Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-8616

Also known as: CVE-2026-20127, tracked as, UAT-8616 by Cisco Talos, Silence.Downloader

Description

UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.

Goals & Targeting

Targeted Sectors

Critical infrastructure
Financial services
Healthcare
Defense
Energy
Nuclear
Government

Targeted Countries / Regions

UA
CN
RU

AI Analysis

· 1 week ago

Executive Summary

UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, targeting Critical Infrastructure and Network Providers since at least 2023. They exploit known vulnerabilities (e.g., CVE-2026-20127) to gain persistent access through network edge devices, posing significant risks to high-value organizations.

Goals & Targeting

UAT-8616's targeting strategy focuses on Critical Infrastructure and Network Providers, indicating a strategic interest in gaining access to high-value assets. Their choice of network edge devices suggests an intent to establish persistent access, possibly for espionage or sabotage purposes. The actor may seek to disrupt operations, gather sensitive information, or maintain long-term influence over targeted organizations.

Enhanced Description

UAT-8616 is a cyber threat actor identified by Cisco Talos as highly sophisticated, engaging in targeted attacks against Critical Infrastructure and Network Providers. Their operations involve exploiting vulnerabilities such as CVE-2026-20127 and CVE-2022-20775 to compromise network edge devices and establish persistent footholds within high-value organizations. This threat actor demonstrates a focus on long-term access, likely aiming to achieve strategic objectives such as data collection or disruption of critical services. UAT-8616's use of sophisticated tactics suggests a potential nation-state or advanced persistent threat (APT) group with the capability and intent to target sensitive sectors.

Key Capabilities

  • Exploitation of zero-day and known vulnerabilities
  • Supply chain compromise or version downgrade attacks
  • Persistent access through network edge devices
  • Lateral movement within networks
  • Credential dumping for elevated privileges

MITRE ATT&CK Tactics

Network Intrusion
Credential Access
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1059.003 - Remote Desktop Protocol (RDP)
T1043 -ansomware Execution from Memebership Initial Access
T1021 - Internal Domain Communication
T1055 - Process Injection

Software / Tooling

Cobalt Strike
Rubeus/Mimikatz
Custom Exploits
Agent Tesla RAT

Campaigns & Victims

UAT-8616 has demonstrated a methodical approach to targeting network edge devices, exploiting known vulnerabilities, and establishing persistent access. Their campaigns likely involve long-term infiltration to maximize data exfiltration or disruption. Notable operations include the exploitation of CVE-2026-20127 in 2023, indicating a focus on emerging vulnerabilities. The actor's persistence suggests they aim to maintain access over extended periods, potentially for strategic advantage.

IOC Patterns

  • Exploitation activity targeting network edge devices
  • Use of Rubeus/Mimikatz for credential dumping
  • Network traffic anomalies in network edge segments

Recommended Actions

  • Patch systems against known CVEs (CVE-2026-20127, CVE-2022-20775)
  • Monitor network edges for unauthorized access or anomalies
  • Implement network segmentation to limit lateral movement
  • Conduct regular employee training on phishing and credential security
  • Deploy multi-factor authentication (MFA) across critical systems

Suggested Tags

APT
Critical Infrastructure
Espionage
Network Provider

Confidence Assessment

High confidence in the actor's sophistication and targeting profile, but limited data on exact TTPs beyond exploit activity. Further analysis of recent campaigns could refine understanding.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 12 Domain 7 URL 1

References

  1. research.splunk.com — Cited by web research for: T1190
  2. attack.mitre.org — Cited by web research for: Interception
  3. blog.talosintelligence.com — Cited by web research for: phishing
  4. blog.talosintelligence.com — Cited by web research for: SolarWinds
  5. www.esentire.com — Cited by web research for: CALENDAR

Intel Summary

1

Techniques

44

Tools

0

Campaigns

23

IOCs

0

Observed Data

1

Tactics

Tags

Critical Infrastructure
APT
Espionage
Network Provider

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.