Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UTG-Q-010

Also known as: the Newscaster Team, SHADOW-WATER-063, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, Paper Werewolf, 560048

Description

UTG‑Q‑010 emerged as a financially motivated threat actor from East Asia in late 2022, quickly establishing a reputation for combining phishing with targeted exploitation of legitimate system processes. Its primary focus has been the pharmaceutical sector and cryptocurrency communities, where it leverages insider knowledge of industry vulnerabilities; key operations typically begin with spear‑phishing attachments that trigger the download of a malicious DLL. The malware chain involves sideloading faultrep.dll into WerFault.exe, a common Windows error reporting program. The DLL then loads additional code—such as Pupy RAT—in memory through reflective DLL loading techniques, thereby bypassing static analysis tools. Operationally, the group has shown a preference for human‑factor attacks, notably targeting HR departments to harvest credentials and personal data that can be monetized directly or used to expand lateral movement within corporate networks. The combination of legitimate process utilization, in‑memory execution, and supply‑chain‑like delivery mechanisms allows UTG‑Q‑010 to maintain persistence across a broad global footprint, often spanning the United States, China, Europe, India, the Middle East and many other jurisdictions.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Aerospace
Media
Education
Information technology
Maritime
Manufacturing
Healthcare
Think tank
Mining
Pharmaceutical
Critical infrastructure
Chemical
Hospitality
Legal services
Nuclear
Entertainment
Food agriculture

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
RU
SA
FR
TW
CA
IL
TR
VN
AU
KZ
PK
UA
PL
NL
BY
AE
SG
IT
BR
ES
IQ
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· 12 hours ago

Executive Summary

UTG‑Q‑010 is an East Asian APT that blends cyber‑espionage with financial gain, concentrating on pharmaceutical firms and cryptocurrency users. The group exploits legitimate Windows processes (e.g., WerFault.exe) to inject malicious DLLs such as faultrep.dll and delivers the Pupy RAT through sophisticated spear‑phishing campaigns. Advanced defense evasion—including in‑memory execution and reflective DLL loading—is employed to conceal activity while exfiltrating sensitive data.

Goals & Targeting

UTG‑Q‑010’s strategic objectives blend espionage with monetary exploitation. The pharmaceutical industry is prized for its valuable intellectual property and R&D data; capturing such information can yield both intelligence value and commercial leverage. Cryptocurrency users provide direct financial pathways, enabling the group to siphon funds or sell stolen wallets without a long‑term foothold. The geographic breadth of attacks—targeting countries from the U.S. to Iran, Ukraine, Saudi Arabia and beyond—reflects an intent to collect broad geopolitical intelligence while simultaneously exploiting local industries for profit. Typical victims are mid‑to‑large organizations with high value assets in health care, finance, technology and energy; HR portals are specifically chosen because they hold a concentrated pool of credentials. The actor’s willingness to blend espionage objectives with economic attack vectors demonstrates an adaptable approach that seeks both strategic benefit and immediate financial return.

Enhanced Description

Key Capabilities

  • DLL sideloading via legitimate Windows processes (e.g., WerFault.exe)
  • In‑memory execution and reflective DLL loading
  • Spear‑phishing attachments and links
  • Employment of Pupy RAT for remote access
  • Credential dumping with tools such as Mimikatz
  • Keylogging and screen capture capabilities
  • Exfiltration over C2 channels using custom web protocols
  • Supply‑chain style delivery on compromised websites
  • Virtualization/sandbox evasion techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Defense Evasion
Discovery
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1053.005
T1113
T1056.001
T1003
T1499.001
T1204.002
T1566.002
T1566.001
T1115
T1040
T1082
T1195
T1190
T1021
T1016
T1497
T1204
T1041
T1059.001
T1547.001
T1078
T1068
T1027
T1546
T1486
T1203
T1499
T1059.003
T1189
T1134
T1111
T1071.001
T1105
T1204.001

Software / Tooling

Pupy RAT
Mimikatz
WerFault.exe (process for sideloading)
faultrep.dll (DLL payload)
Rundll32.exe (malicious use)
Cobalt Strike (potential future use)
Havoc
ELMER
Anchor

Campaigns & Victims

Since its first appearance in late 2022, UTG‑Q‑010 has maintained a steady operational tempo, deploying multi‑stage campaigns that combine spear‑phishing with legitimate process exploitation. The group’s patterns indicate targeted exploitation of HR systems to harvest credentials and internal data, followed by lateral movement via the Pupy RAT for deeper network penetration. Campaigns frequently span numerous countries within a short time frame, suggesting efficient automation pipelines and possibly shared infrastructure across different threat actor aliases. Notable elements include rapid use of weaponized VPN installers and custom domains (e.g., demo‑cloud.space) to distribute malware, as well as the reliance on both Windows Command Shell and PowerShell for execution and persistence. UTG‑Q‑010’s operations remain largely covert; however, emerging indicators point toward a shift toward more aggressive financial sub‑campaigns within the cryptocurrency arena, likely leveraging stolen wallets or credentials for direct monetary gain.

IOC Patterns

  • Spear‑phishing attachments containing malicious Word documents
  • Use of legitimate Windows processes such as WerFault.exe to sideload DLLs
  • Reflective in‑memory DLL loading techniques
  • Exfiltration via custom web protocols on domains like demo-cloud.space and TEMP.Hermit
  • Malicious use of rundll32.exe for execution
  • Domain fronts and bulletproof hosting used for command-and-control
  • Phishing emails luring cryptocurrency users with enticing links

Recommended Actions

  • Implement multi‑factor authentication across all HR portals and critical services to block credential theft. Deploy endpoint detection and response (EDR) solutions that monitor DLL injection activities, especially within trusted system processes. Enforce strict document‑execution policies and sandboxing for email attachments; use virtual machines for preview of suspicious Office files. Continuously update and patch for known Windows exploits and vulnerabilities including kernel privilege escalation flaws. Segment networks to limit lateral movement from compromised user accounts; employ least‑privilege principals especially on sensitive departmental systems. Adopt advanced telemetry (WMI, PowerShell logging) and anomaly detection to surface in‑memory execution and reflective DLL loading behaviors. Maintain an up‑to‑date threat intelligence feed for new domains, file hashes, and phishing templates associated with UTG‑Q‑010.

Suggested Tags

APT
Espionage
Financial Motive
Pharmaceutical Theft
Cryptocurrency Targeting
East Asia Origin
Phishing
Advanced Persistence

Confidence Assessment

The profile is based primarily on the provided group description and linked MITRE TTPs. While the actor’s name, aliases, and tactics are cited in multiple sources, many details—such as specific operational dates or precise victim organizations—are sparse or indirectly referenced. Consequently, confidence remains moderate: key capabilities and techniques are well‑supported, but strategic motivations (e.g., prioritization of HR focus) rely on inference from limited evidence. Future intelligence confirming campaign timelines, precise tool versions, and confirmed infrastructure would raise confidence.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. thehackernews.com — Cited by web research for: Paper Werewolf
  3. www.cyfirma.com — Cited by web research for: 560048
  4. pmc.ncbi.nlm.nih.gov — Cited by web research for: Docker

Intel Summary

36

Techniques

75

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Financial Targeting
Healthcare Targeting
Phishing
Backdoor / C2
Financially Motivated
East Asia
Pharmaceutical Industry
Cryptocurrency
Espionage
Financial Motive
Pharmaceutical Theft
Cryptocurrency Targeting
East Asia Origin
Advanced Persistence

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.