UAT-8837
UAT-8837 is a threat actor tracked by Cisco Talos and assessed with medium confidence to be a China-nexus advanced persistent threat (APT) actor. Since at least 2025, the group has targeted critical infrastructure organizations in North America, including the U.S. and Canada, and appears primarily focused on obtaining initial access to high-value organizations. Reported initial access methods include exploitation of vulnerable public-facing servers and use of compromised credentials. Talos linked the actor’s activity, tooling, and infrastructure to exploitation of the Sitecore vulnerability CVE-2025-53690, described in the reporting as a ViewState deserialization zero-day that enabled pre-authentication remote code execution. The reporting states this suggests the actor may have access to zero-day exploits. Post-compromise, UAT-8837 conducts reconnaissance, credential harvesting, and Active Directory/domain discovery, and establishes multiple channels of access. Reported behavior includes disabling RestrictedAdmin for RDP, hands-on-keyboard activity via cmd.exe, creating or modifying accounts for persistence, and exfiltrating sensitive data. In at least one case, the actor exfiltrated DLL-based shared libraries related to a victim’s products, which Talos assessed could create future trojanization or supply-chain compromise risk. The group is reported to rely heavily on open-source, dual-use, and living-off-the-land tooling, and to rotate tool variants to evade detection. Tools explicitly mentioned in the content include Earthworm, DWAgent, SharpHound, Impacket, GoExec, Rubeus, Certipy, GoTokenTheft, Invoke-WMIExec, SharpWMI, and 7-Zip. Separate reporting tied exploitation of CVE-2025-53690 to deployment of the WeepSteel backdoor for long-term espionage and data exfiltration, with unauthorized administrative accounts such as asp$ and sawadmin also observed. No aliases beyond UAT-8837 are directly supported in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Energy
- Utilities
- Government & Administration
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇨🇦 Canada
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned APT actor targeting North American critical infrastructure; observed exploiting a Sitecore zero-day in intrusions.
China-linked APT activity cluster exploiting Sitecore zero-day CVE-2025-53690 (ViewState insecure deserialization) to gain RCE, deploy the WeepSteel backdoor, establish persistence (e.g., DWAgent service), enable tunneling (Earthworm), create admin accounts (asp$, sawadmin), and exfiltrate sensitive data (e.g., web.config, SAM/SYSTEM hives) for espionage.
China-nexus APT activity targeting North American critical infrastructure. Initial access via exploits (including suspected zero-days) or stolen credentials, followed by hands-on-keyboard post-compromise operations: credential theft, Active Directory reconnaissance/mapping, defense weakening (e.g., disabling RestrictedAdmin for RDP), persistence, lateral movement, and data exfiltration (including product-related DLLs, raising supply-chain trojanization risk).
Chinese state-sponsored intrusion activity targeting North American critical infrastructure, exploiting a Sitecore zero-day to gain initial access and then using tooling (including Earthworm) to discover internal endpoints and establish reverse tunnels for persistent access.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.