UAT-12197 is an unattributed intrusion cluster targeting Cisco Secure Firewall Management Center (FMC) systems. It exploited CVE-2026-20079, an authentication-bypass vulnerability, to deploy JSP-based web shells and a Java Archive-based command executor. The actor used this tooling to execute commands, query internal FMC databases, and obtain user authentication data and credentials. UAT-12197 has not been publicly attributed to a country, known threat actor, or ransomware operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploits Cisco FMC CVE-2026-20079 to gain access, deploy JSP web shells and custom Java command executors, query internal databases, and harvest user authentication data and credentials.
Post-compromise activity cluster that used the FMC authentication-bypass flaw to search internal databases and collect user authentication data and credentials.
A threat cluster exploiting Cisco Secure Firewall Management Center authentication bypass CVE-2026-20079 to obtain root-level access, deploy web shells and a JAR command executor, and harvest internal database data and credentials.
An intrusion cluster that exploited the Cisco FMC authentication-bypass flaw to install a JSP web shell and malicious JAR file, execute commands, query internal databases, and steal authentication data and credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.