# UAT-8616

> As of 2026-07-02, UAT-8616 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning vulnerability, zero day. Also known as UAT8616. ATT&CK coverage spans 57 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1068 (Exploitation for Privilege Escalation), T1046 (Network Service Discovery).

- **Nation:** China
- **Tracked threats:** 6
- **Categories:** VULNERABILITY, ZERO_DAY
- **Also known as:** UAT8616
- **As of:** 2026-07-02

## ATT&CK techniques observed

57 techniques observed across 6 of 6 tracked threats. Tactics: Persistence (8), Defense Impairment (7), Stealth (formerly Defense Evasion) (6), Command and Control (5), Discovery (5), Collection (4).

- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 6 of 6 tracked threats
- [T1068](https://intel.threadlinqs.com/technique/T1068) Exploitation for Privilege Escalation — Privilege Escalation — observed in 5 of 6 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 4 of 6 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Privilege Escalation — observed in 4 of 6 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 4 of 6 tracked threats
- [T1498](https://intel.threadlinqs.com/technique/T1498) Network Denial of Service — Impact — observed in 4 of 6 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 4 of 6 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 3 of 6 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 3 of 6 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 3 of 6 tracked threats
- [T1098](https://intel.threadlinqs.com/technique/T1098) Account Manipulation — Persistence — observed in 3 of 6 tracked threats
- [T1505](https://intel.threadlinqs.com/technique/T1505) Server Software Component — Persistence — observed in 3 of 6 tracked threats
- [T1548](https://intel.threadlinqs.com/technique/T1548) Abuse Elevation Control Mechanism — Privilege Escalation — observed in 3 of 6 tracked threats
- [T1685.006](https://intel.threadlinqs.com/technique/T1685.006) Clear Linux or Mac System Logs — Defense Impairment — observed in 3 of 6 tracked threats
- [T1021.004](https://intel.threadlinqs.com/technique/T1021.004) SSH — Lateral Movement — observed in 2 of 6 tracked threats

## Tracked threats

- [Cisco Catalyst SD-WAN Manager Zero-Day Exploitation Chain (CVE-2026-20245, CVE-2026-20127, CVE-2026-20182)](https://intel.threadlinqs.com/threat/TL-2026-1064) — CRITICAL
- [Cisco Catalyst SD-WAN Manager CVE-2026-20245 — Actively Exploited 0-Day: Authenticated File-Upload Command Injection to Root](https://intel.threadlinqs.com/threat/TL-2026-0696) — HIGH
- [Cisco Catalyst SD-WAN CVE-2026-20182 — Critical Authentication Bypass Zero-Day Actively Exploited by UAT-8616 (CVSS 10.0, CISA KEV, ED 26-03)](https://intel.threadlinqs.com/threat/TL-2026-0516) — CRITICAL
- [CVE-2026-20127: Critical Cisco Catalyst SD-WAN Authentication Bypass Exploited by UAT-8616 Since 2023 (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-0236) — CRITICAL
- [CVE-2026-20127 Cisco Catalyst SD-WAN Zero-Day — UAT-8616 Authentication Bypass Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-0166) — CRITICAL
- [Cisco Catalyst SD-WAN Zero-Day (CVE-2026-20127) — UAT-8616 Active Exploitation Since 2023, Authentication Bypass to Admin, Critical Infrastructure Targeting](https://intel.threadlinqs.com/threat/TL-2026-0145) — CRITICAL

## Related CVEs

8 CVEs referenced by tracked UAT-8616 activity.

- [CVE-2026-20245](https://intel.threadlinqs.com/cve/CVE-2026-20245)
- [CVE-2026-20182](https://intel.threadlinqs.com/cve/CVE-2026-20182)
- [CVE-2026-20129](https://intel.threadlinqs.com/cve/CVE-2026-20129)
- [CVE-2026-20128](https://intel.threadlinqs.com/cve/CVE-2026-20128)
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127)
- [CVE-2026-20126](https://intel.threadlinqs.com/cve/CVE-2026-20126)
- [CVE-2026-20122](https://intel.threadlinqs.com/cve/CVE-2026-20122)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UAT-8616
