Also known as: CL-STA-1062, deployed against government entities, tracked as, Flax, Flax Typhoon, BokBot
UAT‑7237 is a Chinese‑speaking threat actor that has been operating for over two years against Taiwanese web hosting providers, government ministries, and various critical infrastructure sectors such as energy, utilities and defense. The group combines open‑source tools with bespoke components—most notably the SoundBill shellcode loader, which encapsulates arbitrary payloads like Cobalt Strike—and a suite of VPN and remote‑desktop services to maintain persistence and anonymity. Initial access is commonly achieved through ASPX web shells deployed on compromised web applications. From there, the actors leverage L0L reconnaissance tools such as SharpWMI and WMICmd for system enumeration and employ Mimikatz for credential dumping. Privilege escalation is achieved through JuicyPotato scripts that modify UAC settings in the registry. Persistence is secured through Hard‑coded SoftEther VPN servers and client configurations with Simplified Chinese language settings, alongside long‑lived RDP sessions. The attackers also drop additional backdoors (e.g., TinyRCT) delivered via RAR archives, enabling remote command execution, screenshot capture, and file exfiltration. Exfiltration often occurs over HTTP/HTTPS using cURL to transmit query results or database dumps to attacker‑controlled IPs. The actor’s operational tempo demonstrates a preference for stealth, living‑off‑the‑land techniques, and modular tooling that allows rapid adaptation to new targets while maintaining covert footholds.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT‑7237 (alias CL‑STA‑1062, Flax) is a sophisticated Chinese‑speaking APT active since at least 2022 that targets Taiwanese and Southeast Asian government and critical‑infrastructure entities through web infrastructure exploitation. The group uses a hybrid toolkit of custom shellcode loaders, VPN persistence, and living‑off‑the‑land reconnaissance to achieve long‑term footholds. It focuses on credential theft, lateral movement via RDP/SoftEther VPN, and exfiltration of database contents.
Goals & Targeting
UAT‑7237 seeks sustained access to target networks to harvest sensitive information—particularly credentials and database contents—and establish persistent command channels. The group focuses on government and critical infrastructure within Taiwan and China, aiming to exploit publicly visible web applications and internal network services such as RDP and VPN. By embedding themselves into the network’s normal traffic patterns and using native Windows tools (WMI, PowerShell) for discovery, the actors minimize detection while maximizing the breadth of data exfiltration.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first activity in early 2022, UAT‑7237 has maintained active campaigns against Taiwanese web hosts and government systems for more than two years. The actor demonstrates an ability to quickly install a VPN server (softEther) that remains operational for extended periods, signalling long‑term persistence objectives. Victims are typically small‑to‑midscale institutions where internal access controls are weaker, enabling exploitation of RDP and local administrator accounts after initial credential theft. Notable operations include the successful deployment of a SoftEther VPN over two years and consistent use of web shell callbacks to orchestrate database dumps.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly available intelligence from a single source and reported observations, providing moderate confidence in identified tactics, techniques, and tools. However, gaps exist regarding the group’s origins, full geographic scope beyond Taiwan, precise timeline of operations, and evolution of toolset over time. Further evidence such as forensic artefacts or corroborating reports would increase confidence.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics