PULSE NAME
UAT-8302 and its box full of malware
WHITE UAT-8302 AlienVault 2026-05-05 Modified: 2026-05-05
50
IOCs
MEDIUM VOLUME
UAT-8302 is a sophisticated China-nexus advanced persistent threat group targeting government entities in South America since late 2024 and southeastern Europe in 2025. The actor deploys multiple custom-made malware families including NetDraft, a .NET-based backdoor variant of FinalDraft/SquidDoor, and CloudSorcerer version 3. Post-compromise activities involve extensive reconnaissance, credential extraction, information collection from Active Directory, and network proliferation using tools like Impacket. The group establishes persistence through scheduled tasks and deploys additional malware including VSHELL, SNAPPYBEE/DeedRAT, and ZingDoor. UAT-8302 demonstrates connections to several China-nexus threat clusters through shared tooling, including Draculoader and SNOWLIGHT stager. The actor uses legitimate services like MS Graph and OneDrive for command-and-control infrastructure and establishes backdoor access through proxy servers using tools written in Simplified Chinese.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
NetDraft FringePorch CloudSorcerer VSHELL SNOWLIGHT SNOWRUST DeedRAT SNAPPYBEE ZingDoor Draculoader FinalDraft SquidDoor NosyDoor
Indicators of Compromise (6 / 50 total)
All IPv4 CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 111e8abb4b8592172d597926f47f018c 2026-05-05
FileHash-MD5 3d00e34594dbaba266f301ca37246e06 2026-05-05
FileHash-MD5 4c71357de3c0b12094693ca6eff94cad 2026-05-05
FileHash-MD5 99911fce9e0d697c99421b81e8fe2a04 2026-05-05
FileHash-MD5 efc71bd23572eec985a6d1bbf61308fd 2026-05-05
FileHash-MD5 f694401d8e80bb0f672b1b30fd7b153a 2026-05-05