Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-03

UTA0178

As of 2026-07-02, UTA0178 is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware, vulnerability. ATT&CK coverage spans 44 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1041 (Exfiltration Over C2 Channel).

Tracked threats
44 critical
First seen
2026-03-30
Last seen
2026-04-02
ATT&CK techniques
44across 4 of 4 threats
Related CVEs
3Referenced by its activity
4 tracked threat(s) · Categories: MALWARE, VULNERABILITY

Activity timeline

UTA0178 appears in 4 tracked threats between and ; the busiest month was 2026-04 with 3 reports.

ATT&CK techniques observed

44 techniques observed across 4 of 4 tracked threats · Credential Access (6), Command and Control (5), Persistence (5), Stealth (formerly Defense Evasion) (4), Collection (3), Discovery (3)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 4 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 4 of 4 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 4 of 4 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 4 of 4 tracked threats
  • T1505 Server Software Component — Persistenceobserved in 4 of 4 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 4 tracked threats
  • T1090 Proxy — Command and Controlobserved in 3 of 4 tracked threats
  • T1547 Boot or Logon Autostart Execution — Persistenceobserved in 3 of 4 tracked threats
  • T1572 Protocol Tunneling — Command and Controlobserved in 3 of 4 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 3 of 4 tracked threats
  • T1020 Automated Exfiltration — Exfiltrationobserved in 2 of 4 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 2 of 4 tracked threats

Tracked threats

Related CVEs

3 CVEs referenced by tracked UTA0178 activity