China-Nexus APT Reuses Malware Across Government Targets
UAT-8302 is not a one-off intrusion set. It is a China-linked operator that appears to reuse or share tooling across campaigns, which means defenders cannot treat each malware family as an isolated case or assume a clean break between clusters.
Cisco Talos says the group has targeted government entities in South America since late 2024 and southeastern Europe in 2025. The activity includes NetDraft, an updated CloudSorcerer backdoor, VSHELL with SNOWLIGHT, and a new Rust stager called SNOWRUST, plus post-compromise credential extraction and open-source tooling.
The overlap with malware previously tied to Jewelbug and other China-nexus clusters points to shared development, shared operators, or both. That makes attribution less useful than the operational fact that these groups can swap tooling and keep access alive across regions and campaigns.