UAT-9244
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
UAT-9244 is a China-nexus advanced persistent threat actor, first documented by Cisco Talos in early 2026, with activity observed since 2024. The group is assessed with high confidence to be closely associated with Famous Sparrow and to overlap with Tropic Trooper, indicating a well-established operational lineage. Its primary motivation is state-aligned espionage, focusing on the systematic gathering of sensitive intelligence and maintaining long-term access to critical infrastructure rather than immediate financial gain. UAT-9244 distinguishes itself through its multi-platform toolkit, featuring three novel malware families—TernDoor, PeerTime, and BruteEntry—designed for deep, persistent compromise across Windows, Linux, and network edge devices. While sharing targeting profiles with other China-linked groups like Salt Typhoon, Talos has not established a direct connection between UAT-9244 and these other clusters.