UAT-8616UAT-8616

Also known as: UAT-8616

Known aliases
1

Profile

UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.

Aliases· 1

UAT-8616

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UAT-9686
Actor
UAT-10608
Actor
UNC3886
Actor
UAT-6382
Actor
UTA0218
Actor
UAC-0185
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.