UAT-9686 is a China-linked advanced persistent threat actor assessed with moderate confidence to be part of the Chinese cyber-espionage ecosystem. The group is known for exploiting a zero-day vulnerability in Cisco AsyncOS affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances, with activity observed from at least late November 2025. Reporting links the actor’s tooling, infrastructure, and tradecraft to patterns previously associated with Chinese intrusion sets including APT41 and UNC5174, although UAT-9686 is tracked as a distinct cluster. The actor’s operations demonstrate a focus on exploitation of public-facing edge infrastructure for initial access, followed by stealthy persistence and post-compromise access enablement. In the Cisco appliance campaign, UAT-9686 deployed the custom Python backdoor AquaShell as a persistence mechanism and command execution implant. It also used AquaTunnel and Chisel to establish reverse tunnels and proxy traffic from compromised appliances, enabling sustained remote access and potential internal pivoting. To reduce forensic visibility, the actor used AquaPurge to remove or alter log evidence on compromised systems. Observed tradecraft includes unauthenticated exploitation of internet-exposed services, execution of commands with elevated privileges, installation of persistent backdoors, use of tunneling utilities for covert access, and log clearing for defense evasion. The campaign has been characterized as sophisticated espionage activity rather than financially motivated intrusion or ransomware operations. Public reporting specifically ties UAT-9686 to compromises of Cisco email security infrastructure and describes the actor as targeting a limited subset of exposed appliances with non-standard configurations. Some reporting further characterizes the victimology as including telecommunications and critical infrastructure organizations, but the strongest corroborated evidence supports targeting of organizations operating vulnerable Cisco secure email infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus APT exploiting a Cisco AsyncOS zero-day to target Cisco Secure Email Gateway / Secure Email and Web Manager appliances.
China-linked APT actor exploiting a Cisco AsyncOS zero-day against secure email gateway products.
Activity cluster associated (by Talos) with deployment of the AquaShell Python backdoor against Cisco Secure Management Appliance (SMA) environments; observed behavior included backdoor deployment with no follow-on activity in the described incident.
Exploiting a Cisco zero-day affecting Secure Email Gateway and Secure Email and Web Manager.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.