Also known as: APT28, tracked as, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, CHAR, Olalampo, Storm-0842, Red Sandstorm, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, CL-STA-0043, APT27, Winnti, Mustang Panda, DUNE
UAT-8837 is a sophisticated China-linked APT group exploiting critical zero-day vulnerabilities, such as CVE-2025-53690 in the Sitecore platform, to achieve remote code execution and deploy the WeepSteel backdoor for espionage and data exfiltration. The group targets high-value enterprise and government sectors, focusing on public-facing applications to gain initial access and conducting stealthy reconnaissance. UAT-8837 employs techniques like privilege escalation by creating administrative accounts and is linked to targeted intrusions aimed at credential harvesting and internal reconnaissance.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT-8837 is a sophisticated China-linked APT group exploiting critical zero-day vulnerabilities to achieve remote code execution and deploy WeepSteel backdoor for espionage and data exfiltration. The group targets high-value enterprise and government sectors, focusing on public-facing applications, employs stealthy reconnaissance tactics, and maintains long-term access to victim networks. UAT-8837's activities suggest a focus on credential harvesting and internal network exploration.
Goals & Targeting
UAT-8837's strategic objectives appear to focus on espionage and data theft from high-value enterprise and government sectors. The actor's targeting of public-facing applications underscores a focus on gaining initial access points, potentially to facilitate larger campaigns or exfiltrate sensitive information. The group's sustained presence in targeted networks suggests an intent to maintain long-term access for intelligence gathering purposes.
Enhanced Description
UAT-8837 is identified as a highly sophisticated state-sponsored Advanced Persistent Threat (APT) group with suspected ties to China. The actor has demonstrated the ability to exploit zero-day vulnerabilities, such as CVE-2025-53690 in the Sitecore platform, which enables remote code execution and deployment of WeepSteel, a custom backdoor used for espionage and data exfiltration. UAT-8837 targets high-value enterprise and government sectors, focusing on public-facing applications to gain initial access while maintaining operational stealth through advanced reconnaissance techniques. The group has been observed creating administrative accounts to escalate privileges and harvest credentials within targeted networks.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
UAT-8837's campaign patterns focus on high-value targets, with a preference for enterprise and government sectors. The group is known to leverage zero-day exploits and long-term access frameworks, suggesting a patient and methodical approach to achieving its objectives. Notable past operations have included targeted intrusions aiming at credential harvesting and internal network exploration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the assessment of UAT-8837 is moderate, as some details about the group remain unclear or unverified. While its China-linked nature and use of zero-day exploits are well-documented, additional specifics on targeting sectors and countries, as well as exact motivation, could further refine the analysis.
No campaigns linked yet.
No observed data linked yet.
25
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics