Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UTG-Q-008

Also known as: SwimSnake, ValleyRAT, the Newscaster Team, UTG-Q-1000, Void Arachne, has been targeting research, educational institutes in China, Valley Thief, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China. They utilize a massive botnet network for espionage activities, including reconnaissance, brute-forcing, and Trojan component delivery. The actor has a history of compromising thousands of servers in China using a password dictionary based on Chinese Pinyin. UTG-Q-008 operates during standard working hours in the UTC+8 time zone, with potential ties to Eastern Europe.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Energy
Telecommunications
Education
Aerospace
Media
Manufacturing
Information technology
Maritime
Think tank
Mining
Healthcare
Pharmaceutical
Chemical
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
JP
GB
IN
DE
TW
KR
IR
RU
SA
FR
CA
IL
TR
AU
KZ
PK
VN
UA
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.cybersecurity-help.cz — Cited by web research for: has been targeting research
  2. thehackernews.com — Cited by web research for: Valley Thief
  3. misp-galaxy.org — Cited by web research for: cpyy
  4. hybrid-analysis.com — Cited by web research for: T1056.001
  5. pmc.ncbi.nlm.nih.gov — Cited by web research for: Docker

Intel Summary

8

Techniques

40

Tools

0

Campaigns

37

IOCs

0

Observed Data

5

Tactics

Tags

APT
DDoS
Government Targeting

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.