UAT-7237
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Aliases: uat-5918, uat-7237
UAT-7237 is a Chinese-speaking advanced persistent threat group, active since at least 2022, which primarily targets web infrastructure entities in Taiwan with the motivation of establishing long-term persistence in high-value victim environments for intelligence gathering. This group is assessed with high confidence to be a subgroup of UAT-5918, sharing overlapping tooling and victimology, yet it distinguishes itself by its primary reliance on Cobalt Strike as a backdoor, the selective deployment of web shells, and the use of SoftEther VPN and Remote Desktop Protocol (RDP) for sustained access, diverging from the immediate web shell deployment favored by its parent group. Their operational focus on critical web hosting and cloud infrastructure in Taiwan demonstrates a strategic aim to gain leverage through persistent access to digital services.