China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions

î „Ravie Lakshmananî ‚May 05, 2026Network Security / Endpoint Security

A sophisticated China-nexus advanced persistent threat (APT) group has been attributed to attacks targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.

The activity is being tracked by Cisco Talos under the moniker UAT-8302, with post-exploitation involving the deployment of custom-made malware families that have been put to use by other China-aligned hacking groups.

Notable among the malware families is a .NET-based backdoor dubbed NetDraft (aka NosyDoor), a C# variant of FINALDRAFT (aka Squidoor) that has been previously linked to threat clusters known as Ink Dragon, CL-STA-0049, Earth Alux, Jewelbug, and REF7707.

Cybersecurity

ESET is tracking the use of NosyDoor to a group it calls LongNosedGoblin. Interestingly, the same malware has also been deployed against Russian IT organizations by a threat actor referred to as Erudite Mogwai (aka Space Pirates and Webworm), per Russian cybersecurity company Solar, which has given it the name LuckyStrike Agent.

Some of the other tools utilized by UAT-8302 are as follows –

 “Malware deployed by UAT-8302 connects it to several previously publicly disclosed threat clusters, indicating a close operating relationship between them at the very least,” Talos researchers Jungsoo An, Asheer Malhotra, and Brandon White said in a technical report published today.

“Overall, the various malicious artifacts deployed by UAT-8302 indicate that the group has access to tools used by other sophisticated APT actors, all of which have been assessed as China-nexus or Chinese-speaking by various third-party industry reports.”

It’s currently not known what initial access methods the adversary employs to break into target networks, but it’s suspected to involve the tried-and-tested approach of weaponizing zero-day and N-day exploits in web applications.

Upon gaining a foothold, the attackers are known to conduct extensive reconnaissance to map out the network, run open-source tools like gogo to perform automated scanning, and move laterally across the environment. The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.

Cybersecurity

UAT-8302 has also been observed using a Rust-based variant of SNOWLIGHT called SNOWRUST to download the VShell payload from a remote server and execute it. Besides using custom malware, the threat actor sets up alternative means of backdoor access using proxy and VPN tools like Stowaway and SoftEther VPN.

The findings underscore the trend of advanced collaboration tactics between multiple China-aligned groups. In October 2025, Trend Micro shed light on a phenomenon called “Premier Pass-as-a-Service,” where initial access obtained by Earth Estries is passed to Earth Naga for follow-on exploitation, clouding attrition efforts. This partnership is assessed to have existed since at least late 2023.

“Premier Pass-as-a-Service provides direct access to critical assets, reducing the time spent on reconnaissance, initial exploitation and lateral movement phases,” Trend Micro said. “Although the full extent of this model is not yet known, the limited number of observed incidents, combined with the substantial risk of exposure such a service entails, suggests that access is likely restricted to a small circle of threat actors.”

Source link

Visited 1 times, 1 visit(s) today

Related Article

U.S. President Donald Trump shaking hands with Chinese President Xi Jinping at Gimhae International Airport

Trump says China, Xi Jinping are not challenging the US on Iran

NEWYou can now listen to Fox News articles! President Donald Trump said the U.S. hasn’t “been challenged by China” on the conflict with Iran, describing leader Xi Jinping as being “very respectful” with tensions remaining high over the Strait of Hormuz.  Trump made the remark Tuesday at the White House ahead of his visit next week

Aevean - March sees first e-commerce air trade volume decline in years

China’s e-commerce air exports declined in March

E-commerce air trade volumes out of China, which have turbocharged air cargo demand in recent years, declined in March for the first time in a number of years. Analysis carried out by consultant and data provider Aevean shows that in March, e-commerce volumes from China declined by 6% year on year. Aevean managing director Marco

Scenic spots across China enjoy holiday travel boom

Scenic spots across China enjoy holiday travel boom

Scenic spots in Ningxia, Xinjiang, Zhejiang, and other regions welcomed large numbers of visitors during China’s May Day holiday from May 1 to May 5. In Yinchuan City, Ningxia Hui Autonomous Region, a food festival at Lanshan Park featured over 100 stalls offering grilled Tan lamb kebabs paired with local wine, followed by chorus performances

Ford accelerates secret EV truck project to challenge China with $30K model

Ford accelerates secret EV truck project to challenge China with $30K model

Automaker retools manufacturing and targets a 2027 launch of a lower-cost, high-performance electric pickup. On the Dash: A lower-cost EV truck could expand affordability and bring new buyers into showrooms. Simplified manufacturing may improve margins and enable scalable inventory over time. Competitive pressure from China and Tesla signals continued shifts in pricing and technology. Ford

Images of Nvidia's Blackwell GPU from GTC.

Nvidia CEO Jensen Huang wants US to export AI ‘like crazy’

When you buy through links on our articles, Future and its syndication partners may earn a commission. “We have now dropped to zero.” So, says Nvidia CEO Jensen Huang of the company’s market share in China’s AI hardware market. Needless to say, Huang thinks this is a big mistake and Nvidia should be allowed to

China Makes "AI-Powered Robots" Core of National Strategy – IFR Reports

China Makes “AI-Powered Robots” Core of National Strategy – IFR Reports

FRANKFURT AM MAIN, Germany, May 05, 2026–(BUSINESS WIRE)–China has launched its 15th Five-Year Plan by placing robotics at the heart of its modern industrial system. The aim is to pivot its AI research towards physical applications with robots as main drivers for economic growth. This is a next step in the country’s strong automation development:

Volvo sales fall 11% as U.S. demand weakens, China competition intensifies

Volvo sales fall 11% as U.S. demand weakens, China competition intensifies

The automaker posts EV growth but sees declines in hybrid and gas-powered models amid global headwinds. Martin Lundstedt | President and CEO of Volvo AB On the Dash: Weak U.S. consumer sentiment may slow showroom traffic and increase reliance on incentives EV sales growth signals continued demand shift despite broader volume declines Competitive pressure from

Makers of US flags urge Trump to impose tariffs on Chinese imports

May 5, 2026, 5:08 a.m. ET WASHINGTON – U.S. flagmakers say that half the star-spangled banners sold in this country are made in China, so the manufacturers are urging the Trump administration to impose huge new tariffs on imports rather than wave a white flag after the Supreme Courtoverturned his emergency tariffs. “The American flag,

Blast at fireworks factory in China's Hunan kills 21, Xi calls for probe

Blast at fireworks factory in China’s Hunan kills 21, Xi calls for probe

CHANGSHA, May 5 — A blast at a fireworks factory in China’s Hunan province has killed 21 people and injured 61, prompting a call from President Xi Jinping for a thorough investigation, state media reported today. The explosion in Liuyang, under the administration of Hunan’s capital Changsha and a hub for fireworks manufacturing, occurred yesterday

Artist construction of Xiangyunloong fengming (Connor Ashbridge)

New dinosaur species found in China bridges key gap in evolution of colossal plant-eaters

Scientists have identified a new dinosaur species that lived 190 million years ago in what is now China, bridging a major gap in our evolutionary understanding of the long-necked giant. Xiangyunloong fengming was 9-10m long, making it one of the largest-known plant-eating dinosaurs found in China. It lived during the Early Jurassic epoch, between 201

Explosion at fireworks factory in China kills 26, injures 61 | News

Rescue efforts are still under way after a huge explosion ripped through China’s fireworks capital. Published On 5 May 20265 May 2026 Chinese President Xi Jinping has ordered an investigation after an explosion ripped through a fireworks factory in central China and its surrounding area, killing at least 26 people and injuring 61. Xi’s order

Image showing aircraft flying overhead two aircraft carriers and their escorts.

Chinese Navy, Anti-Ship Bombers Stage Against Balikatan Drills

MANILA, Philippines — A pair of heavily-armed Chinese anti-ship bombers and their fighter escort flew over Scarborough Shoal in a combat exercise meant to deter Manila amid the largest Philippine military exercise in years.  The People’s Liberation Army’s Southern Theater Command (PLA STC) claimed that its forces conducted a combat readiness patrol at the disputed

Fire crews work to put out a fire

Fireworks factory blast in Chine kills 21, injures 61 others: state media

NEWYou can now listen to Fox News articles! An explosion at a fireworks factory in a central Chinese province killed at least 21 people and injured 61 others, according to state media. The blast happened at a fireworks plant in Liuyang, a city administered by Changsha in Hunan province, on Monday afternoon, China’s official news

gallagher-re-logo

Gallagher Re appoints Jun Liu as Head of China Agriculture

Gallagher Re, a global reinsurance broker and risk advisory firm, has announced the appointment of Jun Liu as Head of China Agriculture, in addition to his current role as Deputy Head of the Beijing team. The executive joined Gallagher Re in 2025 from Datong Insurance, where he served as Deputy Head of Beijing, Reinsurance Department.

File: In this photo taken on 22 January 2026, a man works at a fireworks factory in Liuyang town, Changsha, central China's Hunan province (AFP via Getty Images)

Massive explosion at China fireworks factory kills 21 people

At least 21 people have been killed and 61 injured by an explosion at a fireworks factory in central China. More than 500 rescuers have been dispatched to the scene after the huge explosion, which occurred at a facility in the city of Changsha in Hunan province on Monday afternoon, according to the state-run newspaper

Waymo test minivan from China seen in Detroit. Will it carry riders?

May 5, 2026, 12:01 a.m. ET Waymo LLC, Alphabet Inc.’s autonomous ride-sharing brand, plans to expand its service to Detroit later this year. But a recent vehicle sighting by The Detroit News suggests the Motor City fleet will include Waymo’s latest vehicle: a China-sourced minivan. Called the Waymo Ojai, the electric minivan shares the so-called

ET logo

21 killed, 61 injured in blast at fireworks factory in China

Beijing: At least 21 people were killed and 61 others injured in a massive explosion at a fireworks factory in China’s Hunan province, officials said on Tuesday. The explosion occurred on Monday afternoon at the plant operated by the Huasheng fireworks manufacturing and display company in Liuyang, a county-level city under Changsha, the provincial capital.Videos

At least 21 dead, 61 injured in explosion at Chinese fireworks factory, state media says

HONG KONG — An explosion at a fireworks factory in China’s Hunan ​province killed 21 people and injured 61 on Monday, prompting ‌President Xi Jinping to call for a thorough investigation, state media reported. Subscribe to read this story ad-free Get unlimited access to ad-free articles and exclusive content. The blast in Hunan’s capital city

0
Would love your thoughts, please comment.x
()
x