UAT-10608

Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:26:16

Targeted industries: technology-and-telecommunications

Context

UAT-10608 is a threat cluster observed by Cisco Talos conducting a large-scale, automated credential-harvesting campaign against public-facing web applications, especially Next.js deployments, using a custom framework called NEXUS Listener to extract and exfiltrate secrets such as credentials, SSH keys, cloud tokens, and API keys. The activity has been linked to broad opportunistic scanning and at least 766 compromised hosts across multiple regions and cloud providers.

Reports & references

  • Cisco Talos — Uat 10608 Inside A Large Scale Automated Credential Harvesting Operation Targeting Web Applications (report)

External references