UAT-8302 Deploys Custom Malware Against Government Networks

A sophisticated advanced persistent threat group known as UAT-8302 has been actively compromising government entities across multiple global regions.

Operating as a China-nexus threat actor, this group has targeted government infrastructure in South America since late 2024 and expanded its espionage operations into southeastern Europe throughout 2025.

Security researchers at Cisco Talos recently disclosed that UAT-8302 deploys an extensive toolkit of custom-made malware families, demonstrating deep technical overlap with several previously known Chinese-speaking threat clusters.

The group prioritizes obtaining and maintaining long-term clandestine access to highly sensitive networks to facilitate sustained espionage, credential extraction, and intelligence collection.

By heavily relying on customized backdoors and open-source proxying utilities, the attackers maintain persistent footholds while silently proliferating across compromised domains.

UAT-8302 Targets Government Networks

After gaining initial access to a target environment, UAT-8302 conducts aggressive, systematic network reconnaissance. The group leverages open-source red-teaming utilities, such as Impacket, alongside custom-built scripts to map the network architecture.

A primary reconnaissance tool is a custom PowerShell script named whatpc, which the attackers persistently use via scheduled tasks to gather system data continuously.

This script executes a series of built-in system commands to identify local administrators, map network routes, and analyze active domain trusts.

UAT-8302's interconnections (Source: talosintelligence)
UAT-8302’s interconnections (Source: talosintelligence)

To discover additional reachable endpoints, threat actors perform extensive ping sweeps and scan for open Server Message Block (SMB) ports across the enterprise network.

Furthermore, UAT-8302 routinely downloads automated network scanning engines written in Simplified Chinese, such as gogo, alongside other open-source scanners like QScan, naabu, and httpx, to deeply enumerate active network services.

UAT-8302 Targets Government Networks (Source: talosintelligence)
UAT-8302 Targets Government Networks (Source: talosintelligence)

As part of their intelligence gathering, UAT-8302 actively extracts credentials and operational data from Active Directory environments. They deploy specialized Python tools to steal Microsoft Entra ID connection credentials directly from enterprise servers.

The attackers also manually query Active Directory user and computer objects to identify administrative accounts and gather sensitive event logging configurations.

For lateral movement, the actors rely heavily on Windows Management Instrumentation and remote scheduled tasks to execute malicious batch files on neighboring systems.

auditpol /get /category:Logon/Logoff
auditpol /get /category:*

To cement their backdoor access, UAT-8302 establishes hidden proxy tunnels using tools such as Stowaway and Anyproxy, while occasionally deploying legitimate virtual private network clients, such as SoftEther, to tunnel traffic directly outside the compromised enterprise network.

According to talosintelligence research, the post-compromise strategy of UAT-8302 centers on deploying multiple sophisticated malware families that share code with prominent threat clusters like Jewelbug, LongNosedGoblin, and Earth Estries.

One of their primary weapons is NetDraft, a .NET backdoor that functions as a variant of the FinalDraft malware family. NetDraft is executed via dynamic-link library sideloading, using an embedded helper library, FringePorch, to interact with the infected endpoint.

This malware uniquely leverages the Microsoft Graph Application Programming Interface to communicate with an attacker-controlled OneDrive account, allowing actors to execute arbitrary commands and manage local files.

In conjunction with NetDraft, the attackers deploy the third version of CloudSorcerer.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories