The Reseacher has identified UAT-8837, a suspected China-nexus advanced persistent threat (APT) group primarily focused on gaining initial access to high-value organizations within critical infrastructure sectors across North America.
Active since at least 2025, the threat actor demonstrates sophisticated tradecraft and likely possesses zero-day exploitation capabilities.
Exploitation and Initial Access
UAT-8837 gains entry through both n-day and zero-day vulnerability exploitation, most recently leveraging CVE-2025-53690, a ViewState Deserialization zero-day in Sitecore products.
After compromising systems, the group conducts preliminary reconnaissance using standard Windows commands, including whoami, netstat, tasklist, and hostname, to map the victim environment.
The threat actor strategically disables RestrictedAdmin for Remote Desktop Protocol to harvest credentials, then stages malicious artifacts in directories such as C:\Users<user>\Desktop, C:\windows\temp, and C:\windows\public\music.
UAT-8837 deploys an extensive arsenal of open-source tools, including Earthworm for network tunneling, SharpHound for Active Directory enumeration, DWAgent for remote administration, Certipy for AD certificate abuse, and GoExec for remote command execution.
The group exhibits adaptive behavior when security products detect their tooling, cycling through multiple tool variants to evade endpoint protection.
UAT-8837 extracts Windows security policies using secedit, queries Service Principal Names through setspn, and performs comprehensive domain reconnaissance with net commands and custom LOTL tooling, including dsquery and dsget.
Notably, the actor has exfiltrated DLL-based shared libraries from victim organizations, raising concerns about potential supply chain compromises through trojanization.
UAT-8837 establishes persistence by creating backdoored user accounts and maintaining multiple access channels throughout compromised networks.
Cisco Talos assesses with medium confidence that UAT-8837 functions primarily as an initial access broker, obtaining footholds in critical infrastructure for follow-on operations.
Organizations should monitor for indicators of compromise available in Talos’ GitHub repository and deploy detection signatures, including ClamAV’s Win.Malware.Earthworm and multiple Snort rules.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.