A threat actor, possibly linked to China, has been targeting critical infrastructure in North America for at least the past year. Cisco Talos, which monitors activity under the name UAT-8837, has assessed it as an APT threat actor and noted similarities to other campaigns conducted by threat actors in the region. The group is exploiting, among other things, a zero-day vulnerability in Sitecore.

The cybersecurity firm noted that the threat actor is “primarily tasked with gaining initial access to high-value organizations.”
“ After gaining initial access — either through successful exploitation of vulnerable servers or through the use of compromised credentials — UAT-8837 primarily deploys open source tools to collect sensitive information such as credentials, security settings, and domain and Active Directory (AD) information to create multiple access channels to its victims ,” the company added
See also: Google Fast Pair: Vulnerabilities allow attackers to track you
Zero-day exploit in Sitecore
UAT-8837 reportedly recently exploited a critical zero-day vulnerability in Sitecore (CVE-2025-53690, CVSS score: 9.0) to gain initial access, with the attack sharing similarities in TTP, tools, and infrastructure with a campaign described by Mandiant in September 2025.
While it is unclear whether the two activities are the work of the same hacking group, the similarities suggest that UAT-8837 may have access to zero-day exploits to carry out cyberattacks.
What happens after initial access?
Once the adversary gains a foothold in target networks, it conducts preliminary reconnaissance, followed by disabling RestrictedAdmin for Remote Desktop Protocol (RDP). This is a security feature that ensures that user credentials and other resources are not exposed to compromised remote hosts.
See also: Modular DS: Critical vulnerability in WordPress plugin

UAT-8837 also reportedly opens “cmd.exe” to conduct hands-on keyboard activity on the infected host and downloads various objects to enable post-compromise exploitation. Some of the notable tools are:
– GoTokenTheft, for stealing access tokens
– EarthWorm, for creating reverse tunnels to servers controlled by the attacker using SOCKS
– DWAgent, for persistent remote access and Active Directory identification
– SharpHound, for collecting Active Directory
– Impacket, for executing commands with elevated privileges
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
– GoExec, a Golang-based tool for executing commands on other connected remote endpoints within the victim's network
– Rubeus, a C#-based toolkit for interacting with and abusing Kerberos
– Certipy, a tool for Active Directory discovery and abuse
"UAT-8837 can execute a series of commands during the intrusion to obtain sensitive information, such as credentials, from victim organizations," researchers Asheer Malhotra, Vitor Ventura , and Brandon White.

“In a victim organization, UAT-8837 exported DLL-based shared libraries related to the victim's products. These libraries can be modified in the future (by attackers). This creates opportunities for supply chain breaches and reverse engineering to find vulnerabilities in these products.“.
See also: AWS CodeBuild: Misconfiguration put GitHub repos at risk
The revelation comes a week after it was revealed that another Chinese group, UAT-7290, was carrying out attacks against entities in South Asia and Southeast Europe, with the aim of espionage.
In recent years, concerns about Chinese threat actors targeting critical infrastructure have prompted Western governments to issue several warnings. Earlier this week, cybersecurity and intelligence agencies from Australia, Germany, the Netherlands, New Zealand, the United Kingdom and the United States warned of growing threats to operational technology (OT) environments.
