PULSE NAME
UAT-8302 and its box full of malware
WHITE UAT-8302 AlienVault 2026-05-05 Modified: 2026-05-05
50
IOCs
MEDIUM VOLUME
UAT-8302 is a sophisticated China-nexus advanced persistent threat group targeting government entities in South America since late 2024 and southeastern Europe in 2025. The actor deploys multiple custom-made malware families including NetDraft, a .NET-based backdoor variant of FinalDraft/SquidDoor, and CloudSorcerer version 3. Post-compromise activities involve extensive reconnaissance, credential extraction, information collection from Active Directory, and network proliferation using tools like Impacket. The group establishes persistence through scheduled tasks and deploys additional malware including VSHELL, SNAPPYBEE/DeedRAT, and ZingDoor. UAT-8302 demonstrates connections to several China-nexus threat clusters through shared tooling, including Draculoader and SNOWLIGHT stager. The actor uses legitimate services like MS Graph and OneDrive for command-and-control infrastructure and establishes backdoor access through proxy servers using tools written in Simplified Chinese.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
NetDraft FringePorch CloudSorcerer VSHELL SNOWLIGHT SNOWRUST DeedRAT SNAPPYBEE ZingDoor Draculoader FinalDraft SquidDoor NosyDoor
Indicators of Compromise (6 / 50 total)
All IPv4 CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 3ddd90b99ee7ac3ec39e1d22b67c257d273a0970 2026-05-05
FileHash-SHA1 738d4398e7d11427051093ba8a6f37e51470795c 2026-05-05
FileHash-SHA1 7b6e094d98eb3f695e5856db4d8d22e11898cec9 2026-05-05
FileHash-SHA1 a1c3520282c81afabdefa4834b96563edf95c3c7 2026-05-05
FileHash-SHA1 c46bac27b5ca151afabd22c5546f78ae2ae3a20d 2026-05-05
FileHash-SHA1 f1551d3e5d144eef4e70a29dd3dc52fb22459d1f 2026-05-05