UAT-7237
UAT-7237 is a Chinese-speaking advanced persistent threat group tracked by Cisco Talos, active since at least 2022. Talos assesses it likely operates as a subgroup of UAT-5918 based on overlaps in tooling, victimology, and activity timelines. Content also notes UAT-5918 overlaps with Chinese APTs such as Volt Typhoon and Flax Typhoon. UAT-7237 has targeted web infrastructure entities in Taiwan, including a Taiwanese web hosting provider, with the objective of establishing long-term access in high-value victim environments and with particular interest in victims’ VPN and cloud infrastructure. According to the provided reporting, UAT-7237 gains initial access by exploiting known vulnerabilities on unpatched internet-exposed servers. It conducts reconnaissance using native commands and administrative tooling, including nslookup, systeminfo, curl, ping, ipconfig, net use, domain enumeration, SharpWMI, and WMICmd. For lateral movement and discovery it uses SMB enumeration, FScan, and smb_version. The group is described as relying heavily on Cobalt Strike as a staple backdoor implant and using a combination of RDP access and SoftEther VPN clients for persistence and backdoor access, while deploying web shells selectively on only a few endpoints. Talos identified a custom shellcode loader named SoundBill, based on VTHello and written in Chinese, which decodes a local file such as ptiti.txt and executes arbitrary shellcode. SoundBill has been observed loading payloads including Mimikatz functionality and Cobalt Strike beacons. The reporting also states that SoundBill contains two embedded executables originating from QQ that Talos assesses are likely decoys. For privilege escalation and credential access, UAT-7237 has used JuicyPotato, LSASS dumping via the GitHub project ssp_dump_lsass, registry searches for VNC credentials, and attempts to weaken Windows security by modifying registry settings to disable UAC remote restrictions and enable WDigest cleartext credential storage. Talos observed SoftEther VPN infrastructure associated with the actor from September 2022 through December 2024 and noted Simplified Chinese language settings in the VPN client configuration. Known alias in the provided content: uat_7237.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
Where they target
Geographies tied to known operations.
- 🇹🇼 Taiwan
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-speaking APT cluster targeting Taiwanese web infrastructure entities using customized open-source tools to establish long-term access.
China-linked espionage cluster targeting a Taiwanese web hosting provider to gain long-term access to victims’ VPN and cloud infrastructure; relies on Cobalt Strike and a mix of custom/open-source tooling for persistence, credential theft, and command execution.
China-linked espionage cluster targeting a Taiwanese web hosting provider to gain long-term access to victims’ VPN and cloud infrastructure; relies on Cobalt Strike and a mix of custom/open-source tooling for persistence, credential theft, and command execution.
UAT-7237 is conducting targeted attacks against Taiwanese web infrastructure using a custom toolset.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.