Also known as: CVE-2026-20127, tracked as, UAT-8616 by Cisco Talos, Silence.Downloader
UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, targeting Critical Infrastructure and Network Providers since at least 2023. They exploit known vulnerabilities (e.g., CVE-2026-20127) to gain persistent access through network edge devices, posing significant risks to high-value organizations.
Goals & Targeting
UAT-8616's targeting strategy focuses on Critical Infrastructure and Network Providers, indicating a strategic interest in gaining access to high-value assets. Their choice of network edge devices suggests an intent to establish persistent access, possibly for espionage or sabotage purposes. The actor may seek to disrupt operations, gather sensitive information, or maintain long-term influence over targeted organizations.
Enhanced Description
UAT-8616 is a cyber threat actor identified by Cisco Talos as highly sophisticated, engaging in targeted attacks against Critical Infrastructure and Network Providers. Their operations involve exploiting vulnerabilities such as CVE-2026-20127 and CVE-2022-20775 to compromise network edge devices and establish persistent footholds within high-value organizations. This threat actor demonstrates a focus on long-term access, likely aiming to achieve strategic objectives such as data collection or disruption of critical services. UAT-8616's use of sophisticated tactics suggests a potential nation-state or advanced persistent threat (APT) group with the capability and intent to target sensitive sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAT-8616 has demonstrated a methodical approach to targeting network edge devices, exploiting known vulnerabilities, and establishing persistent access. Their campaigns likely involve long-term infiltration to maximize data exfiltration or disruption. Notable operations include the exploitation of CVE-2026-20127 in 2023, indicating a focus on emerging vulnerabilities. The actor's persistence suggests they aim to maintain access over extended periods, potentially for strategic advantage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the actor's sophistication and targeting profile, but limited data on exact TTPs beyond exploit activity. Further analysis of recent campaigns could refine understanding.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
44
Tools
0
Campaigns
23
IOCs
0
Observed Data
1
Tactics