Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-03

UAT-9244

Also known as:FamousSparrowOPERATOR PANDARedMikeSalt TyphoonUNC2286Earth EstriesTropic TrooperPirate PandaKeyBoy

As of 2026-06-10, UAT-9244 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning apt. Also known as FamousSparrow, OPERATOR PANDA, RedMike, Salt Typhoon. ATT&CK coverage spans 47 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1014 (Rootkit), T1071.001 (Web Protocols), T1082 (System Information Discovery).

Tracked threats
32 critical · 1 high
First seen
2026-03-07
Last seen
2026-06-10
ATT&CK techniques
47across 3 of 3 threats
Related CVEs
5Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 3 tracked threat(s) · Categories: APT

Activity timeline

UAT-9244 appears in 3 tracked threats between and ; the busiest month was 2026-03 with 1 report.

ATT&CK techniques observed

47 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (13), Command and Control (6), Execution (5), Persistence (5), Resource Development (4), Discovery (3)
  • T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 3 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 3 tracked threats
  • T1505.003 Web Shell — Persistenceobserved in 3 of 3 tracked threats
  • T1573.001 Symmetric Cryptography — Command and Controlobserved in 3 of 3 tracked threats
  • T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 3 of 3 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 2 of 3 tracked threats
  • T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 2 of 3 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 3 tracked threats
  • T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 2 of 3 tracked threats

Tracked threats

Related CVEs

5 CVEs referenced by tracked UAT-9244 activity