UTG-Q-015 is a Southeast Asia-based threat actor active since at least late 2024 that escalated its operations in early 2025. The group has targeted government and enterprise systems, financial institutions, blockchain and Web3 platforms, fintech organizations, Chinese developer forums, and AI research environments. Observed activity includes exploitation of both zero-day and known vulnerabilities in public-facing applications, large-scale scanning, password brute-forcing, watering hole compromises, and instant-messaging phishing used to deliver backdoors and other payloads. In one campaign, the actor compromised more than 100 websites in the blockchain, Web3, and fintech ecosystem and used fake update prompts to deliver .NET-based backdoors. UTG-Q-015 has also used multi-stage intrusion chains that begin with web exploitation and progress to phishing-based payload delivery, followed by establishment of command-and-control access and lateral movement inside victim networks. Post-compromise tooling observed in its operations includes Cobalt Strike as well as lightweight backdoors such as Vshell and Xnote. The actor has also targeted Linux systems associated with AI research by exploiting vulnerable or misconfigured components. UTG-Q-015 demonstrates capabilities spanning reconnaissance, scanning, brute-force access attempts, initial access through exploitation and phishing, persistence via backdoors, lateral movement, and broader post-exploitation activity. Its victimology and tradecraft indicate a mixed profile involving both financially oriented targeting and espionage-like collection, but a single dominant motivation is not established with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UTG-Q-015 is a Southeast Asian threat actor targeting government, enterprise, blockchain, and financial institutions using N-day vulnerabilities and phishing tactics.
UTG-Q-015 is a Southeast Asia-based threat actor known for exploiting 0-day and 1-day vulnerabilities to conduct data exfiltration, espionage, and financially motivated attacks. The group targets government, enterprise, blockchain, Web3, financial tech, and AI research sectors using a variety of techniques including watering hole campaigns, phishing, brute-forcing, and lateral movement. They deploy backdoors and leverage open-source and supply chain vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.