# UAT-10820

> As of 2026-09-08, UAT-10820 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 1 threat spanning threat intel.

- **Nation:** Russia
- **Tracked threats:** 1
- **Categories:** THREAT_INTEL
- **As of:** 2026-09-08

## Tracked threats

- [ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)](https://intel.threadlinqs.com/threat/TL-2026-2387) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UAT-10820
