Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-10608

Also known as: tracked as, unauthenticated atta

Description

UAT-10608 is a threat cluster observed by Cisco Talos conducting a large-scale, automated credential-harvesting campaign against public-facing web applications, especially Next.js deployments, using a custom framework called NEXUS Listener to extract and exfiltrate secrets such as credentials, SSH keys, cloud tokens, and API keys. The activity has been linked to broad opportunistic scanning and at least 766 compromised hosts across multiple regions and cloud providers.

Goals & Targeting

Targeted Sectors

Telecommunications
Government
Information technology
Defense
Critical infrastructure
Healthcare
Financial services

Targeted Countries / Regions

CN
US

AI Analysis

· 1 week ago

Executive Summary

UAT-10608 is an identified threat cluster attributed to a large-scale, automated credential-harvesting campaign targeting public-facing web applications, particularly those using Next.js. The group exploits these environments with a custom toolset, including the NEXUS Listener framework, to extract sensitive information such as credentials and cloud tokens. This activity has compromised at least 766 hosts across multiple regions and cloud providers.

Goals & Targeting

UAT-10608 appears to target sectors with significant exposure of web-facing infrastructure, particularly those using Next.js. Their primary objective is likely credential theft and data exfiltration, which can be monetized or used for further attacks. The targeting across multiple regions and cloud providers suggests a focus on maximizing the scale of compromise rather than sector-specific interests.

Enhanced Description

UAT-10608 represents a sophisticated campaign detected by Cisco Talos that focuses on harvesting credentials from exposed web applications. The threat actors use a custom framework, NEXUS Listener, to automate the extraction and exfiltration of sensitive data like SSH keys, cloud tokens, and API keys. Operating with high efficiency, they have targeted over 766 hosts in various regions and across multiple cloud providers. While specific details on their origin or precise modus operandi beyond credential harvesting are not available, UAT-10608's broad targeting suggests an opportunistic approach to compromising vulnerable web assets. This campaign underscores the risks associated with exposed web applications and highlights the need for robust security measures in cloud environments.

Key Capabilities

  • Large-scale automated credential-harvesting from exposed web applications
  • Use of custom NEXUS Listener framework for data extraction and exfiltration
  • Broad scanning campaigns across multiple regions and cloud providers

MITRE ATT&CK Tactics

Cyber Exploitation
Credential Access

Software / Tooling

NEXUS Listener

Campaigns & Victims

UAT-10608's campaign patterns include broad scanning and automated credential harvesting. The group has demonstrated the ability to compromise at least 766 hosts across multiple regions, indicating a sustained and widespread effort. While specific campaigns have not been widely reported, the March 2023 activity linked to UAT-10608 suggests ongoing operational activity targeting exposed web applications.

IOC Patterns

  • Automated scanning of Next.js deployments
  • Custom framework (NEXUS Listener) for credential extraction
  • Anomalies in cloud token usage and API key exposure

Recommended Actions

  • Implement network monitoring to detect unusual scanning patterns from known threat IPs.
  • Adopt multi-factor authentication for cloud accounts and critical systems.
  • Regularly patch and update web applications, especially Next.js deployments.
  • Conduct security audits of exposed web services and remove unnecessary public access points.
  • Monitor for signs of credential exfiltration through network traffic analysis.

Suggested Tags

credential_harvesting
cloud_exploitation
scanner_campaign
custom_framework
automated_credential_theft next.js_vulnerabilities

Confidence Assessment

The confidence in UAT-10608's profile is moderate based on the limited data provided. The campaign details from Cisco Talos are credible, but additional intelligence regarding TTPs and specific tools beyond NEXUS Listener would strengthen the understanding of their capabilities.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.securityweek.com — Cited by web research for: unauthenticated atta
  2. blog.talosintelligence.com — Cited by web research for: Payload
  3. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  4. fortiguard.fortinet.com — Cited by web research for: Matrix
  5. blog.talosintelligence.com — Cited by web research for: Malware Payloads

Intel Summary

0

Techniques

36

Tools

0

Campaigns

27

IOCs

0

Observed Data

0

Tactics

Tags

credential_harvesting
cloud_exploitation
scanner_campaign
custom_framework
automated_credential_theft next.js_vulnerabilities

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.