UTG-Q-008
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:15:46
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn
Context
UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China. They utilize a massive botnet network for espionage activities, including reconnaissance, brute-forcing, and Trojan component delivery. The actor has a history of compromising thousands of servers in China using a password dictionary based on Chinese Pinyin. UTG-Q-008 operates during standard working hours in the UTC+8 time zone, with potential ties to Eastern Europe.
Reports & references
- ti.qianxin.com — Operation Veles Decade Long Espionage Targeting The Global Research And Education Sector En (report)