Security researchers from Cisco Talos have identified a new advanced persistent threat (APT) actor named UAT-5918 that has been conducting sophisticated attacks against Taiwanese critical infrastructure since at least 2023.
The threat group appears primarily motivated by establishing long-term access for information theft, targeting sectors including critical infrastructure, information technology, telecommunications, academia, and healthcare.
## Attack Methods and Tools
UAT-5918’s attack methodology begins with exploiting unpatched vulnerabilities in internet-facing web and application servers. Once initial access is gained, the group deploys various tools for:
– Network reconnaissance
– System information gathering
– Lateral movement within compromised networks
The group utilizes several specialized tools for maintaining persistence:
– Fast Reverse Proxy (FRP) and Neo-reGeorge to establish reverse proxy tunnels
– Credential harvesting tools including Mimikatz, LaZagne, and BrowserDataLite
– Web shells such as Chopper, Crowdoor, and SparrowDoor
BrowserDataLite specifically targets login credentials, cookies, and browsing history from web browsers, enabling deeper network penetration.
## Connections to Other Threat Groups
Researchers note tactical similarities between UAT-5918 and several Chinese hacking groups, including Volt Typhoon, Flax Typhoon, Tropic Trooper, Earth Estries, and Dalbit.
The group’s post-compromise activities appear to be conducted manually, with systematic data theft as the primary objective. They also deploy web shells across discovered sub-domains and internet-accessible servers to create multiple entry points into victim organizations.
