UAT-8302 China-Nexus APT Campaign — NetDraft, CloudSorcerer v3, VSHELL/SNOWLIGHT, SNOWRUST, SNAPPYBEE/DeedRAT, ZingDoor, and Draculoader Targeting Government Entities in South America and Southeastern Europe — Threadlinqs Intelligence
As of 2026-05-30, UAT-8302 China-Nexus APT Campaign — NetDraft, CloudSorcerer v3, VSHELL/SNOWLIGHT, SNOWRUST, SNAPPYBEE/DeedRAT, ZingDoor, and Draculoader Targeting Government Entities in South America and Southeastern Europe is a high-severity apt threat attributed to UAT-8302 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 67 indicators of compromise.
Threat ID: TL-2026-0462 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: UAT-8302 · China · ESPIONAGE
Cisco Talos disclosed UAT-8302, a sophisticated China-nexus APT targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. The
On 5 May 2026, Cisco Talos researchers Jungsoo An, Asheer Malhotra, and Brandon White published a threat-spotlight disclosure of UAT-8302, a China-nexus advanced persistent threat actor primarily tasked with obtaining and maintaining long-term access to government and related entities worldwide. UAT-8302 has been targeting government entities in South America since at least late 2024 and expanded its targeting to government agencies in southeastern Europe in 2025. Talos assesses with high confidence that UAT-8302 is China-nexus based on heavy malware-portfolio overlap with multiple previously disclosed China-nexus clusters and the use of custom and open-source tooling written in Simplified Chinese.
Initial access methods are not directly observed in this campaign, but the actor's tooling overlaps with APT clusters known to exploit both zero-day and n-day vulnerabilities (e.g., UAT-6382's exploitation of Cityworks zero-day CVE-2025-0994 to deploy VSHELL via SNOWLIGHT). Once inside, UAT-8302 conducts extensive preliminary reconnaissance using Impacket, certutil, nslookup, net.exe, systeminfo, and ipconfig, then escalates to a custom-made PowerShell script ('whatpc.ps1') persisted via scheduled task (e.g., 'ReconLiteDebug', 'RunWhatPC') executing as SYSTEM. The script enumerates local groups and admin membership, network configuration, listening connections, SMB shares, AD users, computers, groups, and trust relationships via nltest, dsmod, and dsquery. Ping sweeps and SMB share-discovery loops over /24 subnets identify proliferation targets, and event logs (Security IDs such as 4768) are queried for administrator activity. Audit policy is enumerated via 'auditpol /get /category:*'. The actor downloads 'gogo' (a GoLang automated network scanner written in Simplified Chinese) directly from its GitHub release URL, alongside QScan, naabu, dddd, PortQry, and httpx.
UAT-8302 collects information using adconnectdump.py for Azure AD Connect / Entra ID Connect credential extraction, manual PowerShell Get-ADUser/Get-ADComputer/Get-ADGroup queries, AD Explorer snapshots packaged with 7zr.exe, and Get-WinEvent log harvests. A Chinese-language tool called 'SharpGetUserLoginIPRP' (deployed as C:\ProgramData\S.exe) extracts login information from domain controllers. MobaXterm credentials are stolen via MobaXtermDecryptor for SSH pivot.
Lateral movement is performed via Impacket and WMI remote process creation ('wmic /node:IP process call create', 'schtasks /S IP'), invoking BAT files that execute the malware on remote systems.
Custom malware deployment uses DLL side-loading triads: a benign signed executable, a malicious DLL loader, and an encoded data file. NetDraft (a .NET-based variant of FinalDraft/SquidDoor; ESET tracks the same family as 'NosyDoor' attributed to LongNosedGoblin; Solar reported NetDraft was used by Erudite Mogwai/LuckyStrike Agent against Russian IT in 2024) embeds a Fody/Costura-compressed .NET helper library Talos tracks as 'FringePorch'. NetDraft uses MS Graph API to communicate with its OneDrive-based C2 and can execute arbitrary commands, run .NET assemblies, perform file operations, and execute .NET plugins. Because NetDraft lacks native persistence, the C2 issues a scheduled-task creation command pointing to 'C:\ProgramData\Microsoft\Microsoft\Appunion.exe'.
CloudSorcerer v3 (an updated version of the malware Kaspersky disclosed in 2024 against Russian government) uses a side-loading triad with executables 'Yandex.exe' and 'VMtools.exe' loading 'mspdb60.dll', which decrypts an INI shellcode file ('test.ini' or 'VM.ini') and injects it into named processes. The shellcode behaves differently per host process: 'dpapimig.exe' gathers system info and listens on a named pipe for commands; 'spoolsv.exe' contacts a GitHub repository or GameSpot profile to obtain C2 information (URL, OneDrive/Dropbox token); 'mspaint.exe' or 'browser' triggers injection back into dpapimig.exe/spoolsv.exe.
VSHELL is delivered via a rel
Target sectors: government
Target regions: South America, Southeastern Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 67 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1588, T1587, T1190, T1059.001, T1059.003, T1047, T1053.005, T1129, T1053.005, T1574.001