UAT-9686UAT-9686

Also known as: UAT-9686

Known aliases
1

Profile

UAT-9686 is a Chinese state-sponsored APT known for targeting networking infrastructure and edge appliances through a sophisticated espionage campaign. They exploit a critical flaw in the Cisco AsyncOS Spam Quarantine interface to gain root access and deploy custom malware, including AquaShell, along with Python scripts that execute natively. Their operations involve reverse tunneling and log purging, demonstrating a methodical approach to compromising communication infrastructure. Talos has observed overlaps in TTPs and tooling with other Chinese-nexus threat actors, indicating a consistent operational pattern.

Aliases· 1

UAT-9686

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UAT-8616
Actor
UAT-9244
Actor
UTA0388
Actor
UAT-6382
Actor
UAT-9921
Actor
UAT-8302
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.