Uptime Hamster: 11d 13h 16mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza UAT-7237

UAT-7237

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: uat-5918, uat-7237
Ver en IntelTracker → APTTrail →
UAT-7237 is a Chinese-speaking advanced persistent threat group, active since at least 2022, which primarily targets web infrastructure entities in Taiwan with the motivation of establishing long-term persistence in high-value victim environments for intelligence gathering. This group is assessed with high confidence to be a subgroup of UAT-5918, sharing overlapping tooling and victimology, yet it distinguishes itself by its primary reliance on Cobalt Strike as a backdoor, the selective deployment of web shells, and the use of SoftEther VPN and Remote Desktop Protocol (RDP) for sustained access, diverging from the immediate web shell deployment favored by its parent group. Their operational focus on critical web hosting and cloud infrastructure in Taiwan demonstrates a strategic aim to gain leverage through persistent access to digital services.

Aliases del actor

uat-5918uat-7237

Actores similares

uat-5918actor · 1UAT-5918apt · 0apt-equationgroupactor · 1Equationactor · 1Aquatic Pandaactor · 1aquatic-pandaactor · 1equation-groupactor · 1UAT-5394apt · 0UAT-8099apt · 0Equation Groupapt · 0
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
6
Actualizado
Tue, 21 Ap