Cisco Talos security researchers have discovered a new hacking group named UAT-5918 , which has been attacking critical infrastructure in Taiwan since at least 2023 .

Cisco Talos says that UAT-5918 attempts to maintain long-term access to compromised systems to steal information and credentials. The hackers use a combination of web shells and open source tools to carry out malicious activities and establish persistence on victims' networks.
Hackers mainly target companies in the following industries: information technology, telecommunications, academia, and healthcare.
See also: Cyber espionage: Aquatic Panda hackers targeted 7 organizations
Researchers believe this is an APT groupthat seeks to establish long-term access to victim environments. Commonalities have also been observed with several Chinese groups, monitored as Volt Typhoon, Flax Typhoon, Tropic Trooper, Earth Estries, and Dalbit.
How do attacks work?
The attacks involve exploiting N-day vulnerabilities in unpatched web and application servers exposed to the internet. Thanks to these vulnerabilities, hackers gain access to the victim's system , and then install open source tools to conduct reconnaissance, gather system information, and lateral movement.
Then, UAT-5918 hackers use Fast Reverse Proxy (FRP) and Neo-reGeorge to create reverse proxy tunnels to access compromised endpoints via remote hosts (controlled by the attackers).
See also: Hackers exploit Apache Tomcat RCE vulnerability
Security researchers also used tools such as Mimikatz, LaZagne, BrowserDataLite (a browser-based extractor for collecting credentials), Chopper web shell, Crowdoor , and SparrowDoor.

BrowserDataLite, in particular, steals login information, cookies, and browsing history from browsers. The threat actor also engages in systematic data theft by scanning local and shared drives for data of interest.
See also: Hackers exploit Checkpoint driver in BYOVD attacks
The fact that UAT-5918 hackers are focused on long-term access and credential collection suggests that their primary goal is espionage and data theft, which could have serious consequences for organizations in the region. Furthermore, the use of open source tools and web shells makes detection more difficult.
If this attack continues or expands, it could affect government agencies, private companies, and infrastructure networks, reinforcing the need for increased surveillance and improved security measures. Taiwan needs to strengthen its defenses against such threats by incorporating more advanced detection and rapid response technologies.
source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
