UAT-7237

First seen
2022-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:23:30

Targeted industries: technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:tw

Context

UAT-7237 is a Chinese-speaking APT group that has been active since at least 2022, primarily targeting web infrastructure entities in Taiwan. They utilize a customized Shellcode loader known as “SoundBill” to execute shellcode, including Cobalt Strike payloads, and rely on SoftEther VPN clients and RDP for persistence and access. UAT-7237 employs techniques such as credential extraction using Mimikatz, reconnaissance with WMI-based tools, and selective deployment of web shells. Their operations indicate a focus on long-term persistence and stealth, with a preference for open-sourced and customized tooling.

Reports & references

  • Cisco Talos — Uat 7237 Targets Web Hosting Infra (report)
  • Palo Alto Unit 42 — Cl Sta 1062 Tinyrct Backdoor (report)

External references