Exposed: Chinese-Linked APT Group UAT-5918 Infiltrates Taiwan’s Critical Infrastructure


# New APT Group UAT-5918 Targets Taiwan’s Critical Infrastructure

Security researchers from Cisco Talos have identified a new advanced persistent threat (APT) actor named UAT-5918 that has been conducting sophisticated attacks against Taiwanese critical infrastructure since at least 2023.

The threat group appears primarily motivated by establishing long-term access for information theft, targeting sectors including critical infrastructure, information technology, telecommunications, academia, and healthcare.

## Attack Methods and Tools

UAT-5918’s attack methodology begins with exploiting unpatched vulnerabilities in internet-facing web and application servers. Once initial access is gained, the group deploys various tools for:

– Network reconnaissance
– System information gathering
– Lateral movement within compromised networks

The group utilizes several specialized tools for maintaining persistence:
– Fast Reverse Proxy (FRP) and Neo-reGeorge to establish reverse proxy tunnels
– Credential harvesting tools including Mimikatz, LaZagne, and BrowserDataLite
– Web shells such as Chopper, Crowdoor, and SparrowDoor

BrowserDataLite specifically targets login credentials, cookies, and browsing history from web browsers, enabling deeper network penetration.

## Connections to Other Threat Groups

Researchers note tactical similarities between UAT-5918 and several Chinese hacking groups, including Volt Typhoon, Flax Typhoon, Tropic Trooper, Earth Estries, and Dalbit.

The group’s post-compromise activities appear to be conducted manually, with systematic data theft as the primary objective. They also deploy web shells across discovered sub-domains and internet-accessible servers to create multiple entry points into victim organizations.

Share This Article