UAT-7810
Reports
7
First seen
Jul 7, 2026
Last seen
Aug 7, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
Taiwan ×1
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×7T1090 Proxy ×5T1041 Exfiltration Over C2 Channel ×4T1219 Remote Access Software ×4T1071 Application Layer Protocol ×4T1486 Data Encrypted for Impact ×3T1505 Web Shell ×2T1566 Phishing ×2T1059 Command and Scripting Interpreter ×2T1047 Windows Management Instrumentation ×2T1105 Ingress Tool Transfer ×2T1059.001 PowerShell ×1
Indicators
hash_sha256 ×81cve ×41url ×9ip_v4 ×4hash_md5 ×4filename ×3domain ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-2492 (exploited)CVE-2020-22658 (exploited)CVE-2020-22653 (exploited)CVE-2023-25717 (exploited)CVE-2025-3248 (exploited)CVE-2024-42009 (exploited)CVE-2020-25499 (exploited)CVE-2020-8515 (exploited)CVE-2022-35733 (exploited)CVE-2025-28137 (exploited)CVE-2025-34152 (exploited)CVE-2025-49113 (exploited)CVE-2025-55182 (exploited)CVE-2025-5777 (exploited)CVE-2025-66376 (exploited)CVE-2025-9491 (exploited)CVE-2025-9528 (exploited)CVE-2026-11405CVE-2026-15409 (exploited)CVE-2026-15410 (exploited)
Recent reports
Critical