UAT-9244 is a China-nexus advanced persistent threat cluster engaged in cyberespionage against telecommunications infrastructure in South America since at least 2024. The activity is assessed to overlap closely with FamousSparrow and to share overlap with Tropic Trooper. Reporting has also linked related FamousSparrow activity to an intrusion against an Azerbaijani oil and gas company, indicating broader espionage victimology beyond telecom, but the strongest direct attribution for UAT-9244 centers on South American telecom providers. The cluster operates across Windows, Linux, and network edge environments and has used three notable malware families: TernDoor, PeerTime, and BruteEntry. TernDoor is a Windows backdoor in the CrowDoor/SparrowDoor lineage that has been delivered through DLL sideloading, executed in memory, and injected into legitimate processes. It supports remote command execution, file operations, system information gathering, persistence through scheduled tasks, services, and Run-key mechanisms, and includes a malicious driver used to suspend, resume, or terminate processes. PeerTime is a multi-architecture Linux backdoor, including variants for ARM, AArch64, MIPS, and PowerPC, enabling compromises of servers, routers, embedded appliances, and other telecom-supporting infrastructure. It uses BitTorrent-style peer-to-peer communications for tasking and payload retrieval, can disguise process names, and has shown awareness of containerized environments. BruteEntry is a Go-based brute-force and scanning utility used to convert compromised edge devices into Operational Relay Boxes that support scanning, credential attacks, relay activity, and follow-on access expansion. Observed tradecraft includes exploitation of exposed or unpatched internet-facing services, use of weak credentials, web-shell deployment in related FamousSparrow-linked operations, DLL sideloading, in-memory execution, process injection, persistence via scheduled tasks and services, registry-based persistence, anti-analysis measures, and use of peer-to-peer communications to reduce dependence on centralized command infrastructure. BruteEntry has been used to target exposed SSH, PostgreSQL, and Apache Tomcat services, while compromised Linux systems have been repurposed for scanning, brute-force activity, lateral movement support, and covert relay operations. The actor's targeting of critical communications infrastructure, emphasis on durable access, and tooling choices are consistent with long-term intelligence collection rather than disruptive or destructive operations. Available evidence supports espionage as the dominant motivation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
55 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked activity cluster targeting telecom and Linux infrastructure, using multi-platform malware including PeerTime to establish persistence and convert compromised systems into operational relay boxes for scanning, brute-force activity, covert communications, and lateral movement.
Activity cluster reported by Cisco Talos and linked with high confidence to FamousSparrow; associated in the content with Terndoor deployment patterns including driver-backed behavior.
Activity cluster reported targeting South American telecommunications providers using three new malware implants.
Targeting South American telecommunications providers using three newly reported malware implants.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.