UAT-5918 is a China-linked cyber-espionage threat actor active since at least 2023 and associated with intrusions targeting Taiwan, particularly critical infrastructure and telecommunications-related entities. The group’s operations are oriented toward long-term persistence, credential theft, and post-compromise access rather than disruptive effects. Reporting has linked the actor to campaigns intended to establish durable footholds inside victim environments, especially in Taiwanese networks. UAT-5918 is known for using web shells extensively after initial compromise, along with open-source tooling and reverse-shell access for persistence, credential access, and follow-on operations. Observed tradecraft includes exploitation of unpatched internet-facing systems, deployment of multiple web shells, use of Meterpreter-based reverse shells, credential theft, and broader post-exploitation activity consistent with espionage objectives. The actor has also been associated with use of operational relay box infrastructure to obscure downstream operations. The group has documented overlap with several China-nexus activity clusters and is reported to share similarities with or overlap activity commonly tracked as Volt Typhoon, Flax Typhoon, Earth Estries, and Dalbit. These overlaps do not establish that the clusters are identical, but they place UAT-5918 within the broader ecosystem of Chinese state-aligned intrusion activity. UAT-5918 has also been identified as a consumer of relay infrastructure provided by the separate China-nexus actor UAT-7810, although the two are tracked as distinct entities despite tooling overlap. Cisco Talos has further assessed that UAT-7237 is likely a subgroup or division under the broader UAT-5918 umbrella. In contrast to UAT-5918’s heavier reliance on Meterpreter and widespread web-shell deployment, UAT-7237 has been described as relying more on Cobalt Strike, selective web-shell use, and persistence through remote desktop access and SoftEther VPN. Taken together, UAT-5918 appears to represent a broader China-aligned espionage cluster with multiple related activity sets focused on stealthy access, credential theft, and sustained operations against high-value Taiwanese targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"The attacks themselves weaponize N-day security vulnerabilities (e.g., CVE-2015-1548 and CVE-2017-17663) to obtain initial access."
"The attacks themselves weaponize N-day security vulnerabilities (e.g., CVE-2015-1548 and CVE-2017-17663) to obtain initial access."
83 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Secondary China-nexus actor described as a consumer of ORB infrastructure established by UAT-7810, with tooling overlap but treated as a distinct entity.
Separate China-linked APT that receives infrastructure support from UAT-7810 and has overlapping tooling.
A China-nexus threat actor that leveraged UAT-7810's ORB infrastructure in attacks targeting critical infrastructure entities in Taiwan to establish persistent access.
A separate China-linked threat actor that shares some tools with UAT-7810 but is tracked independently with different objectives.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.