Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UTA0388

Also known as: tracked as, Bluenoroff, cryptocurrency businesses, ATMs, Andariel, Hidden Cobra, Diamond Sleet, defense, IT organizations, Jade Sleet, cryptocurrency companies, Emerald Sleet, Kimsuky, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, manufacturing, the custom Voldemort ba, Store.vbs, TA415, Sapphire Sleet, Citrine Sleet, Onyx Sleet, ZINC, UNC4899, THALLIUM, HealthKick, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, ScrambleCross, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, PLUTONIUM

Description

UTA0388 operates as a state‑aligned threat actor with a primary motivation of monetary gain while simultaneously advancing Chinese geopolitical objectives. The actor employs sophisticated spear‑phishing campaigns that leverage large language models (LLMs) to craft highly authentic, multilingual emails—including English, Simplified Chinese, Japanese, French, and German—to build rapport before delivering malicious archives. The payloads are often distributed via cloud hosts—GitHub, Google Drive, or the actor’s own servers—and may contain backdoors such as GOVERSHELL, a Go‑based implant, or the Voldemort backdoor family. UTA0388 also uses environmental keying: cryptographic checks on host drivers and virtualization layers to tailor execution to legitimate production environments. Beyond initial compromise, the group demonstrates advanced persistence tactics by deploying malicious AWS AMIs and Docker images, deleting prior artifacts, and manipulating system services and registry settings. Its use of legitimate third‑party cloud accounts for command-and-control (C2) and exfiltration through popular web services shows an awareness of defensive analytics and efforts to blur attribution. Overall, UTA0388 showcases a hybrid skill set that marries classic phishing with automation, cloud deception, and context-aware malware execution—making it a significant threat to both public‑sector and high‑profile private sector targets.

Goals & Targeting

Targeted Sectors

Financial services
Media
Government
Defense
Manufacturing
Education
Information technology
Think tank
Aerospace

Targeted Countries / Regions

CN
TW
US
KP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

UTA0388 is a China‑aligned APT that exploits spear‑phishing and LLM‑generated emails to deliver the GOVERSHELL malware family and other backdoors such as Voldemort, Ghost RAT, and Cobalt Strike. The group combines traditional social engineering with advanced cloud‑based command-and-control and container image backdos to maintain persistence across financial, defense, and technology sectors worldwide. Key attacks target Taiwanese semiconductor companies, Asian government institutions, and major North American financial firms, using localized languages and tailored environmental checks to evade defenders.

Goals & Targeting

The actor’s strategic objectives appear dual: first, generate financial profit through ransomware, data monetization, or illicit cryptocurrency operations; second, facilitate state‑level intelligence gathering by compromising critical infrastructure in geopolitically sensitive regions such as Taiwan. Their focus on defense, aerospace, and semiconductor sectors indicates an intent to collect proprietary technology or disrupt supply chains that would benefit Chinese strategic interests. Targeting high-profile organizations also serves to elevate the actor’s visibility within a broader cyber‑statecraft narrative, potentially allowing for deniability while projecting power. The use of multi‑language phishing and localized environmental checks suggests sophisticated threat actors aligned with national security agendas.

Enhanced Description

Key Capabilities

  • Spear‑phishing using fabricated corporate identities
  • Multi‑language (English, Chinese, Japanese, French, German) email creation via LLMs
  • Rapport‑building iterative phishing prior to payload injection
  • Distributing malicious archives (.zip/.rar) that host executables
  • Hosting phishing portals on cloud services or attacker infrastructure
  • Abusing legitimate third‑party accounts for command & control and exfiltration
  • Developing custom malware components (droppers, backdoors, packers, infected removable media)
  • Enumerating local device drivers to detect defenses and virtualization
  • Incorporating environmental keying with cryptographic guards based on target environment
  • Deploying malicious cloud/container images for persistence in AWS, GCP, Docker
  • Re‑compressing/re‑duplicating malware copies for obfuscation
  • Deleting files to remove forensic evidence
  • Establishing long-term control via backdoors (GOVERSHELL, Voldemort, Ghost RAT)
  • Using spearphishing attachments and links disguised as images

MITRE ATT&CK Tactics

Initial Access
Command and Control
Exfiltration
Persistence
Defense Evasion
Execution

ATT&CK Techniques

T1037
T1059
T1070.004
T1071
T1071.004
T1078
T1082
T1087
T1092
T1098
T1105
T1110
T1111 (not listed but likely used)
T1115
T1119
T1123
T1020
T1027
T1048.003
T1059
T1064 (not listed)
T1086 (not listed)
T1185
T1217
T1543
T1547
T1555
T1557
T1612
T1583
T1580
T1584
T1586
T1595
T1609
T1613
T1619
T1650
T1651
T1659
T1671
T1748 (not listed)

Software / Tooling

GOVERSHELL
Ghost RAT
Cobalt Strike
Voldemort backdoor
POOLRAT
RustBucket
SUGARLOADER
KANDYKORN
HLOADER
netsh
PowerShell

Campaigns & Victims

UTA0388 conducts large‑scale, highly coordinated spear‑phishing campaigns that span multiple languages and leverage LLMs for automated content generation. The actor often uses cloud platforms (GitHub, Google Drive) to host malicious archives or command‑and‑control endpoints, sometimes hijacking legitimate third‑party accounts. Persistence is frequently achieved through backdoored container images or AMI snapshots that survive reboots or system reinstalls. While the exact operational tempo fluctuates, recent operations noted a March–June 2025 focus on Taiwanese semiconductor firms, deploying Cobalt Strike and Voldemort-based payloads. Victims are typically high‑profile organizations in finance, defense, aerospace, and technology sectors that hold strategic or economic value for China. Notably, UTA0388’s campaigns also exhibit environmental keying tactics—cryptographically checking host drivers and virtualization status—to bypass sandboxing and dynamic analysis tools. Additionally, the actor demonstrates advanced exfiltration techniques by abusing cloud storage services and popular social platforms for data transport. Overall, the pattern points to a sophisticated, state‑aligned operation that blends financial incentives with broader geopolitical goals.

IOC Patterns

  • Phishing emails containing malicious links disguised as images or attachments
  • Remote hosted archives (.zip/.rar) containing executable payloads
  • Hosting phishing landing pages on cloud services or actor-controlled domains
  • Use of legitimate third‑party cloud accounts for C2 or exfiltration
  • Malicious DLLs/EXEs such as spoolsv.exe, user32.dll, and custom loaders

Recommended Actions

  • Enhance spear‑phishing awareness training focused on image‑link indicators and LLM‑crafted content
  • Implement enterprise email gateways with URL reputation checks, attachment sandboxing, and archive filtering
  • Block or quarantine archives (.zip/.rar) unless delivered by trusted sources
  • Enforce multi‑factor authentication across all administrative and cloud accounts to mitigate credential compromise
  • Monitor and block domains used for phishing deployments; maintain an up‑to‑date domain threat list
  • Deploy linguistic analysis tools to detect AI‑generated phishing content and suspicious language patterns
  • Audit login activity on popular web services (GitHub, Twitter, Google Drive) and restrict unauthorized access
  • Implement endpoint detection that flags file deletion, unauthorized copying, and anomalous device driver enumeration
  • Maintain comprehensive logs of outbound command-and-control traffic; correlate with known attacker IPs and domains
  • Block malicious domains and URLs associated with Ghost RAT, Cobalt Strike, Voldemort backdoor
  • Limit the use of cloud storage buckets for exfiltration except when verified and monitored
  • Enable container security monitoring to detect backdoored images or AMIs that could be used for persistence

Suggested Tags

APT
China‑aligned
State-sponsored
Spearphishing
LLM-assisted phishing
Phishing campaigns
Malware delivery via archive
Targeting Asian governments
Taiwan focus
Rapport-building phishing
ChineseStateActor
LLMCampaigns
WebServiceC2
Exfiltration over web services
CloudAccountCompromise
EnvironmentalKeying
ContainerImageBackdooring
GOVERSHELL
Taiwanese semiconductor sector
Cobalt Strike
Ghost RAT
Voldemort backdoor
Backdoor

Confidence Assessment

Confidence in the core attribution of UTA0388 to a China‑aligned state actor is moderate-to-high based on consistent TTPs, language use, and public reports. Information gaps remain regarding precise operational tempo, full geographic reach (especially presence beyond CN/TW/US/KP), and evolution of their malicious toolset over time—many data points derive from static malware samples and limited reporting. Continuous monitoring of cloud infrastructure, new email campaign content, and changes in backdoor capabilities will help refine threat profiles.

ATT&CK Techniques

Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Email Address 1 Domain 7 SHA-256 Hash 2 Filename 3 IPv4 Address 6 URL 1

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Bluenoroff
  2. attack.mitre.org — Cited by web research for: services
  3. www.proofpoint.com — Cited by web research for: manufacturing
  4. www.volexity.com — Cited by web research for: PowerShell
  5. www.cypro.se — Cited by web research for: contact@cypro.se
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.ghost_rat — Cited by AI analysis.

Intel Summary

51

Techniques

43

Tools

0

Campaigns

39

IOCs

0

Observed Data

14

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
State-sponsored
Geopolitical espionage
China-aligned
China‑aligned
Spearphishing
LLM-assisted phishing
Phishing campaigns
Malware delivery via archive
Targeting Asian governments
Taiwan focus
Rapport-building phishing
ChineseStateActor
LLMCampaigns
WebServiceC2
Exfiltration over web services
CloudAccountCompromise
EnvironmentalKeying
ContainerImageBackdooring
GOVERSHELL
Taiwanese semiconductor sector
Cobalt Strike
Ghost RAT
Voldemort backdoor
Backdoor

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.