Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-5918

Also known as: tracked as

Description

UAT‑5918 operates as a sophisticated APT that primarily targets Taiwanese entities in the telecommunications, healthcare, and IT domains. Initial access is typically achieved by exploiting N‑day vulnerabilities in public‑facing web and application servers; once inside, the actors deploy custom or widely available web shells such as Chopper to maintain persistence across exposed sub‑domains. The group’s operations are heavily tool‑centric. They leverage open‑source reconnaissance utilities (FRPC, FScan, NetSpy) to map the victim network and identify privileged accounts. Credential harvesting is performed through well‑known dumping tools like Mimikatz and LaZagne, as well as browser credential stealers, followed by the creation of new administrative users to expand lateral movement. For pivoting they use RDP, WMIC, PowerShell remoting, and Impacket. Data exfiltration often involves backing up databases with SQLCMD.exe, while persistence is also reinforced through disabling Microsoft Defender scanning on working directories and deploying reverse Meterpreter shells or custom backdoors (e.g., LONGLEASH, DOGLEASH). The actor consistently exhibits defense‑evading tactics such as obfuscation of files and use of well‑known CVE identifiers to exploit unpatched systems.

Goals & Targeting

Targeted Sectors

Critical infrastructure
Government
Telecommunications
Healthcare
Defense
Information technology
Utilities

Targeted Countries / Regions

TW
CN
US
GB
DE
IT
IR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

UAT‑5918 is an advanced persistent threat that focuses on Taiwan’s critical infrastructure—especially telecommunications, healthcare and IT sectors—and exploits unpatched web servers to establish long‑term footholds. The group deploys a mix of commercially available and open‑source tools for credential harvesting, lateral movement, and exfiltration, while frequently disabling Microsoft Defender and creating new admin accounts for persistence. Their tactics mirror other Chinese state-sponsored actors and indicate an emphasis on stealthy, financially motivated data theft.

Goals & Targeting

UAT‑5918’s overarching objective appears to be sustained financial gain through the theft of sensitive information—particularly customer data, credentials and proprietary technology—from critical infrastructure providers. By embedding persistent web shells and creating legitimate admin accounts they can access a wide array of assets over long horizons, enabling incremental data exfiltration that is hard for defenders to detect. Their focus on publicly exposed servers suggests a strategy of low‑cost high‑reward intrusion points, while the use of well‑known exploitation techniques indicates reliance on readily available tooling rather than bespoke malware development. Strategically, the group targets high-value sectors in Taiwan and occasionally neighboring countries such as China, the U.S., Germany, Italy, the UK and Iran. These regions likely offer access to valuable industrial or personal data that can be monetized through resale or leverage.

Enhanced Description

Key Capabilities

  • Deploying and maintaining web shells on exposed sub‑domains and servers
  • Exploiting unpatched N‑day vulnerabilities in public‑facing web and application servers for initial access
  • Using open‑source network reconnaissance tools (FRPC, FScan, NetSpy) to map victim networks
  • Harvesting credentials from local accounts, domain controllers (NTDS) and web browsers
  • Creating new administrative user accounts for persistence and lateral movement
  • Lateral movement via RDP, WMIC PowerShell remoting and Impacket
  • Dumping registry hives for credential extraction
  • Disabling Microsoft Defender scanning on working directories
  • Using reverse Meterpreter shells for persistent access
  • Backing up databases with SQLCMD.exe to exfiltrate data

MITRE ATT&CK Tactics

Persistence
Credential Access
Lateral Movement
Discovery
Initial Access
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1003
T1003.002
T1059.001
T1047
T1021.001
T1190
T1069
T1082
T1046
T1112
T1136.001
T1016.001
T1555.005
T1021.004
T1078
T1027.013
T1218
T1195.002

Software / Tooling

FRPC
FScan
In‑Swor
Earthworm
Neo-reGeorg
Mimikatz
LaZagne
SNetCracker
PortBrute
NetSpy
Chopper web shell
JuicyPotato
Metasploit
WMIC
PowerShell
Impacket
PuTTY pscp
Meterpreter
Browser credential stealers
SQLCMD.exe
DOGLEASH backdoor
JARLEASH backdoor
SHORTLEASH
LONGLEASH
Expand
Cobalt
WmiExec
Matrix
Hook
Nexus
Interception
systemd
Custom malware
Open‑source tools
Leash
TriBack Loader
Process Hollowing
AppDomainManager
Group Policy
Windows Command Shell
BITS
Web Shell
Trojan
UAT-8302
MySQL
MSBuild

Campaigns & Victims

Since at least 2023, UAT‑5918 has consistently targeted critical infrastructure operators in Taiwan, exploiting publicly exposed web assets for initial footholds. Their operational tempo appears moderate but persistent, frequently re‑deploying web shells and leveraging shared tooling with the related UAT‑7810 group. Victims span telecommunications towers, hospital networks, financial IT services and utility control systems—all of which require frequent internet exposure. The group’s attack pattern shows a blend of automated reconnaissance, opportunistic exploitation of known CVEs, and manual post‑compromise data exfiltration through SQL backups. Notable past operations underline their focus on credential theft and lateral movement; in several documented incursions they disabled Defender scanning and created multiple new admin accounts to sidestep detection. While explicit ties to a nation-state remain unconfirmed due to the lack of attribution signals, the TTP overlap with known Chinese actors suggests potential state sponsorship or ideological alignment. Overall, UAT‑5918 demonstrates disciplined persistence, a modular toolset, and an emphasis on stealthy data extraction in high-value sectors.

IOC Patterns

  • Web shell upload and persistence in web roots
  • Registry hive dump / NTDS extraction for credential leakage
  • Creation of new administrative user accounts
  • RDP and PowerShell remoting usage for lateral movement
  • Execution of open‑source reconnaissance utilities (e.g., FRPC, FScan)
  • Deployment of credential‑dumping tools (Mimikatz, LaZagne, browser stealers)
  • Use of known CVE identifiers in exploitation
  • IP addresses used as command‑and‑control hosts

Recommended Actions

  • Patch all web and application servers promptly to mitigate N‑day exploits
  • Detect and block web shell indicators; monitor anomalous files in web roots
  • Monitor for, detect, or block execution of credential dumping tools (Mimikatz, LaZagne)
  • Restrict and harden RDP access; enforce MFA and least privilege policies
  • Ensure Microsoft Defender remains enabled and cannot be disabled by policy
  • Implement monitoring for WMIC/Impacket execution anomalies
  • Deploy privileged account monitoring to detect unauthorized admin account creation

Suggested Tags

APT
Taiwan critical infrastructure
Web shell
Credential dumping
RDP lateral movement
Mimikatz
FRPC
FScan
In‑Swor
UAT-5918
Vulnerability exploitation
Defense evasion
Microsoft Defender disable
Remote access tools
CVE-based attacks
SQLCMD backup extraction
Telecommunications
Healthcare
IT sectors

Confidence Assessment

The analysis is based on two primary publicly available sources and aggregated TTP evidence, providing a moderate to high level of confidence in the core capabilities such as web shell deployment, credential dumping, and lateral movement via RDP/WMIC. However, gaps remain regarding the actor’s exact origin, full persistence mechanisms beyond web shells, potential supply‑chain attacks, and detailed command‑and‑control infrastructure. Additional sightings or technical reports would strengthen attribution certainty and allow finer mapping of the group’s tool chain.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 7 Domain 3 Filename 10

References

  1. attack.mitre.org — Cited by web research for: Interception
  2. blog.talosintelligence.com — Cited by web research for: PowerShell
  3. blog.talosintelligence.com — Cited by web research for: ShortLeash
  4. unit42.paloaltonetworks.com — Cited by web research for: phishing
  5. https://malpedia.caad.fkie.fraunhofer.de/actor/uat-5918 — Cited by AI analysis.

Intel Summary

18

Techniques

59

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

APT
Healthcare Targeting
Critical Infrastructure
Phishing
Backdoor / C2
Data Exfiltration
Espionage
Taiwan
Telecommunications
Healthcare
IT Sector
Taiwan critical infrastructure
Web shell
Credential dumping
RDP lateral movement
Mimikatz
FRPC
FScan
In‑Swor
UAT-5918
Vulnerability exploitation
Defense evasion
Microsoft Defender disable
Remote access tools
CVE-based attacks
SQLCMD backup extraction
IT sectors

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.