Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-9244

Also known as: tracked as, Postgres, Tomcat servers, angrypeer, API patching

Description

UAT‑9244 is an emerging, China‑nexus Advanced Persistent Threat that first appeared in 2024. The group’s operations have been disclosed by Cisco Talos on March 5, 2026 and are closely associated with the well‑known Famous Sparrow and Tropic Trooper campaigns. UAT‑9244 primarily targets telecommunication infrastructure across South America while also attacking entities in energy, oil & gas, government, financial services, defense, non‑profit, manufacturing and media sectors. The threat actor’s geographic focus spans countries including China, Russia, Azerbaijan, the United States, Ukraine, and notably includes widespread operations against telecommunications providers on the continent. Tactical execution is facilitated by a triad of custom malware families: TernDoor (a Windows backdoor exploiting DLL side‑loading and a stealth kernel driver), PeerTime/angrypeer (an ELF‑based peer‑to‑peer backdoor that uses BitTorrent for resilient command‑and‑control), and BruteEntry (a GoLang scanner designed to turn edge devices into operational relay boxes, enabling brute‑force attacks against SSH, PostgreSQL and Tomcat). The operator combines public-facing application exploits—most notably ProxyShell/ProxyNotShell on Microsoft Exchange—with sophisticated persistence mechanisms such as a Windows service that mimics LogMeIn Hamachi. Lateral movement is achieved through remote desktop protocol (RDP) with domain‑admin credentials and SMB shares, often leveraging the Impacket toolkit. Defense evasion techniques include DLL side‑loading of legitimate libraries (e.g., winmm.dll), API hooking to patch memory protections, installation of a kernel rootkit driver (vmflt.sys), and covert C2 traffic over HTTPS domains such as bloopencil.net. The actor also uses P2P BitTorrent for additional stealth. This modular approach allows UAT‑9244 to remain flexible while delivering robust command‑and‑control capabilities across heterogeneous environments.

Goals & Targeting

Targeted Sectors

Telecommunications
Energy
Oil gas
Government
Pharmaceutical
Financial services
Defense
Non profit
Manufacturing
Media
Critical infrastructure

Targeted Countries / Regions

CN
RU
AZ
US
UA

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

UAT‑9244 is a China‑linked APT that has been active since 2024 and focuses on South American telecommunications providers, extending attacks into energy, oil & gas, government, financial services, defense and other critical sectors. The group deploys three custom implants—TernDoor, PeerTime (angrypeer) and BruteEntry—to establish persistent Windows and Linux footholds, leveraging known Exchange CVEs, DLL side‑loading and kernel drivers for stealth. Their operations are linked to Famous Sparrow and Tropic Trooper, indicating a sophisticated, modular threat actor with cross‑nation targeting.

Goals & Targeting

UAT‑9244’s strategic objectives appear to center on espionage and establishing enduring footholds within critical infrastructure, particularly telecommunications networks in South America. By exploiting high–impact vulnerabilities in Microsoft Exchange and deploying versatile backdoors capable of bypassing standard security controls, the actor seeks to gather intelligence that could be leveraged for geopolitical leverage or further attacks against energy and defense assets. The preference for widely used protocols (HTTP/HTTPS, SMB, RDP) and legitimate service names (LogMeIn Hamachi) reflects a blend of stealth and resourcefulness intended to outlast patch cycles and evade detection.

Enhanced Description

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. blog.talosintelligence.com — Cited by web research for: Postgres
  2. www.bitdefender.com — Cited by web research for: T1190
  3. blog.talosintelligence.com — Cited by web research for: Payload
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  5. gurucul.com — Cited by web research for: Global

Intel Summary

14

Techniques

47

Tools

0

Campaigns

39

IOCs

0

Observed Data

7

Tactics

Tags

APT
Backdoor / C2

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.