Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-8837

Also known as: APT28, tracked as, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, Fancy Bear, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, telecom entities, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, CHAR, Olalampo, Storm-0842, Red Sandstorm, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, MuddyWater, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, CL-STA-0043, APT27, Winnti, Mustang Panda, DUNE

Description

UAT-8837 is a sophisticated China-linked APT group exploiting critical zero-day vulnerabilities, such as CVE-2025-53690 in the Sitecore platform, to achieve remote code execution and deploy the WeepSteel backdoor for espionage and data exfiltration. The group targets high-value enterprise and government sectors, focusing on public-facing applications to gain initial access and conducting stealthy reconnaissance. UAT-8837 employs techniques like privilege escalation by creating administrative accounts and is linked to targeted intrusions aimed at credential harvesting and internal reconnaissance.

Goals & Targeting

Targeted Sectors

Critical infrastructure
Government
Financial services
Energy
Manufacturing
Transportation
Defense
Telecommunications
Education
Construction
Maritime
Aerospace
Healthcare
Retail
Aviation
Non profit
Utilities
Chemical
Nuclear
Media
Mining
Pharmaceutical

Targeted Countries / Regions

CN
RU
US
PL
AE
RO
KZ
UA
BR
IL
KR
IN
TR
PK
GB
VN
JP
KP
BY
NG
SA
MX
ES
IT
DE
NL

AI Analysis

· 1 week ago

Executive Summary

UAT-8837 is a sophisticated China-linked APT group exploiting critical zero-day vulnerabilities to achieve remote code execution and deploy WeepSteel backdoor for espionage and data exfiltration. The group targets high-value enterprise and government sectors, focusing on public-facing applications, employs stealthy reconnaissance tactics, and maintains long-term access to victim networks. UAT-8837's activities suggest a focus on credential harvesting and internal network exploration.

Goals & Targeting

UAT-8837's strategic objectives appear to focus on espionage and data theft from high-value enterprise and government sectors. The actor's targeting of public-facing applications underscores a focus on gaining initial access points, potentially to facilitate larger campaigns or exfiltrate sensitive information. The group's sustained presence in targeted networks suggests an intent to maintain long-term access for intelligence gathering purposes.

Enhanced Description

UAT-8837 is identified as a highly sophisticated state-sponsored Advanced Persistent Threat (APT) group with suspected ties to China. The actor has demonstrated the ability to exploit zero-day vulnerabilities, such as CVE-2025-53690 in the Sitecore platform, which enables remote code execution and deployment of WeepSteel, a custom backdoor used for espionage and data exfiltration. UAT-8837 targets high-value enterprise and government sectors, focusing on public-facing applications to gain initial access while maintaining operational stealth through advanced reconnaissance techniques. The group has been observed creating administrative accounts to escalate privileges and harvest credentials within targeted networks.

Key Capabilities

  • Exploitation of critical zero-day vulnerabilities
  • Deployment of custom backdoors (e.g., WeepSteel)
  • Privilege escalation via administrative account creation
  • Credential harvesting and internal reconnaissance
  • Stealthy network exfiltration techniques

MITRE ATT&CK Tactics

Initial Access
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery

Software / Tooling

WeepSteel backdoor

Campaigns & Victims

UAT-8837's campaign patterns focus on high-value targets, with a preference for enterprise and government sectors. The group is known to leverage zero-day exploits and long-term access frameworks, suggesting a patient and methodical approach to achieving its objectives. Notable past operations have included targeted intrusions aiming at credential harvesting and internal network exploration.

IOC Patterns

  • Exploitation of CVE-2025-53690 in Sitecore
  • Use of WeepSteel backdoor
  • Creation of administrative accounts for privilege escalation
  • Signs of network reconnaissance and lateral movement

Recommended Actions

  • Implement robust zero-day protection measures.
  • Monitor for anomaly detection alerts related to public-facing applications.
  • Conduct regular credential audits and implement multi-factor authentication.
  • Enhance network segmentation to limit lateral movement.
  • Use threat intelligence feeds to detect UAT-8837-related TTPs.

Suggested Tags

APT
espionage
government
enterprise
zero-day

Confidence Assessment

The confidence in the assessment of UAT-8837 is moderate, as some details about the group remain unclear or unverified. While its China-linked nature and use of zero-day exploits are well-documented, additional specifics on targeting sectors and countries, as well as exact motivation, could further refine the analysis.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. attack.mitre.org — Cited by web research for: T1548
  3. attack.mitre.org — Cited by web research for: Interception
  4. unit42.paloaltonetworks.com — Cited by web research for: NET-STAR
  5. blog.talosintelligence.com — Cited by web research for: SharpHound
  6. www.paloaltonetworks.com — Cited by web research for: lsass.exe
  7. fortiguard.fortinet.com — Cited by web research for: outbreak.Find

Intel Summary

25

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

APT
Phishing
Zero-Day Exploitation
Backdoor / C2
Data Exfiltration
Government Targeting
espionage
government
enterprise
zero-day

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.