UAT-8616

First seen
2023-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:25:37

Targeted industries: energy-and-utilities government-and-public-sector technology-and-telecommunications

Context

UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.

Exploited vulnerabilities

  • CVE-2022-20775 (vulnerability)
  • CVE-2026-20127 (vulnerability)

Reports & references

  • Cisco Talos — Uat 8616 Sd Wan (report)

External references