UAT-9686
UAT-9686 is a China-linked / China-nexus advanced persistent threat (APT) actor assessed by Cisco Talos with moderate confidence to be China-affiliated. The group has been observed exploiting the Cisco AsyncOS zero-day CVE-2025-20393 against Cisco Secure Email Gateway (SEG) and Cisco Secure Email and Web Manager (SEWM/SMA) appliances, with activity reported since at least late November 2025 and exploitation confirmed by December 10, 2025. The campaign targeted internet-exposed appliances with Spam Quarantine enabled, and reporting describes the activity as a sophisticated espionage operation. Cisco Talos linked UAT-9686 to deployment of a custom persistence mechanism/backdoor called AquaShell, a lightweight Python backdoor embedded in Cisco AsyncOS web server files that receives encoded commands via unauthenticated HTTP POST requests and executes them in the system shell. Associated tooling used in the campaign includes AquaTunnel / ReverseSSH for reverse SSH tunneling, Chisel for HTTP-based tunneling and internal pivoting, and AquaPurge for log clearing and anti-forensics. Reporting also notes use of tunneling tools and a Python backdoor, as well as log purging and persistence installation on compromised appliances. Cisco Talos stated that the group’s tooling, infrastructure, and TTPs overlap with known Chinese groups including APT41 and UNC5174, and that AquaTunnel and related tools have previously been linked to those Chinese state-backed groups. The provided content does not state that UAT-9686 is the same actor as APT41 or UNC5174, only that there is overlap. No additional aliases or sub-groups are provided beyond UAT-9686.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus APT exploiting a Cisco AsyncOS zero-day to target Cisco Secure Email Gateway / Secure Email and Web Manager appliances.
China-linked APT actor exploiting a Cisco AsyncOS zero-day against secure email gateway products.
Activity cluster associated (by Talos) with deployment of the AquaShell Python backdoor against Cisco Secure Management Appliance (SMA) environments; observed behavior included backdoor deployment with no follow-on activity in the described incident.
Exploiting a Cisco zero-day affecting Secure Email Gateway and Secure Email and Web Manager.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.