Cyber & Technology — 2026-05-07
Cisco Talos Exposes China-Linked APT UAT-8302 Campaign Targeting Government Networks Across Continents
Cisco Talos on May 5 disclosed UAT-8302, a China-nexus APT targeting government entities in South America since at least late 2024 and southeastern Europe through 2025. Talos identifies the primary implant, NetDraft, as a .NET variant of the FINALDRAFT/SquidDoor family previously used by Jewelbug and REF7707; ESET independently tracks it as NosyDoor, attributed to a cluster it calls LongNosedGoblin. UAT-8302 also deployed CloudSorcerer version 3, previously linked by Kaspersky to attacks on Russian government entities, and VSHELL delivered via the SNOWLIGHT stager or a new Rust-based loader Talos tracks as SNOWRUST. Post-compromise tradecraft documented by Talos includes bulk Active Directory enumeration, Azure AD Connect credential extraction via adconnectdump.py, lateral movement through Impacket and WMI, and persistent access maintained through Stowaway proxy and SoftEther VPN tunnels.
AnalysisPer a single Cisco Talos report, UAT-8302's targeting of government networks in diplomatically low-visibility regions signals a deliberate Chinese collection expansion where bilateral costs of a response are minimal. Azure AD Connect credential harvesting is the campaign's highest-leverage move: by targeting hybrid identity infrastructure, the actor gained persistent cloud access that outlasts on-premises remediation. The convergence of CloudSorcerer, REF7707 tools, and Jewelbug tradecraft points either to a Chinese APT shared-tooling ecosystem or to false-flag seeding by a non-Chinese actor exploiting known PRC implants to misdirect attribution. Formal attribution to Beijing by any targeted government is
unlikely within the next 90 days; neither technical attribution capacity nor political leverage to absorb bilateral costs exists in the affected regions.
3 sources
- China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions - The Hacker News
- UAT-8302 and its box full of malware - Cisco Talos
- UAT-8302 Targets Government Agencies With Custom Malware and Open-Source Tools - GBHackers
View in full brief →