UTA0388 is a China-aligned cyber-espionage threat actor active since at least 2025 and associated with multilingual spear-phishing campaigns designed to deliver the GOVERSHELL backdoor family. The actor has targeted organizations and individuals across North America, Europe, and Asia, with reporting indicating a particular interest in Asian geopolitical issues and a special focus on Taiwan. Observed victimology includes Taiwan’s semiconductor sector, U.S. academia, U.S. think tanks, and organizations representing Chinese minorities. Activity has also been linked to targeting of a Serbian aviation-related government department and other European institutions. UTA0388 overlaps with the cluster tracked by Proofpoint as UNK_DropPitch, and GOVERSHELL has been assessed as a successor to the earlier HealthKick malware family. UTA0388 is notable for using large language models, including ChatGPT, to help generate spear-phishing content and support malicious workflows. Campaigns used fabricated personas and organizations, often impersonating senior researchers or analysts, and delivered lures in multiple languages including English, Chinese, Japanese, French, and German. Later operations adopted rapport-building phishing, in which the actor exchanged emails with targets before sending malicious links. The actor also abused legitimate cloud and email services for staging and delivery. The actor’s malware delivery commonly relied on links to remotely hosted ZIP or RAR archives containing a benign executable and a malicious DLL. Execution was achieved through DLL side-loading or search-order hijacking, after which GOVERSHELL established persistence via scheduled tasks and enabled remote command execution. Multiple GOVERSHELL variants have been documented, including HealthKick, TE32, TE64, WebSocket, and Beacon. Across these variants, capabilities included command execution through cmd.exe or PowerShell, polling-based task retrieval, and encrypted command-and-control communications. The malware family appears to be under active development, with iterative changes in communications methods, execution flow, and operational tradecraft. High-confidence attribution to a China-aligned operator is supported by targeting patterns, Chinese-language development artifacts, and broader espionage-oriented victim selection. UTA0388’s dominant motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UTA0388 is a Chinese state-sponsored APT group using AI services to enhance spear-phishing operations, targeting high-value sectors.
Conducting China-nexus cyberespionage-oriented spear-phishing campaigns using ChatGPT-generated lure content to deliver archive files (ZIP/RAR) that install the GOVERSHELL backdoor; leveraging common cloud/web services for staging and enabling PowerShell-based post-compromise activity via a Beacon variant.
China-aligned espionage activity conducting highly tailored spear-phishing (including rapport-building phishing) to deliver the GOVERSHELL backdoor via archives and DLL side-loading; also noted for using ChatGPT to generate phishing content and assist with malicious workflows.
Described as a China-aligned activity cluster (UTA0388) leveraging ChatGPT to automate multilingual spear-phishing.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.