Skip to main content
Mallory
🇨🇳 CN11 malware familiesExploits CVEs in the wild

UAT-8837

Also known asUAT-8837

UAT-8837 is a threat actor tracked by Cisco Talos and assessed with medium confidence to be a China-nexus advanced persistent threat (APT) actor. Since at least 2025, the group has targeted critical infrastructure organizations in North America, including the U.S. and Canada, and appears primarily focused on obtaining initial access to high-value organizations. Reported initial access methods include exploitation of vulnerable public-facing servers and use of compromised credentials. Talos linked the actor’s activity, tooling, and infrastructure to exploitation of the Sitecore vulnerability CVE-2025-53690, described in the reporting as a ViewState deserialization zero-day that enabled pre-authentication remote code execution. The reporting states this suggests the actor may have access to zero-day exploits. Post-compromise, UAT-8837 conducts reconnaissance, credential harvesting, and Active Directory/domain discovery, and establishes multiple channels of access. Reported behavior includes disabling RestrictedAdmin for RDP, hands-on-keyboard activity via cmd.exe, creating or modifying accounts for persistence, and exfiltrating sensitive data. In at least one case, the actor exfiltrated DLL-based shared libraries related to a victim’s products, which Talos assessed could create future trojanization or supply-chain compromise risk. The group is reported to rely heavily on open-source, dual-use, and living-off-the-land tooling, and to rotate tool variants to evade detection. Tools explicitly mentioned in the content include Earthworm, DWAgent, SharpHound, Impacket, GoExec, Rubeus, Certipy, GoTokenTheft, Invoke-WMIExec, SharpWMI, and 7-Zip. Separate reporting tied exploitation of CVE-2025-53690 to deployment of the WeepSteel backdoor for long-term espionage and data exfiltration, with unauthorized administrative accounts such as asp$ and sawadmin also observed. No aliases beyond UAT-8837 are directly supported in the provided content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Energy
  • Utilities
  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States
  • 🇨🇦 Canada

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics25 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
3 techniques
T1078×2
Valid Accounts
T1190×3
Exploit Public-Facing Application
T1195×2
Supply Chain Compromise
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.003
Windows Command Shell
TA0003
Persistence
2 techniques
T1078×2
Valid Accounts
T1136
Create Account
TA0004
Privilege Escalation
2 techniques
T1078×2
Valid Accounts
T1134
Access Token Manipulation
TA0005
Stealth
2 techniques
T1078×2
Valid Accounts
T1134
Access Token Manipulation
TA0006
Credential Access
3 techniques
T1003
OS Credential Dumping
T1558
Steal or Forge Kerberos Tickets
T1558.003
Kerberoasting
T1649×2
Steal or Forge Authentication Certificates
TA0007
Discovery
4 techniques
T1016
System Network Configuration Discovery
T1018×2
Remote System Discovery
T1082
System Information Discovery
T1482
Domain Trust Discovery
TA0008
Lateral Movement
1 technique
T1021×2
Remote Services
T1021.001×2
Remote Desktop Protocol
TA0011
Command and Control
2 techniques
T1090×2
Proxy
T1090.002
External Proxy
T1219
Remote Access Tools
TA0010
Exfiltration
1 technique
T1041×2
Exfiltration Over C2 Channel
ACTIVITY FEED

Recent activity

13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cloudatg insightsNews
Feb 13, 2026
AI Development & Software Engineering | CloudATG

China-aligned APT actor targeting North American critical infrastructure; observed exploiting a Sitecore zero-day in intrusions.

Read more
secpod blogNews
Jan 19, 2026
Unmasking UAT-8837: The Zero-Day Exploit That Could Ruin Your Year - SecPod Blog

China-linked APT activity cluster exploiting Sitecore zero-day CVE-2025-53690 (ViewState insecure deserialization) to gain RCE, deploy the WeepSteel backdoor, establish persistence (e.g., DWAgent service), enable tunneling (Earthworm), create admin accounts (asp$, sawadmin), and exfiltrate sensitive data (e.g., web.config, SAM/SYSTEM hives) for espionage.

Read more
security affairsNews
Jan 17, 2026
China-linked APT UAT-8837 targets North American critical infrastructure

China-nexus APT activity targeting North American critical infrastructure. Initial access via exploits (including suspected zero-days) or stolen credentials, followed by hands-on-keyboard post-compromise operations: credential theft, Active Directory reconnaissance/mapping, defense weakening (e.g., disabling RestrictedAdmin for RDP), persistence, lateral movement, and data exfiltration (including product-related DLLs, raising supply-chain trojanization risk).

Read more
scworldNews
Jan 16, 2026
North American critical infrastructure subjected to Chinese attacks | SC Media

Chinese state-sponsored intrusion activity targeting North American critical infrastructure, exploiting a Sitecore zero-day to gain initial access and then using tooling (including Earthworm) to discover internal endpoints and establish reverse tunnels for persistent access.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping21

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal11

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

UAT-8837 | Mallory