UAT-8616
- First seen
- 2023-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:25:37
Targeted industries: energy-and-utilities government-and-public-sector technology-and-telecommunications
Context
UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.
Exploited vulnerabilities
- CVE-2022-20775 (vulnerability)
- CVE-2026-20127 (vulnerability)
Reports & references
- Cisco Talos — Uat 8616 Sd Wan (report)