Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors uat-8302

Description

UAT-8302 is a sophisticated China-nexus advanced persistent threat group targeting government entities in South America since late 2024 and southeastern Europe in 2025. The actor deploys multiple custom-made malware families including NetDraft, a .NET-based backdoor variant of FinalDraft/SquidDoor, and CloudSorcerer version 3. Post-compromise activities involve extensive reconnaissance, credential extraction, information collection from Active Directory, and network proliferation using tools like Impacket. The group establishes persistence through scheduled tasks and deploys additional malware including VSHELL, SNAPPYBEE/DeedRAT, and ZingDoor. UAT-8302 demonstrates connections to several China-nexus threat clusters through shared tooling, including Draculoader and SNOWLIGHT stager. The actor uses legitimate services like MS Graph and OneDrive for command-and-control infrastructure and establishes backdoor access through proxy servers using tools written in Simplified Chinese.

Goals & Targeting

Targeted Sectors

Government
Communications

Targeted Countries / Regions

Japan
Russian Federation

AI Analysis

· 1 week ago

Executive Summary

UAT-8302 is a sophisticated China-linked advanced persistent threat (APT) group targeting government entities in South America and southeastern Europe, primarily focusing on sectors such as government and communications. The group employs custom malware, including NetDraft, VSHELL, and ZingDoor, leveraging legitimate services like MS Graph for command-and-control. UAT-8302 demonstrates connections to other China-nexus threat clusters through shared tooling and operational techniques.

Goals & Targeting

UAT-8302's strategic objectives appear to focus on espionage and intelligence gathering, targeting government entities and communications sectors. The group's selection of South America and southeastern Europe suggests a potential interest in geopolitical influence or diplomatic operations. The actor's use of persistent, long-term access indicates an intent to maintain a foothold within targeted networks for prolonged periods, likely to enable continuous data exfiltration or further espionage activities.

Enhanced Description

UAT-8302 is a known advanced persistent threat group with a suspected nexus to China, targeting government entities in South America since late 2024 and expanding its operations to southeastern Europe in 2025. The group deploys multiple custom-made malware families, including NetDraft, a .NET-based backdoor variant of FinalDraft/SquidDoor, and CloudSorcerer version 3. Post-compromise activities involve extensive reconnaissance, credential extraction, information collection from Active Directory, and network proliferation using tools like Impacket. UAT-8302 establishes persistence through scheduled tasks and deploys additional malware including VSHELL, SNAPPYBEE/DeedRAT, and ZingDoor. The actor demonstrates connections to several China-nexus threat clusters through shared tooling, including Draculoader and SNOWLIGHT stager. UAT-8302 uses legitimate services like MS Graph and OneDrive for command-and-control infrastructure and establishes backdoor access through proxy servers using tools written in Simplified Chinese.

Key Capabilities

  • Custom .NET-based malware
  • Multiple backdoor variants (NetDraft, FinalDraft/SquidDoor)
  • CloudSorcerer v3 malware family
  • Impacket toolset for network access and lateral movement
  • Scheduled task persistence mechanisms
  • Legitimate service abuse (MS Graph, OneDrive)
  • Proxy server exploitation in China-linked environments

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Defense Evasion
Credential Access
Persistence
Network Discovery

ATT&CK Techniques

T1049
T1543.001
T1687
T1070
T1003
T1075.001

Software / Tooling

NetDraft
FinalDraft/SquidDoor
CloudSorcerer v3
Impacket
VSHELL
SNAPPYBEE/DeedRAT
ZingDoor
Draculoader
SNOWLIGHT

Campaigns & Victims

UAT-8302 has conducted campaigns targeting government entities in South America and southeastern Europe. The group's operational tempo suggests careful, methodical campaigns with a focus on maintaining persistence within networks. Notable activities include extensive Active Directory exploitation, credential extraction, and lateral movement using known tools like Impacket. The actor's recent shift to targeting Japan and the Russian Federation indicates potential expansion or strategic pivoting.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • .NET-based backdoor activity (NetDraft)
  • Use of legitimate services like MS Graph for C2
  • Proxy server traffic originating from China-linked IP addresses
  • Scheduled task creation related to UAT-8302 tools
  • Registry modifications and persistence mechanisms

Recommended Actions

  • Monitor network traffic for anomalies in legitimate services like MS Graph and OneDrive.
  • Implement endpoint detection rules for known UAT-8302 tool signatures (e.g., NetDraft, CloudSorcerer).
  • Conduct regular audits of Active Directory to detect unauthorized access or changes.
  • Apply patches and updates to mitigate vulnerabilities exploited by UAT-8302.
  • Use email filtering to block spear-phishing attempts and macro-laced Office documents.
  • Enhance network segmentation to limit lateral movement within the network.

Suggested Tags

APT
espionage
government-sector
China-nexus

Confidence Assessment

Confidence in UAT-8302's details is medium due to limited available intelligence on specific campaign dates and exact origins. While the group demonstrates clear China-linked characteristics and sophisticated TTPs, further evidence could enhance understanding of its precise objectives and capabilities.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

15

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Government Targeting
espionage
government-sector
China-nexus

Details

Type
Unknown
Country of Origin
C
Confidence
55%
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.