Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-02

UAT-8616

Also known as:UAT8616

As of 2026-07-02, UAT-8616 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning vulnerability, zero day. Also known as UAT8616. ATT&CK coverage spans 57 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1068 (Exploitation for Privilege Escalation), T1046 (Network Service Discovery).

Tracked threats
65 critical · 1 high
First seen
2026-02-26
Last seen
2026-07-02
ATT&CK techniques
57across 6 of 6 threats
Related CVEs
8Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 6 tracked threat(s) · Categories: VULNERABILITY, ZERO_DAY

Activity timeline

UAT-8616 appears in 6 tracked threats between and ; the busiest month was 2026-03 with 2 reports.

ATT&CK techniques observed

57 techniques observed across 6 of 6 tracked threats · Persistence (8), Defense Impairment (7), Stealth (formerly Defense Evasion) (6), Command and Control (5), Discovery (5), Collection (4)
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 6 of 6 tracked threats
  • T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 5 of 6 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 4 of 6 tracked threats
  • T1078 Valid Accounts — Privilege Escalationobserved in 4 of 6 tracked threats
  • T1133 External Remote Services — Initial Accessobserved in 4 of 6 tracked threats
  • T1498 Network Denial of Service — Impactobserved in 4 of 6 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 4 of 6 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 3 of 6 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 3 of 6 tracked threats
  • T1090 Proxy — Command and Controlobserved in 3 of 6 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 3 of 6 tracked threats
  • T1505 Server Software Component — Persistenceobserved in 3 of 6 tracked threats
  • T1548 Abuse Elevation Control Mechanism — Privilege Escalationobserved in 3 of 6 tracked threats
  • T1685.006 Clear Linux or Mac System Logs — Defense Impairmentobserved in 3 of 6 tracked threats
  • T1021.004 SSH — Lateral Movementobserved in 2 of 6 tracked threats

Tracked threats

Related CVEs

8 CVEs referenced by tracked UAT-8616 activity