Also known as: tracked as, Postgres, Tomcat servers, angrypeer, API patching
UAT‑9244 is an emerging, China‑nexus Advanced Persistent Threat that first appeared in 2024. The group’s operations have been disclosed by Cisco Talos on March 5, 2026 and are closely associated with the well‑known Famous Sparrow and Tropic Trooper campaigns. UAT‑9244 primarily targets telecommunication infrastructure across South America while also attacking entities in energy, oil & gas, government, financial services, defense, non‑profit, manufacturing and media sectors. The threat actor’s geographic focus spans countries including China, Russia, Azerbaijan, the United States, Ukraine, and notably includes widespread operations against telecommunications providers on the continent. Tactical execution is facilitated by a triad of custom malware families: TernDoor (a Windows backdoor exploiting DLL side‑loading and a stealth kernel driver), PeerTime/angrypeer (an ELF‑based peer‑to‑peer backdoor that uses BitTorrent for resilient command‑and‑control), and BruteEntry (a GoLang scanner designed to turn edge devices into operational relay boxes, enabling brute‑force attacks against SSH, PostgreSQL and Tomcat). The operator combines public-facing application exploits—most notably ProxyShell/ProxyNotShell on Microsoft Exchange—with sophisticated persistence mechanisms such as a Windows service that mimics LogMeIn Hamachi. Lateral movement is achieved through remote desktop protocol (RDP) with domain‑admin credentials and SMB shares, often leveraging the Impacket toolkit. Defense evasion techniques include DLL side‑loading of legitimate libraries (e.g., winmm.dll), API hooking to patch memory protections, installation of a kernel rootkit driver (vmflt.sys), and covert C2 traffic over HTTPS domains such as bloopencil.net. The actor also uses P2P BitTorrent for additional stealth. This modular approach allows UAT‑9244 to remain flexible while delivering robust command‑and‑control capabilities across heterogeneous environments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT‑9244 is a China‑linked APT that has been active since 2024 and focuses on South American telecommunications providers, extending attacks into energy, oil & gas, government, financial services, defense and other critical sectors. The group deploys three custom implants—TernDoor, PeerTime (angrypeer) and BruteEntry—to establish persistent Windows and Linux footholds, leveraging known Exchange CVEs, DLL side‑loading and kernel drivers for stealth. Their operations are linked to Famous Sparrow and Tropic Trooper, indicating a sophisticated, modular threat actor with cross‑nation targeting.
Goals & Targeting
UAT‑9244’s strategic objectives appear to center on espionage and establishing enduring footholds within critical infrastructure, particularly telecommunications networks in South America. By exploiting high–impact vulnerabilities in Microsoft Exchange and deploying versatile backdoors capable of bypassing standard security controls, the actor seeks to gather intelligence that could be leveraged for geopolitical leverage or further attacks against energy and defense assets. The preference for widely used protocols (HTTP/HTTPS, SMB, RDP) and legitimate service names (LogMeIn Hamachi) reflects a blend of stealth and resourcefulness intended to outlast patch cycles and evade detection.
Enhanced Description
No campaigns linked yet.
No observed data linked yet.
14
Techniques
47
Tools
0
Campaigns
39
IOCs
0
Observed Data
7
Tactics