Also known as: tracked as
UAT‑5918 operates as a sophisticated APT that primarily targets Taiwanese entities in the telecommunications, healthcare, and IT domains. Initial access is typically achieved by exploiting N‑day vulnerabilities in public‑facing web and application servers; once inside, the actors deploy custom or widely available web shells such as Chopper to maintain persistence across exposed sub‑domains. The group’s operations are heavily tool‑centric. They leverage open‑source reconnaissance utilities (FRPC, FScan, NetSpy) to map the victim network and identify privileged accounts. Credential harvesting is performed through well‑known dumping tools like Mimikatz and LaZagne, as well as browser credential stealers, followed by the creation of new administrative users to expand lateral movement. For pivoting they use RDP, WMIC, PowerShell remoting, and Impacket. Data exfiltration often involves backing up databases with SQLCMD.exe, while persistence is also reinforced through disabling Microsoft Defender scanning on working directories and deploying reverse Meterpreter shells or custom backdoors (e.g., LONGLEASH, DOGLEASH). The actor consistently exhibits defense‑evading tactics such as obfuscation of files and use of well‑known CVE identifiers to exploit unpatched systems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT‑5918 is an advanced persistent threat that focuses on Taiwan’s critical infrastructure—especially telecommunications, healthcare and IT sectors—and exploits unpatched web servers to establish long‑term footholds. The group deploys a mix of commercially available and open‑source tools for credential harvesting, lateral movement, and exfiltration, while frequently disabling Microsoft Defender and creating new admin accounts for persistence. Their tactics mirror other Chinese state-sponsored actors and indicate an emphasis on stealthy, financially motivated data theft.
Goals & Targeting
UAT‑5918’s overarching objective appears to be sustained financial gain through the theft of sensitive information—particularly customer data, credentials and proprietary technology—from critical infrastructure providers. By embedding persistent web shells and creating legitimate admin accounts they can access a wide array of assets over long horizons, enabling incremental data exfiltration that is hard for defenders to detect. Their focus on publicly exposed servers suggests a strategy of low‑cost high‑reward intrusion points, while the use of well‑known exploitation techniques indicates reliance on readily available tooling rather than bespoke malware development. Strategically, the group targets high-value sectors in Taiwan and occasionally neighboring countries such as China, the U.S., Germany, Italy, the UK and Iran. These regions likely offer access to valuable industrial or personal data that can be monetized through resale or leverage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since at least 2023, UAT‑5918 has consistently targeted critical infrastructure operators in Taiwan, exploiting publicly exposed web assets for initial footholds. Their operational tempo appears moderate but persistent, frequently re‑deploying web shells and leveraging shared tooling with the related UAT‑7810 group. Victims span telecommunications towers, hospital networks, financial IT services and utility control systems—all of which require frequent internet exposure. The group’s attack pattern shows a blend of automated reconnaissance, opportunistic exploitation of known CVEs, and manual post‑compromise data exfiltration through SQL backups. Notable past operations underline their focus on credential theft and lateral movement; in several documented incursions they disabled Defender scanning and created multiple new admin accounts to sidestep detection. While explicit ties to a nation-state remain unconfirmed due to the lack of attribution signals, the TTP overlap with known Chinese actors suggests potential state sponsorship or ideological alignment. Overall, UAT‑5918 demonstrates disciplined persistence, a modular toolset, and an emphasis on stealthy data extraction in high-value sectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on two primary publicly available sources and aggregated TTP evidence, providing a moderate to high level of confidence in the core capabilities such as web shell deployment, credential dumping, and lateral movement via RDP/WMIC. However, gaps remain regarding the actor’s exact origin, full persistence mechanisms beyond web shells, potential supply‑chain attacks, and detailed command‑and‑control infrastructure. Additional sightings or technical reports would strengthen attribution certainty and allow finer mapping of the group’s tool chain.
No campaigns linked yet.
No observed data linked yet.
18
Techniques
59
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics