UAT-9221 is a threat actor tracked by Cisco Talos as a newly identified cluster of activity. The actor has been observed leveraging the VoidLink framework in campaigns, and its operational history may extend back to 2019, including activity that predates observed use of VoidLink. Publicly available information in this context is limited, and there is not enough high-confidence evidence here to characterize the actor’s victimology, geographic focus, sector targeting, broader toolset, or state affiliation. Based on confirmed reporting, UAT-9221 is best described as an emerging tracked actor associated with use of the VoidLink framework over a multi-year period.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly reported activity cluster observed by Cisco Talos leveraging the VoidLink framework in campaigns; assessed activity potentially dating back to 2019 (including possible operations prior to adopting VoidLink).
Newly identified activity cluster observed by Cisco Talos conducting campaigns leveraging VoidLink; activity possibly dating back to 2019 (including operations predating use of VoidLink).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.