Cisco Talos reported multiple intrusions against high-value North American critical infrastructure organizations attributed to UAT-8837, assessed with medium confidence as a China-nexus APT focused on obtaining initial access. Talos said the actor gained entry via compromised credentials and exploitation of vulnerable servers, then conducted hands-on-keyboard activity to harvest credentials and environment data (including security configurations and Active Directory information) to establish redundant access paths. Observed post-compromise tooling included Earthworm (used to create reverse tunnels and expose internal endpoints), SharpHound, DWAgent, and Certipy, alongside common discovery commands (e.g., tasklist /svc, netstat -aon -p TCP, whoami).
Talos linked UAT-8837 activity to exploitation of CVE-2025-53690, described as a ViewState deserialization zero-day affecting Sitecore products, noting that the overlap in tooling/infrastructure with other observed exploitation suggests the actor may have access to zero-day exploits. Reporting also highlighted that the vulnerability had previously been emphasized by U.S. federal cybersecurity authorities with a mandated patch timeline for federal civilian agencies, and that prior third-party analysis of incidents involving the same bug described similar post-exploitation tooling—reinforcing the assessment that this vulnerability has been operationalized in real intrusions against critical infrastructure targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Alongside its January 2026 report, Cisco Talos published indicators of compromise including file hashes and command-and-control IP addresses, as well as ClamAV and Snort detection coverage. The release provided defenders with technical details to identify and respond to UAT-8837 intrusions.
On January 15, 2026, Cisco Talos published research on UAT-8837, assessing with medium confidence that the actor is China-nexus based on overlaps in tactics, techniques, and procedures with other China-linked groups. The report detailed the actor's use of hands-on-keyboard reconnaissance, credential theft, tunneling, account manipulation, and tooling such as Earthworm, SharpHound, Certipy, Impacket, and Rubeus.
Google previously analyzed an incident involving CVE-2025-53690 and identified post-exploitation tooling overlaps later echoed in Talos' UAT-8837 findings. The overlap contributed to Talos' assessment that the actor may have access to zero-day exploits.
U.S. federal cybersecurity officials highlighted CVE-2025-53690 in the fall of 2025 and required federal civilian agencies to remediate it by September 25. This official response underscored the severity of the Sitecore zero-day being used in intrusions.
By September 2025, CVE-2025-53690, a Sitecore ViewState deserialization zero-day, was reported as being actively exploited in the wild. Talos later linked several UAT-8837 intrusions to exploitation of this vulnerability, suggesting the actor may have had access to zero-day exploits.
Cisco Talos assessed that since at least 2025, the cluster tracked as UAT-8837 has focused on gaining initial access to high-value organizations in North American critical infrastructure sectors. The actor used compromised credentials and exploitation of vulnerable internet-facing servers to breach multiple organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcetherecord.media
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.