Also known as: the Newscaster Team, SHADOW-WATER-063, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, Paper Werewolf, 560048
UTG‑Q‑010 emerged as a financially motivated threat actor from East Asia in late 2022, quickly establishing a reputation for combining phishing with targeted exploitation of legitimate system processes. Its primary focus has been the pharmaceutical sector and cryptocurrency communities, where it leverages insider knowledge of industry vulnerabilities; key operations typically begin with spear‑phishing attachments that trigger the download of a malicious DLL. The malware chain involves sideloading faultrep.dll into WerFault.exe, a common Windows error reporting program. The DLL then loads additional code—such as Pupy RAT—in memory through reflective DLL loading techniques, thereby bypassing static analysis tools. Operationally, the group has shown a preference for human‑factor attacks, notably targeting HR departments to harvest credentials and personal data that can be monetized directly or used to expand lateral movement within corporate networks. The combination of legitimate process utilization, in‑memory execution, and supply‑chain‑like delivery mechanisms allows UTG‑Q‑010 to maintain persistence across a broad global footprint, often spanning the United States, China, Europe, India, the Middle East and many other jurisdictions.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UTG‑Q‑010 is an East Asian APT that blends cyber‑espionage with financial gain, concentrating on pharmaceutical firms and cryptocurrency users. The group exploits legitimate Windows processes (e.g., WerFault.exe) to inject malicious DLLs such as faultrep.dll and delivers the Pupy RAT through sophisticated spear‑phishing campaigns. Advanced defense evasion—including in‑memory execution and reflective DLL loading—is employed to conceal activity while exfiltrating sensitive data.
Goals & Targeting
UTG‑Q‑010’s strategic objectives blend espionage with monetary exploitation. The pharmaceutical industry is prized for its valuable intellectual property and R&D data; capturing such information can yield both intelligence value and commercial leverage. Cryptocurrency users provide direct financial pathways, enabling the group to siphon funds or sell stolen wallets without a long‑term foothold. The geographic breadth of attacks—targeting countries from the U.S. to Iran, Ukraine, Saudi Arabia and beyond—reflects an intent to collect broad geopolitical intelligence while simultaneously exploiting local industries for profit. Typical victims are mid‑to‑large organizations with high value assets in health care, finance, technology and energy; HR portals are specifically chosen because they hold a concentrated pool of credentials. The actor’s willingness to blend espionage objectives with economic attack vectors demonstrates an adaptable approach that seeks both strategic benefit and immediate financial return.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first appearance in late 2022, UTG‑Q‑010 has maintained a steady operational tempo, deploying multi‑stage campaigns that combine spear‑phishing with legitimate process exploitation. The group’s patterns indicate targeted exploitation of HR systems to harvest credentials and internal data, followed by lateral movement via the Pupy RAT for deeper network penetration. Campaigns frequently span numerous countries within a short time frame, suggesting efficient automation pipelines and possibly shared infrastructure across different threat actor aliases. Notable elements include rapid use of weaponized VPN installers and custom domains (e.g., demo‑cloud.space) to distribute malware, as well as the reliance on both Windows Command Shell and PowerShell for execution and persistence. UTG‑Q‑010’s operations remain largely covert; however, emerging indicators point toward a shift toward more aggressive financial sub‑campaigns within the cryptocurrency arena, likely leveraging stolen wallets or credentials for direct monetary gain.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The profile is based primarily on the provided group description and linked MITRE TTPs. While the actor’s name, aliases, and tactics are cited in multiple sources, many details—such as specific operational dates or precise victim organizations—are sparse or indirectly referenced. Consequently, confidence remains moderate: key capabilities and techniques are well‑supported, but strategic motivations (e.g., prioritization of HR focus) rely on inference from limited evidence. Future intelligence confirming campaign timelines, precise tool versions, and confirmed infrastructure would raise confidence.
No campaigns linked yet.
No observed data linked yet.
36
Techniques
75
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics