Also known as: tracked as, unauthenticated atta
UAT-10608 is a threat cluster observed by Cisco Talos conducting a large-scale, automated credential-harvesting campaign against public-facing web applications, especially Next.js deployments, using a custom framework called NEXUS Listener to extract and exfiltrate secrets such as credentials, SSH keys, cloud tokens, and API keys. The activity has been linked to broad opportunistic scanning and at least 766 compromised hosts across multiple regions and cloud providers.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT-10608 is an identified threat cluster attributed to a large-scale, automated credential-harvesting campaign targeting public-facing web applications, particularly those using Next.js. The group exploits these environments with a custom toolset, including the NEXUS Listener framework, to extract sensitive information such as credentials and cloud tokens. This activity has compromised at least 766 hosts across multiple regions and cloud providers.
Goals & Targeting
UAT-10608 appears to target sectors with significant exposure of web-facing infrastructure, particularly those using Next.js. Their primary objective is likely credential theft and data exfiltration, which can be monetized or used for further attacks. The targeting across multiple regions and cloud providers suggests a focus on maximizing the scale of compromise rather than sector-specific interests.
Enhanced Description
UAT-10608 represents a sophisticated campaign detected by Cisco Talos that focuses on harvesting credentials from exposed web applications. The threat actors use a custom framework, NEXUS Listener, to automate the extraction and exfiltration of sensitive data like SSH keys, cloud tokens, and API keys. Operating with high efficiency, they have targeted over 766 hosts in various regions and across multiple cloud providers. While specific details on their origin or precise modus operandi beyond credential harvesting are not available, UAT-10608's broad targeting suggests an opportunistic approach to compromising vulnerable web assets. This campaign underscores the risks associated with exposed web applications and highlights the need for robust security measures in cloud environments.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
UAT-10608's campaign patterns include broad scanning and automated credential harvesting. The group has demonstrated the ability to compromise at least 766 hosts across multiple regions, indicating a sustained and widespread effort. While specific campaigns have not been widely reported, the March 2023 activity linked to UAT-10608 suggests ongoing operational activity targeting exposed web applications.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in UAT-10608's profile is moderate based on the limited data provided. The campaign details from Cisco Talos are credible, but additional intelligence regarding TTPs and specific tools beyond NEXUS Listener would strengthen the understanding of their capabilities.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
36
Tools
0
Campaigns
27
IOCs
0
Observed Data
0
Tactics