ThreatCluster
About Blog Help Contact
Login
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Taiwan Web Servers Breached by UAT-7237 Using Customized Open-Source Hacking Tools

Threat Score:
80
The Hacker News
2 hours ago
Part of cluster #1990

Overview

A Chinese-speaking advanced persistent threat (APT) actor has been observed targeting web infrastructure entities in Taiwan using customized versions of open-sourced tools with an aim to establish long-term access within high-value victim environments. The activity has been attributed by Cisco Talos to an activity cluster it tracks asUAT-7237, which is believed to be active since at least 2022. The hacking group is assessed to be a sub-group ofUAT-5918, which is known to be attacking critical in...

Continue Reading on Original Site

Related Articles

5 articles
1

US and Five Global Partners Release First Unified OT Security Taxonomy

Infosecurity Magazine • 6 hours ago

Germany, the Netherlands and four of the Five Eyes countries a common asset inventory for industrial cybersecurity

Score
85
Read more
2
Stop Reacting; Start Anticipating: The Global State of Threat Intelligence

Stop Reacting; Start Anticipating: The Global State of Threat Intelligence

Brighttalk • 4 hours ago

Presented by Jitin Shabadu, Forrester Analyst | Jayce Nichols, Director, Intelligence Solutions, Google Threat Intelligence Group

Score
83
Read more
3
Colt Telecom attack claimed by WarLock ransomware, data up for sale

Colt Telecom attack claimed by WarLock ransomware, data up for sale

BleepingComputer • 3 hours ago

Colt Telecom attack claimed by WarLock ransomware, data up for sale Bill Toulas August 15, 2025 11:25 AM 0 UK-based telecommunications company Colt Technology Services is dealing with a cyberattack that has caused a multi-day outage of some of the company's operations, including hosting and porting services, Colt Online, and Voice API platforms. The British telecommunications and network services provider disclosed that the attack started on August 12 and the disruption continues as its IT staff

Score
83
Read more
4

Cisco Patches Critical Vulnerability in Firewall Management Platform

SecurityWeek • 11 hours ago

Cisco has released over 20 advisories as part of its August 2025 bundled publication for ASA, FMC and FTD products.

Score
83
Read more
5

Cisco Discloses Critical RCE Flaw in Firewall Management Software

Infosecurity Magazine • 8 hours ago

Cisco has issued a software update to address the vulnerability, which can allow an unauthenticated, remote attacker to inject arbitrary shell commands

Score
82
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

ATTACK TYPES
APT Exploitation
Advanced Persistent Threat
Privilege Escalation
Rootkit
Web Infrastructure Attack
COUNTRIES
China
Taiwan
VULNERABILITIES
Privilege Escalation
COMPANIES
Cisco
Cisco Talos
PLATFORMS
Windows
APT GROUPS
Cobalt
Flax Typhoon
Gelsemium
UAT-5918
UAT-7237
RANSOMWARE
Desktop
core
MITRE ATT&CK
Rootkit
T1046
T1053
T1059.001
T1071.001
MALWARE
Cobalt Strike
JuicyPotato
Leverage
MimiKatz
Pay2Key
INDUSTRIES
Cybersecurity
Web Hosting
ARTICLE INFORMATION
Article #11984
Published 2 hours ago
The Hacker News

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration