# UAT-9244

> As of 2026-06-10, UAT-9244 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning apt. Also known as FamousSparrow, OPERATOR PANDA, RedMike, Salt Typhoon. ATT&CK coverage spans 47 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1014 (Rootkit), T1071.001 (Web Protocols), T1082 (System Information Discovery).

- **Nation:** China
- **Tracked threats:** 3
- **Categories:** APT
- **Also known as:** FamousSparrow, OPERATOR PANDA, RedMike, Salt Typhoon, UNC2286, Earth Estries, Tropic Trooper, Pirate Panda, KeyBoy
- **As of:** 2026-06-10

## ATT&CK techniques observed

47 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (13), Command and Control (6), Execution (5), Persistence (5), Resource Development (4), Discovery (3).

- [T1014](https://intel.threadlinqs.com/technique/T1014) Rootkit — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 3 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 3 of 3 tracked threats
- [T1505.003](https://intel.threadlinqs.com/technique/T1505.003) Web Shell — Persistence — observed in 3 of 3 tracked threats
- [T1573.001](https://intel.threadlinqs.com/technique/T1573.001) Symmetric Cryptography — Command and Control — observed in 3 of 3 tracked threats
- [T1574.001](https://intel.threadlinqs.com/technique/T1574.001) DLL — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 2 of 3 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 2 of 3 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 3 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 2 of 3 tracked threats

## Tracked threats

- [FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT, Terndoor, Mofu Loader)](https://intel.threadlinqs.com/threat/TL-2026-0749) — CRITICAL
- [FamousSparrow APT Multi-Wave Intrusion at Azerbaijani Oil & Gas Company — Evolved Two-Stage DLL Sideloading Delivers Deed RAT (0xFF66ABCD) and Terndoor via Mofu Loader](https://intel.threadlinqs.com/threat/TL-2026-0509) — CRITICAL
- [UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom](https://intel.threadlinqs.com/threat/TL-2026-0191) — HIGH

## Related CVEs

5 CVEs referenced by tracked UAT-9244 activity.

- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UAT-9244
