UTG-Q-015 is a threat actor associated with compromises of Chinese developer forums disclosed in December 2024 and subsequent campaigns against government organizations, enterprises, financial institutions, blockchain and Web3 services, and Linux-based artificial intelligence research infrastructure. Its operations combine exploitation of public-facing applications, distributed scanning, password brute-forcing, watering-hole attacks, and instant-messaging phishing. A specific country of origin, state affiliation, and dominant motivation have not been established with high confidence. During March and April 2025, UTG-Q-015 scanned and compromised public-facing servers, exploiting vulnerabilities including CVE-2021-38647, CVE-2017-12611, and CVE-2017-9805. Following successful access, it deployed Cobalt Strike and modified nps tunneling software, and used fscan and successfully brute-forced passwords to attempt lateral movement. Its watering-hole campaign compromised more than 100 websites, including blockchain homepages, Bitcoin administration interfaces, electronic-signature management systems, and GitLab login pages. Injected JavaScript presented fraudulent update prompts that delivered malicious payloads, including lightweight .NET backdoors supporting command execution and file uploads. Against financial institutions, UTG-Q-015 combined perimeter-server exploitation with instant-messaging lures and multistage payload delivery. Compromised institutional infrastructure served as payload staging points, and downloaders were loaded in memory. Its Linux operations used Xnote, Ghost, and Vshell backdoors. In 2025, these operations included exploitation of an unauthorized-access vulnerability in ComfyUI-Manager to deliver a malicious model and exploitation of CVE-2023-48022 against AI research servers, followed by reverse-shell access, script execution, and Vshell deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
By April this batch of nodes started exploiting Nday vulnerabilities such as CVE-2021-38647, CVE-2017-12611, and CVE-2017-9805.
By April this batch of nodes started exploiting Nday vulnerabilities such as CVE-2021-38647, CVE-2017-12611, and CVE-2017-9805.
By April this batch of nodes started exploiting Nday vulnerabilities such as CVE-2021-38647, CVE-2017-12611, and CVE-2017-9805.
CVE-2023-48022 was used to hack into domestic AI-related research servers back in April, bouncing the shell and then executing bash scripts and plugins with the same origin as above, eventually loading Vshell.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UTG-Q-015 is a Southeast Asian threat actor targeting government, enterprise, blockchain, and financial institutions using N-day vulnerabilities and phishing tactics.
UTG-Q-015 is a Southeast Asia-based threat actor known for exploiting 0-day and 1-day vulnerabilities to conduct data exfiltration, espionage, and financially motivated attacks. The group targets government, enterprise, blockchain, Web3, financial tech, and AI research sectors using a variety of techniques including watering hole campaigns, phishing, brute-forcing, and lateral movement. They deploy backdoors and leverage open-source and supply chain vulnerabilities.
A Chinese-speaking group described as operating from Southeast Asia and providing penetration and intelligence services to regional companies and institutions. Its reported activities include retaliatory compromises of programming forums, brute-force attacks and vulnerability exploitation against public-facing servers, watering-hole campaigns, phishing against financial institutions, and compromises of Linux-based AI research systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.