Skip to main content
Mallory
🇨🇳 CN2 malware families

UTA0388

Also known asuta0388

UTA0388 is a China-aligned threat actor tracked by Volexity and linked to the Proofpoint cluster UNK_DropPitch. Reporting attributes to UTA0388 a series of spear-phishing campaigns active from at least June through September 2025 targeting organizations and individuals in North America, Europe, and Asia, with targeting described as consistent with Chinese cyberespionage interests and a particular focus on Asian geopolitical issues, including Taiwan. Reported targets included Taiwan’s semiconductor industry, U.S. academia, U.S. think tanks, and organizations representing Chinese minorities. UTA0388 used tailored, multilingual phishing lures in English, Chinese, Japanese, French, and German, often impersonating fabricated senior researchers and analysts. Later campaigns used rapport-building phishing, delaying delivery of malicious links until after email exchanges with targets. The actor used ChatGPT to generate spear-phishing content and assist malicious workflows, including information gathering on installing tools such as nuclei and fscan; OpenAI reported banning associated accounts. Volexity assessed with high confidence that UTA0388 used LLMs in support of phishing, and with medium confidence that some content generation and sending may have been automated with little human oversight. The campaigns delivered GOVERSHELL, a Go-based backdoor family that Volexity assessed is actively developed and used exclusively by UTA0388. GOVERSHELL was delivered via links to ZIP or RAR archives staged on legitimate services including Netlify, Sync, and OneDrive, as well as actor-controlled infrastructure. Phishing emails were sent via Proton Mail, Outlook, and Gmail. The archives typically contained a benign executable and a malicious DLL that was executed through DLL side-loading or DLL search-order hijacking, often using Tablacus Explorer. Persistence was achieved via scheduled tasks, and the malware enabled remote command execution, largely through PowerShell. Volexity identified five GOVERSHELL variants: HealthKick, TE32, TE64, WebSocket, and Beacon. HealthKick, first observed in April 2025, is described as the earliest observed GOVERSHELL variant and a predecessor/successor overlap with a prior C++ family also referred to as HealthKick. TE32 used a PowerShell reverse shell; TE64 used HTTPS JSON-based polling and PowerShell commands for system information gathering and task execution; WebSocket used AES-GCM-encrypted WebSocket communications and included an unimplemented update sub-command; Beacon, observed in September 2025, supported polling interval randomization and PowerShell command execution. Reporting also noted Simplified Chinese developer artifacts, Chinese-language log statements in at least one variant, and actor infrastructure registered behind Cloudflare, including domains referencing Taiwan or impersonating legitimate services. Known aliases and linked designations directly mentioned in the reporting are UTA0388 and UNK_DropPitch.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇹🇼 Taiwan

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics22 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0002
Execution
4 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1204
User Execution
T1204.002
Malicious File
T1574
Hijack Execution Flow
T1574.001
DLL
TA0003
Persistence
1 technique
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
TA0004
Privilege Escalation
1 technique
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
TA0005
Stealth
1 technique
T1574
Hijack Execution Flow
T1574.001
DLL
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1219
Remote Access Tools
IOCS

Observables

12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping11

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables12

Domains, IPs, and hashes tied to this actor, refreshed continuously.