Activity timeline
UAT-9244 appears in 3 tracked threats between and ; the busiest month was 2026-03 with 1 report.
ATT&CK techniques observed
- T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
- T1505.003 Web Shell — Persistenceobserved in 3 of 3 tracked threats
- T1573.001 Symmetric Cryptography — Command and Controlobserved in 3 of 3 tracked threats
- T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 2 of 3 tracked threats
- T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 2 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
- T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
- T1057 Process Discovery — Discoveryobserved in 2 of 3 tracked threats
Tracked threats
- FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT, Terndoor, Mofu Loader)CRITICAL
- FamousSparrow APT Multi-Wave Intrusion at Azerbaijani Oil & Gas Company — Evolved Two-Stage DLL Sideloading Delivers Deed RAT (0xFF66ABCD) and Terndoor via Mofu LoaderCRITICAL
- UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American TelecomHIGH