Also known as: tracked as, Bluenoroff, cryptocurrency businesses, ATMs, Andariel, Hidden Cobra, Diamond Sleet, defense, IT organizations, Jade Sleet, cryptocurrency companies, Emerald Sleet, Kimsuky, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, manufacturing, the custom Voldemort ba, Store.vbs, TA415, Sapphire Sleet, Citrine Sleet, Onyx Sleet, ZINC, UNC4899, THALLIUM, HealthKick, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, ScrambleCross, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, PLUTONIUM
UTA0388 operates as a state‑aligned threat actor with a primary motivation of monetary gain while simultaneously advancing Chinese geopolitical objectives. The actor employs sophisticated spear‑phishing campaigns that leverage large language models (LLMs) to craft highly authentic, multilingual emails—including English, Simplified Chinese, Japanese, French, and German—to build rapport before delivering malicious archives. The payloads are often distributed via cloud hosts—GitHub, Google Drive, or the actor’s own servers—and may contain backdoors such as GOVERSHELL, a Go‑based implant, or the Voldemort backdoor family. UTA0388 also uses environmental keying: cryptographic checks on host drivers and virtualization layers to tailor execution to legitimate production environments. Beyond initial compromise, the group demonstrates advanced persistence tactics by deploying malicious AWS AMIs and Docker images, deleting prior artifacts, and manipulating system services and registry settings. Its use of legitimate third‑party cloud accounts for command-and-control (C2) and exfiltration through popular web services shows an awareness of defensive analytics and efforts to blur attribution. Overall, UTA0388 showcases a hybrid skill set that marries classic phishing with automation, cloud deception, and context-aware malware execution—making it a significant threat to both public‑sector and high‑profile private sector targets.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UTA0388 is a China‑aligned APT that exploits spear‑phishing and LLM‑generated emails to deliver the GOVERSHELL malware family and other backdoors such as Voldemort, Ghost RAT, and Cobalt Strike. The group combines traditional social engineering with advanced cloud‑based command-and-control and container image backdos to maintain persistence across financial, defense, and technology sectors worldwide. Key attacks target Taiwanese semiconductor companies, Asian government institutions, and major North American financial firms, using localized languages and tailored environmental checks to evade defenders.
Goals & Targeting
The actor’s strategic objectives appear dual: first, generate financial profit through ransomware, data monetization, or illicit cryptocurrency operations; second, facilitate state‑level intelligence gathering by compromising critical infrastructure in geopolitically sensitive regions such as Taiwan. Their focus on defense, aerospace, and semiconductor sectors indicates an intent to collect proprietary technology or disrupt supply chains that would benefit Chinese strategic interests. Targeting high-profile organizations also serves to elevate the actor’s visibility within a broader cyber‑statecraft narrative, potentially allowing for deniability while projecting power. The use of multi‑language phishing and localized environmental checks suggests sophisticated threat actors aligned with national security agendas.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UTA0388 conducts large‑scale, highly coordinated spear‑phishing campaigns that span multiple languages and leverage LLMs for automated content generation. The actor often uses cloud platforms (GitHub, Google Drive) to host malicious archives or command‑and‑control endpoints, sometimes hijacking legitimate third‑party accounts. Persistence is frequently achieved through backdoored container images or AMI snapshots that survive reboots or system reinstalls. While the exact operational tempo fluctuates, recent operations noted a March–June 2025 focus on Taiwanese semiconductor firms, deploying Cobalt Strike and Voldemort-based payloads. Victims are typically high‑profile organizations in finance, defense, aerospace, and technology sectors that hold strategic or economic value for China. Notably, UTA0388’s campaigns also exhibit environmental keying tactics—cryptographically checking host drivers and virtualization status—to bypass sandboxing and dynamic analysis tools. Additionally, the actor demonstrates advanced exfiltration techniques by abusing cloud storage services and popular social platforms for data transport. Overall, the pattern points to a sophisticated, state‑aligned operation that blends financial incentives with broader geopolitical goals.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core attribution of UTA0388 to a China‑aligned state actor is moderate-to-high based on consistent TTPs, language use, and public reports. Information gaps remain regarding precise operational tempo, full geographic reach (especially presence beyond CN/TW/US/KP), and evolution of their malicious toolset over time—many data points derive from static malware samples and limited reporting. Continuous monitoring of cloud infrastructure, new email campaign content, and changes in backdoor capabilities will help refine threat profiles.
No campaigns linked yet.
No observed data linked yet.
51
Techniques
43
Tools
0
Campaigns
39
IOCs
0
Observed Data
14
Tactics