Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-9921

Also known as: UAT-9921, VoidLink Operator, highlighting how on-demand compilation, Alchimist, tracked as, ClamAV, industry-leading signature detection, Snort, delivers advanced, modular plugins, Insekt, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Winnti Umbrella, BokBot, Silence.Downloader, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

UAT-9921 has been active since 2019 and is tracked by Cisco Talos as a China‑based adversary group with significant resources and deep technical expertise. The actor introduced the VoidLink framework in 2026, a modular malware system that leverages AI‑enabled development environments (ZigLang implants and GoLang backends) to accelerate rapid weaponization of new capabilities. VoidLink is distributed through public web services—such as Google, Twitter, Dropbox, Exchange/Office365—and employs P2P mesh networking for resilient command & control. On the victim side, UAT-9921 focuses on high‑value sectors including technology, finance, defense, critical infrastructure, and manufacturing. Their operations routinely exploit software vulnerabilities (e.g., Apache Dubbo Java serialization bugs), remote service weaknesses, and Windows service binary hijacking to achieve persistence, lateral movement, and denial‑of‑service impact against network services. The group also demonstrates sophisticated use of cloud resources: they inject malicious or backdoored images into AWS, GCP, or Azure registries to maintain persistence while evading detection. Additionally, UAT-9921 employs spoofed browser and system attributes—such as HTTP User‑Agent headers—to facilitate phishing campaigns and evade security controls. Finally, the actor uses eBPF rootkits for kernel‑level persistence on Linux systems typical of IoT and critical infrastructure deployments, illustrating a blend of traditional Windows malware techniques with modern containerized and cloud‑native tactics.

Goals & Targeting

Targeted Sectors

Financial services
Media
Defense
Critical infrastructure
Manufacturing
Energy
Information technology
Utilities
Healthcare
Nuclear
Government
Critical infrastructure

Targeted Countries / Regions

UA
CN
RU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

UAT-9921 is a high‑sophistication threat actor linked to China that primarily pursues financial gain by targeting technology and financial organizations worldwide. The group operates through the modular VoidLink framework, exploiting web services for command & control, phishing, and exfiltration while maintaining persistence with local/domain accounts and cloud/container images. Their tactics include advanced exploitation of software vulnerabilities, service binary hijacking, DoS attacks, and attempts to bypass multi‑factor authentication.

Goals & Targeting

UAT-9921’s strategic objectives combine financial exploitation with opportunistic information gathering. By targeting technology and finance sectors that hold valuable intellectual property and financial assets, the group maximizes revenue potential through credential theft, ransomware, and covert exfiltration of sensitive data. Leveraging popular web services for C2 reduces traceability and allows rapid pivoting between targets across geopolitical boundaries (e.g., Ukraine, China, Russia). Their tactics reflect a preference for stealthy, long‑term persistence rather than short‑lived attacks, indicating a focus on sustained revenue streams.

Enhanced Description

Key Capabilities

  • Deploy VoidLink malware targeting technology and finance sectors
  • Use web services for command & control, exfiltration, and phishing
  • Create local and domain accounts to maintain persistence
  • Target Exchange/Office365/Google Workspace using stolen credentials
  • Perform endpoint denial‑of‑service attacks against network services
  • Exploit remote services for lateral movement
  • Exploitation of software vulnerabilities for code execution
  • Hijack service binaries by replacing executable files
  • Implant malicious cloud or container images for persistence
  • Spoof browser and system attributes such as HTTP User‑Agent
  • Target multi‑factor authentication mechanisms
  • Utilize AI‑enabled IDEs for rapid development (ZigLang implants, GoLang backend)
  • Implement P2P mesh networking for resilient C2
  • Deploy eBPF rootkits on Linux systems for kernel‑level persistence
  • Exploit Java serialization vulnerabilities in Apache Dubbo

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command and Control
Collection
Exfiltration
Impact

ATT&CK Techniques

T1071.003
T1136.001
T1136.002
T1048.006
T1499
T1566.001
T1210
T1068
T1037
T1557
T1583
T1613
T1123
T1547
T1119
T1115
T1071
T1190
T1659
T1010
T1560
T1185
T1580
T1217
T1092
T1003.001
T1595
T1548
T1087
T1059
T1020
T1609
T1584
T1612
T1586
T1619
T1554
T1098
T1110
T1078
T1531
T1671
T1197
T1650
T1651
T1134
T1526
T1538

Software / Tooling

VoidLink
MailSniper
BRICKSTORM
Emotet
Manjusaka
Fscan
Cobalt Strike
Winnti Rootkit
Truebot
PowerShell
Matrix
Hook
Hive

Campaigns & Victims

UAT-9921’s campaigns exhibit a pattern of low‑visibility persistence, often beginning with phishing for credential theft and escalating to system compromise via software vulnerabilities. Their operational tempo is moderate; attacks typically unfold over weeks or months rather than immediate high‑impact incidents. Victim profiles skew toward medium‑to‑large enterprises in technology, finance, and critical infrastructure sectors across Ukraine, China, Russia, and other strategic regions. A notable past operation includes the Bayer Cyber Attack, where the group deployed a blend of phishing, credential theft, and ransomware tactics. Detection and mitigation have highlighted recurring use of public cloud services for C2; analysts should therefore monitor anomalous traffic to such services as well as unusual account creation events within victim domains.

IOC Patterns

  • Domain
  • File

Recommended Actions

  • Deploy ClamAV signature Unix.Trojan.VoidLink-10059283 to block VoidLink malware
  • Monitor outbound web service traffic (Google, Twitter, Dropbox) for suspicious C2 activity
  • Detect and investigate local/domain account creation events for unauthorized persistence
  • Harden Exchange/Office365 credentials and enforce MFA with strict monitoring
  • Protect against endpoint denial‑of‐service attacks by strengthening network services
  • Enforce multi‑factor authentication to mitigate credential theft
  • Scan cloud image registries (AWS, GCP, Azure) for malicious or backdoored images
  • Implement application whitelisting and monitor file system permissions for service binaries
  • Apply timely patches for known software vulnerabilities
  • Inspect HTTP traffic for spoofed User‑Agent strings

Suggested Tags

VoidLink
UAT-9921
Web Service C2
Command & Control via Web Services
Denial of Service
Credential Theft
Cloud Infrastructure Abuse
Financial Theft
Remote Services Exploitation
Service Binary Hijacking
Cloud Persistence
Masquerading/Spoofing
Multi-Factor Authentication Bypass
Lateral Movement

Confidence Assessment

The intelligence indicates a high‑confident assessment of UAT-9921’s capabilities and targeting profile, supported by multiple vendor reports (Cisco Talos, Rescana, CXODigitalPulse). However, gaps remain regarding the actor’s exact origin, operational tempo variability, and the full extent of their cloud persistence techniques. Limited dates for first and last sightings impede precise trend analysis, underscoring a need for ongoing monitoring and threat intelligence sharing.

ATT&CK Techniques

Exfiltration
1 technique
Lateral Movement
1 technique
Reconnaissance
1 technique

Observed Data

No observed data linked yet.

References

  1. blog.talosintelligence.com — Cited by web research for: Alchimist
  2. attack.mitre.org — Cited by web research for: services
  3. attack.mitre.org — Cited by web research for: Matrix
  4. blog.talosintelligence.com — Cited by web research for: Global
  5. www.cxodigitalpulse.com — Cited by web research for: DigitalPulse
  6. https://www.rescana.com/post/uat-9921-targets-technology-and-financial-sectors-with-voidlink-malware-via-apache-dub — Cited by AI analysis.
  7. https://www.cxodigitalpulse.com/uat-9921-deploys-voidlink-malware-in-campaigns-targeting-tech-and-fine — Cited by AI analysis.

Intel Summary

48

Techniques

45

Tools

1

Campaigns

38

IOCs

0

Observed Data

15

Tactics

Tags

Financial Targeting
Critical Infrastructure
Backdoor / C2
APT
Financial Sector
Linux Exploits
VoidLink
UAT-9921
Web Service C2
Command & Control via Web Services
Denial of Service
Credential Theft
Cloud Infrastructure Abuse
Financial Theft
Remote Services Exploitation
Service Binary Hijacking
Cloud Persistence
Masquerading/Spoofing
Multi-Factor Authentication Bypass
Lateral Movement

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.