UAT-9686

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:22:24

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

UAT-9686 is a Chinese state-sponsored APT known for targeting networking infrastructure and edge appliances through a sophisticated espionage campaign. They exploit a critical flaw in the Cisco AsyncOS Spam Quarantine interface to gain root access and deploy custom malware, including AquaShell, along with Python scripts that execute natively. Their operations involve reverse tunneling and log purging, demonstrating a methodical approach to compromising communication infrastructure. Talos has observed overlaps in TTPs and tooling with other Chinese-nexus threat actors, indicating a consistent operational pattern.

Exploited vulnerabilities

  • CVE-2025-20393 (vulnerability)

Reports & references

  • secpod.com — Zero Day Crisis Cve 2025 20393 Unpatched On Cisco Email Gateways Exploited By China Linked Hackers (report)
  • Cisco Talos — Uat 9686 (report)

External references