apt
UAT-8302 and its box full of malware
High
Summary
Cisco Talos has identified UAT-8302, a China-nexus advanced persistent threat (APT) group, targeting government entities in South America and southeastern Europe. The group utilizes a range of custom malware families, including NetDraft (a variant of FinalDraft/SquidDoor), CloudSorcerer, and SNOWRUST, alongside established tools like VSHELL and Impacket. UAT-8302’s activities involve information collection, credential extraction, and network proliferation, demonstrating connections to other known China-nexus APT actors.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
