UAT-5918 is a China-linked cyber-espionage threat actor active since at least 2023 and associated with intrusions against high-value targets in Taiwan, particularly critical infrastructure and telecommunications-related organizations. The actor is assessed to overlap with activity clusters commonly tracked as Volt Typhoon, Flax Typhoon, Earth Estries, and Dalbit, but is tracked as a distinct cluster. Reporting also indicates that UAT-7237 is likely a subgroup operating under the broader UAT-5918 umbrella. The group’s operations emphasize long-term access, information theft, and persistence in victim environments rather than disruptive or destructive effects. UAT-5918 has been linked to campaigns targeting Taiwan’s critical infrastructure with the apparent objective of establishing durable footholds. It has also been described as specializing in telecommunications targeting and as using operational relay box infrastructure such as LapDogs in at least one espionage operation against Taiwan, although available reporting does not establish whether UAT-5918 operated that relay network directly or consumed it as a client. Tradecraft associated with UAT-5918 includes exploitation of unpatched internet-facing servers for initial access, extensive use of web shells, and reliance on open-source post-exploitation tooling for persistence, credential theft, reconnaissance, and lateral movement. Tooling overlaps tied to the broader cluster include utilities such as iox, fscan, suo5, and Neo-reGeorg, consistent with hands-on-keyboard post-compromise activity and covert tunneling. UAT-5918 is also associated with Meterpreter-style reverse shell access in contrast to subgroup UAT-7237’s heavier use of Cobalt Strike. The subgroup UAT-7237 has been observed using SoftEther VPN, RDP, WMI-based tooling, JuicyPotato, LSASS dumping, registry-based credential searches, and a custom shellcode loader called SoundBill to maintain persistence, escalate privileges, steal credentials, and move laterally inside Taiwanese environments. Available evidence supports assessment of UAT-5918 as an espionage-oriented China-nexus actor focused on persistent access and credential collection against strategically relevant targets, especially in Taiwan. Tooling and infrastructure overlaps with other Chinese intrusion sets are notable, but the cluster is treated as a separate actor with its own operational objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"The attacks themselves weaponize N-day security vulnerabilities (e.g., CVE-2015-1548 and CVE-2017-17663) to obtain initial access."
"The attacks themselves weaponize N-day security vulnerabilities (e.g., CVE-2015-1548 and CVE-2017-17663) to obtain initial access."
83 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for TTP overlap with similar Chinese-origin post-exploitation tooling.
Secondary China-nexus actor described as a consumer of ORB infrastructure established by UAT-7810, with tooling overlap but treated as a distinct entity.
Separate China-linked APT that receives infrastructure support from UAT-7810 and has overlapping tooling.
A China-nexus threat actor that leveraged UAT-7810's ORB infrastructure in attacks targeting critical infrastructure entities in Taiwan to establish persistent access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.