UAT-8837 is a threat actor tracked by Cisco Talos and assessed with medium confidence to be a China-nexus advanced persistent threat (APT) actor. Since at least 2025, the group has targeted critical infrastructure organizations in North America, including the U.S. and Canada, and appears primarily focused on obtaining initial access to high-value organizations. Reported initial access methods include exploitation of vulnerable public-facing servers and use of compromised credentials. Talos linked the actor’s activity, tooling, and infrastructure to exploitation of the Sitecore vulnerability CVE-2025-53690, described in the reporting as a ViewState deserialization zero-day that enabled pre-authentication remote code execution. The reporting states this suggests the actor may have access to zero-day exploits. Post-compromise, UAT-8837 conducts reconnaissance, credential harvesting, and Active Directory/domain discovery, and establishes multiple channels of access. Reported behavior includes disabling RestrictedAdmin for RDP, hands-on-keyboard activity via cmd.exe, creating or modifying accounts for persistence, and exfiltrating sensitive data. In at least one case, the actor exfiltrated DLL-based shared libraries related to a victim’s products, which Talos assessed could create future trojanization or supply-chain compromise risk. The group is reported to rely heavily on open-source, dual-use, and living-off-the-land tooling, and to rotate tool variants to evade detection. Tools explicitly mentioned in the content include Earthworm, DWAgent, SharpHound, Impacket, GoExec, Rubeus, Certipy, GoTokenTheft, Invoke-WMIExec, SharpWMI, and 7-Zip. Separate reporting tied exploitation of CVE-2025-53690 to deployment of the WeepSteel backdoor for long-term espionage and data exfiltration, with unauthorized administrative accounts such as asp$ and sawadmin also observed. No aliases beyond UAT-8837 are directly supported in the provided content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-aligned APT actor targeting North American critical infrastructure; observed exploiting a Sitecore zero-day in intrusions.
China-linked APT activity cluster exploiting Sitecore zero-day CVE-2025-53690 (ViewState insecure deserialization) to gain RCE, deploy the WeepSteel backdoor, establish persistence (e.g., DWAgent service), enable tunneling (Earthworm), create admin accounts (asp$, sawadmin), and exfiltrate sensitive data (e.g., web.config, SAM/SYSTEM hives) for espionage.
China-nexus APT activity targeting North American critical infrastructure. Initial access via exploits (including suspected zero-days) or stolen credentials, followed by hands-on-keyboard post-compromise operations: credential theft, Active Directory reconnaissance/mapping, defense weakening (e.g., disabling RestrictedAdmin for RDP), persistence, lateral movement, and data exfiltration (including product-related DLLs, raising supply-chain trojanization risk).
Chinese state-sponsored intrusion activity targeting North American critical infrastructure, exploiting a Sitecore zero-day to gain initial access and then using tooling (including Earthworm) to discover internal endpoints and establish reverse tunnels for persistent access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.