UAT-7237
- First seen
- 2022-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:23:30
Targeted industries: technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:tw
Context
UAT-7237 is a Chinese-speaking APT group that has been active since at least 2022, primarily targeting web infrastructure entities in Taiwan. They utilize a customized Shellcode loader known as “SoundBill” to execute shellcode, including Cobalt Strike payloads, and rely on SoftEther VPN clients and RDP for persistence and access. UAT-7237 employs techniques such as credential extraction using Mimikatz, reconnaissance with WMI-based tools, and selective deployment of web shells. Their operations indicate a focus on long-term persistence and stealth, with a preference for open-sourced and customized tooling.
Reports & references
- Cisco Talos — Uat 7237 Targets Web Hosting Infra (report)
- Palo Alto Unit 42 — Cl Sta 1062 Tinyrct Backdoor (report)