UAT-729 is a suspected Chinese advanced persistent threat group that has conducted cyber-espionage operations against telecommunications providers and critical infrastructure organizations in South Asia since at least 2022. The actor appears to focus on intelligence collection rather than disruptive or financially motivated activity. Reported targeting indicates an emphasis on sectors that can provide strategic access to communications and sensitive operational networks. Available reporting links UAT-729 to long-running intrusion activity consistent with state-aligned espionage tradecraft. High-confidence characterization supports targeting of telcos and critical infrastructure, but publicly available detail in this context is limited regarding specific malware families, intrusion chains, or sub-group structure. No widely established alternate aliases are confirmed here beyond UAT-729 itself. Based on the supported facts, UAT-729 should be assessed as a suspected China-linked espionage actor focused on persistent access and post-compromise intelligence collection against South Asian strategic sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.