China-linked UAT-8302 expands espionage against governments

Cisco Talos has described UAT-8302, a sophisticated China-linked threat actor running long-term espionage campaigns against government organisations in South America and southeastern Europe. The group uses a broad arsenal of custom malware, including variants tied to previously known Chinese-speaking APT clusters. Talos has observed multiple backdoors, credential theft utilities and stealthy mechanisms for maintaining access over time.

What this means for your organisation

This kind of actor is not after a quick win. The goal is durable access, which makes defence less about stopping the first intrusion than about detecting someone already inside and behaving well. Norwegian organisations in public administration, defence, energy and research sit in the same target group. The overlap between clusters that Talos points to also makes attribution less useful as management information than detection capability.

Berigo recommends

  • Ensure log retention reaches far enough back to uncover access that has lasted for months.
  • Prioritise detection of misused credentials and abnormal internal traffic, not only malware signatures.
  • Run a threat hunt in your own networks based on the indicators Talos has published.
  • Decide in advance who contacts the national security authority if you find signs of a state actor.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch