UAT-8302 is a sophisticated China-nexus advanced persistent threat group targeting government entities in South America since late 2024 and southeastern Europe in 2025. The actor deploys multiple custom-made malware families including NetDraft, a .NET-based backdoor variant of FinalDraft/SquidDoor, and CloudSorcerer version 3. Post-compromise activities involve extensive reconnaissance, credential extraction, information collection from Active Directory, and network proliferation using tools like Impacket. The group establishes persistence through scheduled tasks and deploys additional malware including VSHELL, SNAPPYBEE/DeedRAT, and ZingDoor. UAT-8302 demonstrates connections to several China-nexus threat clusters through shared tooling, including Draculoader and SNOWLIGHT stager. The actor uses legitimate services like MS Graph and OneDrive for command-and-control infrastructure and establishes backdoor access through proxy servers using tools written in Simplified Chinese.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT-8302 is a sophisticated China-linked advanced persistent threat (APT) group targeting government entities in South America and southeastern Europe, primarily focusing on sectors such as government and communications. The group employs custom malware, including NetDraft, VSHELL, and ZingDoor, leveraging legitimate services like MS Graph for command-and-control. UAT-8302 demonstrates connections to other China-nexus threat clusters through shared tooling and operational techniques.
Goals & Targeting
UAT-8302's strategic objectives appear to focus on espionage and intelligence gathering, targeting government entities and communications sectors. The group's selection of South America and southeastern Europe suggests a potential interest in geopolitical influence or diplomatic operations. The actor's use of persistent, long-term access indicates an intent to maintain a foothold within targeted networks for prolonged periods, likely to enable continuous data exfiltration or further espionage activities.
Enhanced Description
UAT-8302 is a known advanced persistent threat group with a suspected nexus to China, targeting government entities in South America since late 2024 and expanding its operations to southeastern Europe in 2025. The group deploys multiple custom-made malware families, including NetDraft, a .NET-based backdoor variant of FinalDraft/SquidDoor, and CloudSorcerer version 3. Post-compromise activities involve extensive reconnaissance, credential extraction, information collection from Active Directory, and network proliferation using tools like Impacket. UAT-8302 establishes persistence through scheduled tasks and deploys additional malware including VSHELL, SNAPPYBEE/DeedRAT, and ZingDoor. The actor demonstrates connections to several China-nexus threat clusters through shared tooling, including Draculoader and SNOWLIGHT stager. UAT-8302 uses legitimate services like MS Graph and OneDrive for command-and-control infrastructure and establishes backdoor access through proxy servers using tools written in Simplified Chinese.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAT-8302 has conducted campaigns targeting government entities in South America and southeastern Europe. The group's operational tempo suggests careful, methodical campaigns with a focus on maintaining persistence within networks. Notable activities include extensive Active Directory exploitation, credential extraction, and lateral movement using known tools like Impacket. The actor's recent shift to targeting Japan and the Russian Federation indicates potential expansion or strategic pivoting.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in UAT-8302's details is medium due to limited available intelligence on specific campaign dates and exact origins. While the group demonstrates clear China-linked characteristics and sophisticated TTPs, further evidence could enhance understanding of its precise objectives and capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
15
IOCs
0
Observed Data
0
Tactics