Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-02

UAT-9686

As of 2026-09-15, UAT-9686 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability. ATT&CK coverage spans 27 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1027 (Obfuscated Files or Information), T1059 (Command and Scripting Interpreter).

Tracked threats
22 critical
First seen
2026-02-05
Last seen
2026-09-14
ATT&CK techniques
27across 2 of 2 threats
Related CVEs
2Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 2 tracked threat(s) · Categories: VULNERABILITY

Activity timeline

UAT-9686 appears in 2 tracked threats between and ; the busiest month was 2026-02 with 1 report.

ATT&CK techniques observed

27 techniques observed across 2 of 2 tracked threats · Command and Control (5), Stealth (formerly Defense Evasion) (4), Execution (3), Lateral Movement (3), Collection (2), Persistence (2)
  • T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 2 tracked threats
  • T1059.004 Unix Shell — Executionobserved in 2 of 2 tracked threats
  • T1059.006 Python — Executionobserved in 2 of 2 tracked threats
  • T1068 Exploitation for Privilege Escalation — Privilege Escalationobserved in 2 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 2 tracked threats
  • T1090 Proxy — Command and Controlobserved in 2 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
  • T1505.003 Web Shell — Persistenceobserved in 2 of 2 tracked threats
  • T1572 Protocol Tunneling — Command and Controlobserved in 2 of 2 tracked threats
  • T1587.004 Exploits — Resource Developmentobserved in 2 of 2 tracked threats
  • T1685.006 Clear Linux or Mac System Logs — Defense Impairmentobserved in 2 of 2 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1021.004 SSH — Lateral Movementobserved in 1 of 2 tracked threats

Tracked threats

Related CVEs

2 CVEs referenced by tracked UAT-9686 activity