Cisco Talos observed that the Chinese APT group UAT-8302 has been targeting government agencies in South America since at least late 2024 and government agencies in southeastern Europe since 2025.

After the initial breach, the group deploys custom malware on the systems, which has been used by other hacking groups linked to China.
One of the most notable malware is a .NET-based backdoor called NetDraft (also known as NosyDoor), a C# variant of FINALDRAFT (also known as Squidoor). Previously, it was used by the Ink Dragon, CL-STA-0049, Earth Alux, Jewelbug, and REF7707 groups.
ESET is tracking the use of NosyDoor by a group called LongNosedGoblin. Interestingly, the same malware has also been deployed against Russian IT by a threat actor referred to as Erudite Mogwai (according to Russian cybersecurity firm Solar).
See also: MetInfo CMS vulnerability exploited for RCE attacks
UAT-8302: What other tools does the team use?
– CloudSorcerer, a backdoor observed in attacks against Russian entities
– SNOWLIGHT, a VShell stager used by UNC5174, UNC6586 and UAT-6382
– Deed RAT (also known as Snappybee) and Zingdoor, which were developed by Earth Estries in late 2024.
– Draculoader, a shellcode loader used to deliver Crowdoor and HemiGate.
"The malware deployed by UAT-8302 shows connections to several other threat groups, suggesting at least a close functional relationship between them," said Talos researchers Jungsoo An, Asheer Malhotra, and Brandon White.
“Overall, the various malicious artifacts deployed by UAT-8302 indicate that the group has access to tools used by other advanced APT actors. All have been linked to China or Chinese-speaking actors.“.
See also: ScarCruft hacks gaming platform to distribute BirdCall malware

How does the team work?
It is currently unknown what initial access methods the group uses to enter target networks, but it is likely exploiting zero-day and N-day vulnerabilities in web applications.
Once they gain access, attackers conduct reconnaissance to map the network, and use open source tools (such as gogo) to perform automated scanning and move laterally in the environment. The attack chains culminate in the deployment of NetDraft, CloudSorcerer (version 3.0), and VShell.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
UAT-8302 has also been observed using a variant of SNOWLIGHT, called SNOWRUST, to download the VShell payload from a remote server and execute it. In addition to using custom malware, the threat actor creates alternative means of backdoor using tools and VPN such as Stowaway and SoftEther VPN.
Overall, UAT-8302’s activity highlights the continued evolution of state-sponsored cyberthreats and their shift towards more complex and collaborative business models. The use of common tools, shared infrastructure, and the use of advanced malware families reveal a highly organized attack ecosystem in which distinguishing between different groups is becoming increasingly difficult. The targeting of government entities in critical geopolitical regions underscores that cyberattacks have become a key tool for strategic influence and intelligence gathering.
See also: SimpleHelp and ScreenConnect misused for phishing attacks
These findings make it clear that organizations, especially government agencies, must invest in advanced capabilities for detection, continuous monitoring and timely response to security incidents. At the same time, international cooperation in the field of cybersecurity and the exchange of information on new attack techniques and infrastructures are more necessary than ever. In an environment where threat actors operate in a coordinated manner and with increased technical complexity, proactive defense and collective preparedness are key factors for protection.

Cooperation between Chinese threat actors
The findings highlight a trend of sophisticated collaborative tactics between multiple groups aligned with China. In October 2025, Trend Micro shed light on a phenomenon called Premier Pass-as-a-Service, where initial access gained by Earth Estries was passed on to Earth Naga for further exploitation, obscuring attribution efforts. This collaboration appears to have been in place since at least late 2023.
“Premier Pass-as-a-Service provides immediate access to critical assets, reducing the time spent on reconnaissance, initial exploitation, and lateral movement phases,” Trend Micro said. “While the full extent of this model is not yet known, the limited number of observed incidents, combined with the substantial risk of exposure that such a service entails, suggests that access is likely limited to a small circle of threat actors.”
