through proxy servers and uses tools like Stowaway for tunneling traffic. Their operations indicate a close relationship with other known China-nexus threat actors, leveraging shared malware families and TTPs.

Aliases· 1

UAT-8302

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UAT-6382
Actor
UNG0002
Actor
UTA0388
Actor
UAC-0063
Actor
UAT-8099
Actor
UAT-7237
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.