UAT-7237 is a Chinese-speaking advanced persistent threat group active since at least 2022 that has targeted web infrastructure entities in Taiwan, including a Taiwanese web hosting provider, with the apparent objective of establishing long-term access in high-value environments. The cluster is assessed to be closely related to, and likely a subgroup of, UAT-5918, with overlap noted against broader Chinese intrusion activity associated with clusters such as Volt Typhoon and Flax Typhoon. UAT-7237 is distinguished by heavier reliance on Cobalt Strike, selective rather than widespread web shell deployment, and persistent access through RDP and SoftEther VPN. The actor has been observed gaining initial access by exploiting known vulnerabilities in unpatched internet-facing servers. After compromise, it conducts rapid host and network reconnaissance, including system fingerprinting, domain and administrative-share enumeration, and SMB discovery. For lateral movement and remote execution, UAT-7237 uses WMI-based tooling such as SharpWMI and WMICmd, along with other open-source utilities and native Windows commands. A notable element of the toolchain is SoundBill, a custom Chinese-language shellcode loader based on VTHello that decodes and executes local shellcode and can launch arbitrary payloads, including Cobalt Strike and credential-theft functionality associated with Mimikatz. UAT-7237 has also used JuicyPotato for privilege escalation and command execution, modified system settings to weaken security controls, enabled cleartext credential storage, searched for stored remote-access credentials, and dumped LSASS memory to obtain credentials. Network scanning and internal discovery have included tools such as FScan and SMB-focused enumeration. Operationally, UAT-7237 emphasizes persistence and post-compromise access. SoftEther VPN appears to have been used over an extended period, and observed configuration artifacts indicate operator proficiency in Simplified Chinese. The actor's tradecraft aligns with espionage-oriented intrusion activity focused on durable access, credential theft, and continued presence inside strategically relevant Taiwanese infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-speaking APT cluster targeting Taiwanese web infrastructure entities using customized open-source tools to establish long-term access.
China-linked espionage cluster targeting a Taiwanese web hosting provider to gain long-term access to victims’ VPN and cloud infrastructure; relies on Cobalt Strike and a mix of custom/open-source tooling for persistence, credential theft, and command execution.
China-linked espionage cluster targeting a Taiwanese web hosting provider to gain long-term access to victims’ VPN and cloud infrastructure; relies on Cobalt Strike and a mix of custom/open-source tooling for persistence, credential theft, and command execution.
UAT-7237 is conducting targeted attacks against Taiwanese web infrastructure using a custom toolset.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.