UAT-10147
Reports
3
First seen
Aug 20, 2026
Last seen
Aug 20, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Top ATT&CK techniques
T1562.001 Impair Defenses: Disable or Modify Tools ×3T1027 Obfuscated Files or Information ×2T1190 Exploit Public-Facing Application ×2T1505.003 Web Shell ×2T1068 Exploitation for Privilege Escalation ×2T1218 System Binary Proxy Execution ×2T1547 Boot or Logon Autostart Execution ×2T1083 File and Directory Discovery ×1T1070 Indicator Removal ×1T1059 Command and Scripting Interpreter ×1T1543 Create or Modify System Process ×1T1059.001 PowerShell ×1
Indicators
filename ×18cve ×13domain ×7hash_sha256 ×5hash_md5 ×5registry_key ×4url ×2ip_v4 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2010-3904 (exploited)CVE-2015-3246 (exploited)CVE-2015-5287 (exploited)CVE-2019-16098 (exploited)CVE-2019-18935 (exploited)CVE-2021-21551 (exploited)CVE-2021-23758 (exploited)CVE-2021-29441 (exploited)CVE-2021-29442 (exploited)CVE-2021-3156 (exploited)CVE-2022-0847 (exploited)CVE-2022-0995 (exploited)CVE-2022-27925 (exploited)
Recent reports
High