Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-7237

Also known as: CL-STA-1062, deployed against government entities, tracked as, Flax, Flax Typhoon, BokBot

Description

UAT‑7237 is a Chinese‑speaking threat actor that has been operating for over two years against Taiwanese web hosting providers, government ministries, and various critical infrastructure sectors such as energy, utilities and defense. The group combines open‑source tools with bespoke components—most notably the SoundBill shellcode loader, which encapsulates arbitrary payloads like Cobalt Strike—and a suite of VPN and remote‑desktop services to maintain persistence and anonymity. Initial access is commonly achieved through ASPX web shells deployed on compromised web applications. From there, the actors leverage L0L reconnaissance tools such as SharpWMI and WMICmd for system enumeration and employ Mimikatz for credential dumping. Privilege escalation is achieved through JuicyPotato scripts that modify UAC settings in the registry. Persistence is secured through Hard‑coded SoftEther VPN servers and client configurations with Simplified Chinese language settings, alongside long‑lived RDP sessions. The attackers also drop additional backdoors (e.g., TinyRCT) delivered via RAR archives, enabling remote command execution, screenshot capture, and file exfiltration. Exfiltration often occurs over HTTP/HTTPS using cURL to transmit query results or database dumps to attacker‑controlled IPs. The actor’s operational tempo demonstrates a preference for stealth, living‑off‑the‑land techniques, and modular tooling that allows rapid adaptation to new targets while maintaining covert footholds.

Goals & Targeting

Targeted Sectors

Government
Critical infrastructure
Energy
Telecommunications
Utilities
Education
Healthcare
Defense

Targeted Countries / Regions

TW
CN

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 hour ago

Executive Summary

UAT‑7237 (alias CL‑STA‑1062, Flax) is a sophisticated Chinese‑speaking APT active since at least 2022 that targets Taiwanese and Southeast Asian government and critical‑infrastructure entities through web infrastructure exploitation. The group uses a hybrid toolkit of custom shellcode loaders, VPN persistence, and living‑off‑the‑land reconnaissance to achieve long‑term footholds. It focuses on credential theft, lateral movement via RDP/SoftEther VPN, and exfiltration of database contents.

Goals & Targeting

UAT‑7237 seeks sustained access to target networks to harvest sensitive information—particularly credentials and database contents—and establish persistent command channels. The group focuses on government and critical infrastructure within Taiwan and China, aiming to exploit publicly visible web applications and internal network services such as RDP and VPN. By embedding themselves into the network’s normal traffic patterns and using native Windows tools (WMI, PowerShell) for discovery, the actors minimize detection while maximizing the breadth of data exfiltration.

Enhanced Description

Key Capabilities

  • Deploy ASPX web shells for initial access
  • Use SoftEther VPN client/server and VNT for lateral movement and persistence
  • Credential dumping with Mimikatz
  • Database exfiltration via MSSQL queries
  • Outbound enumeration using cURL to attacker IPs
  • Drop RAR archives containing backdoors (TinyRCT)
  • Remote command execution and file exfiltration
  • Screenshot capture through TinyRCT
  • Custom shellcode loader SoundBill for Cobalt Strike delivery
  • Privilege escalation via JuicyPotato and UAC disabling
  • Living‑off‑the‑land reconnaissance with SharpWMI/WMICmd
  • Network scanning
  • Configure softEther VPN client language to Simplified Chinese

MITRE ATT&CK Tactics

Persistence
Privilege Escalation
Credential Access
Discovery
Command and Control
Defense Evasion

ATT&CK Techniques

T1574.014
T1003
T1068
T1112
T1021.004
T1047
T1071.001
T1018

Software / Tooling

SoftEther VPN
SoftEther VPN Client
Mimikatz
TinyRCT
PerfWatson2.exe
SoundBill
Cobalt Strike
JuicyPotato
SharpWMI
WMICmd
VNT

Campaigns & Victims

Since its first activity in early 2022, UAT‑7237 has maintained active campaigns against Taiwanese web hosts and government systems for more than two years. The actor demonstrates an ability to quickly install a VPN server (softEther) that remains operational for extended periods, signalling long‑term persistence objectives. Victims are typically small‑to‑midscale institutions where internal access controls are weaker, enabling exploitation of RDP and local administrator accounts after initial credential theft. Notable operations include the successful deployment of a SoftEther VPN over two years and consistent use of web shell callbacks to orchestrate database dumps.

IOC Patterns

  • domain
  • file
  • ip-v4
  • hash-sha256

Recommended Actions

  • Monitor for ASPX web shells on public webapps
  • Audit installation of SoftEther VPN components and RAR archives
  • Block execution and monitoring of Mimikatz binaries
  • Detect registry changes that disable UAC and modify WMI settings
  • Enforce MFA on all RDP and VPN access points
  • Inspect outbound cURL traffic to attacker‑controlled IP addresses
  • Block suspicious HTTPS C2 domains such as lambda‑based AWS endpoints
  • Deploy intrusion detection signatures for SoundBill shellcode loaders
  • Log WMI activity extensively
  • Restrict and monitor RDP sessions with strict session timeout policies

Suggested Tags

UAT-7237
CL-STA-1062
TinyRCT
APT
Chinese-speaking
Targeted Attacks
Web Infrastructure
CobaltStrike
SoundBill
Mimikatz
JuicyPotato
VPN Persistence
Credential Dumping
Privilege Escalation
Long‑term Persistence
SoftEther
Chinese-language configuration

Confidence Assessment

The analysis is based on publicly available intelligence from a single source and reported observations, providing moderate confidence in identified tactics, techniques, and tools. However, gaps exist regarding the group’s origins, full geographic scope beyond Taiwan, precise timeline of operations, and evolution of toolset over time. Further evidence such as forensic artefacts or corroborating reports would increase confidence.

ATT&CK Techniques

Command & Control
1 technique
Credential Access
1 technique
Defense impairment
1 technique
Discovery
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique
Stealth
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 11 Domain 4 IPv4 Address 2 SHA-256 Hash 3

References

  1. www.securityweek.com — Cited by web research for: Flax
  2. nubetia.com — Cited by web research for: Flax Typhoon
  3. attack.mitre.org — Cited by web research for: Interception
  4. unit42.paloaltonetworks.com — Cited by web research for: Web Shells
  5. blog.talosintelligence.com — Cited by web research for: PowerShell
  6. blog.talosintelligence.com — Cited by web research for: Telecommunications

Intel Summary

8

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

APT
Backdoor / C2
UAT-7237
CL-STA-1062
TinyRCT
Chinese-speaking
Targeted Attacks
Web Infrastructure
CobaltStrike
SoundBill
Mimikatz
JuicyPotato
VPN Persistence
Credential Dumping
Privilege Escalation
Long‑term Persistence
SoftEther
Chinese-language configuration

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.