Briefing

China‑Nexus APT Group UAT‑8302 Targets South American and European Governments

security
by [email protected] (The Hacker News) ·

Monitor for UAT‑8302 indicators and update threat intelligence feeds.

What to do now

Monitor threat intelligence for UAT‑8302 indicators and update security controls.

Summary

An advanced persistent threat (APT) group linked to China has been active against government entities in South America since late 2024 and in southeastern Europe in 2025. Cisco Talos tracks the activity under the moniker UAT‑8302, cataloguing the group's tactics and tools. The attackers deploy custom‑made malware families during post‑exploitation to maintain persistence and exfiltrate data. The malware is tailored to target specific government infrastructure, leveraging zero‑day exploits discovered in public and private networks. The threat actors have demonstrated a pattern of lateral movement within target networks, using credential dumping and encrypted command‑and‑control channels. Recent reports indicate that the APT has expanded its footprint to include diplomatic missions and intelligence agencies. Security teams are advised to update detection rules for the custom malware signatures and to monitor for unusual outbound traffic patterns. The group’s continued evolution underscores the need for continuous threat hunting and rapid incident response.

Key changes

  • China‑nexus APT group active against South American governments since late 2024
  • Expanded attacks to southeastern European government agencies in 2025
  • Cisco Talos tracks the group as UAT‑8302, documenting tactics and malware
  • Post‑exploitation involves custom‑made malware families tailored for persistence
  • Malware uses credential dumping and encrypted C2 channels for lateral movement
  • Recent activity includes targeting diplomatic missions and intelligence agencies

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting