UTA0388
UTA0388 is a China-aligned threat actor tracked by Volexity and linked to the Proofpoint cluster UNK_DropPitch. Reporting attributes to UTA0388 a series of spear-phishing campaigns active from at least June through September 2025 targeting organizations and individuals in North America, Europe, and Asia, with targeting described as consistent with Chinese cyberespionage interests and a particular focus on Asian geopolitical issues, including Taiwan. Reported targets included Taiwan’s semiconductor industry, U.S. academia, U.S. think tanks, and organizations representing Chinese minorities. UTA0388 used tailored, multilingual phishing lures in English, Chinese, Japanese, French, and German, often impersonating fabricated senior researchers and analysts. Later campaigns used rapport-building phishing, delaying delivery of malicious links until after email exchanges with targets. The actor used ChatGPT to generate spear-phishing content and assist malicious workflows, including information gathering on installing tools such as nuclei and fscan; OpenAI reported banning associated accounts. Volexity assessed with high confidence that UTA0388 used LLMs in support of phishing, and with medium confidence that some content generation and sending may have been automated with little human oversight. The campaigns delivered GOVERSHELL, a Go-based backdoor family that Volexity assessed is actively developed and used exclusively by UTA0388. GOVERSHELL was delivered via links to ZIP or RAR archives staged on legitimate services including Netlify, Sync, and OneDrive, as well as actor-controlled infrastructure. Phishing emails were sent via Proton Mail, Outlook, and Gmail. The archives typically contained a benign executable and a malicious DLL that was executed through DLL side-loading or DLL search-order hijacking, often using Tablacus Explorer. Persistence was achieved via scheduled tasks, and the malware enabled remote command execution, largely through PowerShell. Volexity identified five GOVERSHELL variants: HealthKick, TE32, TE64, WebSocket, and Beacon. HealthKick, first observed in April 2025, is described as the earliest observed GOVERSHELL variant and a predecessor/successor overlap with a prior C++ family also referred to as HealthKick. TE32 used a PowerShell reverse shell; TE64 used HTTPS JSON-based polling and PowerShell commands for system information gathering and task execution; WebSocket used AES-GCM-encrypted WebSocket communications and included an unimplemented update sub-command; Beacon, observed in September 2025, supported polling interval randomization and PowerShell command execution. Reporting also noted Simplified Chinese developer artifacts, Chinese-language log statements in at least one variant, and actor infrastructure registered behind Cloudflare, including domains referencing Taiwan or impersonating legitimate services. Known aliases and linked designations directly mentioned in the reporting are UTA0388 and UNK_DropPitch.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇹🇼 Taiwan
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UTA0388 is a Chinese state-sponsored APT group using AI services to enhance spear-phishing operations, targeting high-value sectors.
Conducting China-nexus cyberespionage-oriented spear-phishing campaigns using ChatGPT-generated lure content to deliver archive files (ZIP/RAR) that install the GOVERSHELL backdoor; leveraging common cloud/web services for staging and enabling PowerShell-based post-compromise activity via a Beacon variant.
China-aligned espionage activity conducting highly tailored spear-phishing (including rapport-building phishing) to deliver the GOVERSHELL backdoor via archives and DLL side-loading; also noted for using ChatGPT to generate phishing content and assist with malicious workflows.
Described as a China-aligned activity cluster (UTA0388) leveraging ChatGPT to automate multilingual spear-phishing.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.