Threats · 132 days ago
UAT-8302 is not a one-off intrusion set. It is a China-linked operator that appears to reuse or share tooling across campaigns, which means defenders cannot treat each malware family as an isolated case or assume a clean break between clusters.
Cisco Talos says the group has targeted government entities in South America since late 2024 and southeastern Europe in 2025. The activity includes NetDraft, an updated CloudSorcerer backdoor, VSHELL with SNOWLIGHT, and a new Rust stager called SNOWRUST, plus post-compromise credential extraction and open-source tooling.
The overlap with malware previously tied to Jewelbug and other China-nexus clusters points to shared development, shared operators, or both. That makes attribution less useful than the operational fact that these groups can swap tooling and keep access alive across regions and campaigns.
2 sources covering this story
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
UAT-8302 targets governments since 2024 using shared China-linked malware, enabling persistent access and cross-group cyber operations.
UAT-8302 and its box full of malware
Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.
Part of the PlainSec briefing for 2026-05-06