Article Details

Scrape Timestamp (UTC): 2026-01-16 07:24:05.229

Source: https://thehackernews.com/2026/01/china-linked-apt-exploits-sitecore-zero.html

Original Article Text

Click to Toggle View

China-Linked APT Exploits Sitecore Zero-Day in Attacks on American Critical Infrastructure. A threat actor likely aligned with China has been observed targeting critical infrastructure sectors in North America since at least last year. Cisco Talos, which is tracking the activity under the name UAT-8837, assessed it to be a China-nexus advanced persistent threat (APT) actor with medium confidence based on tactical overlaps with other campaigns mounted by threat actors from the region. The cybersecurity company noted that the threat actor is "primarily tasked with obtaining initial access to high-value organizations," based on the tactics, techniques, and procedures (TTPs) and post-compromise activity observed. "After obtaining initial access — either by successful exploitation of vulnerable servers or by using compromised credentials — UAT-8837 predominantly deploys open-source tools to harvest sensitive information such as credentials, security configurations, and domain and Active Directory (AD) information to create multiple channels of access to their victims," it added. UAT-8837 is said to have most recently exploited a critical zero-day vulnerability in Sitecore (CVE-2025-53690, CVSS score: 9.0) to obtain initial access, with the intrusion sharing TTP, tooling, and infrastructure similarities with a campaign detailed by Google-owned Mandiant in September 2025. While it's not clear if these two clusters are the work of the same actor, it suggests that UAT-8837 may have access to zero-day exploits to conduct cyber attacks. Once the adversary obtains a foothold in target networks, it conducts preliminary reconnaissance, followed by disabling RestrictedAdmin for Remote Desktop Protocol (RDP), a security feature that ensures credentials and other user resources aren't exposed to compromised remote hosts. UAT-8837 is also said to open "cmd.exe" to conduct hands-on keyboard activity on the infected host and download several artifacts to enable post-exploitation. Some of the notable artifacts include - "UAT-8837 may run a series of commands during the intrusion to obtain sensitive information, such as credentials from victim organizations," researchers Asheer Malhotra, Vitor Ventura, and Brandon White said. "In one victim organization, UAT-8837 exfiltrated DLL-based shared libraries related to the victim's products, raising the possibility that these libraries may be trojanized in the future. This creates opportunities for supply chain compromises and reverse engineering to find vulnerabilities in those products." The disclosure comes a week after Talos attributed another China-nexus threat actor known as UAT-7290 to espionage-focused intrusions against entities in South Asia and Southeastern Europe using malware families such as RushDrop, DriveSwitch, and SilentRaid. In recent years, concerns about Chinese threat actors targeting critical infrastructure have prompted Western governments to issue several alerts. Earlier this week, cybersecurity and intelligence agencies from Australia, Germany, the Netherlands, New Zealand, the U.K., and the U.S. warned about the growing threats to operational technology (OT) environments. The guidance offers a framework to design, secure, and manage connectivity in OT systems, urging organizations to limit exposure, centralize and standardize network connections, use secure protocols, harden OT boundary, ensure all connectivity is monitored and logged, and avoid using obsolete assets that could heighten the risk of security incidents. "Exposed and insecure OT connectivity is known to be targeted by both opportunistic and highly capable actors," the agencies said. "This activity includes state-sponsored actors actively targeting critical national infrastructure (CNI) networks. The threat is not just limited to state-sponsored actors with recent incidents showing how exposed OT infrastructure is opportunistically targeted by hacktivists."

Daily Brief Summary

NATION STATE ACTIVITY // China-Linked APT Exploits Sitecore Zero-Day Targeting U.S. Infrastructure

Cisco Talos has identified a China-nexus APT, UAT-8837, targeting critical infrastructure in North America, leveraging a Sitecore zero-day vulnerability (CVE-2025-53690) with a CVSS score of 9.0.

The threat actor focuses on initial access to high-value organizations, using open-source tools to gather sensitive information, including credentials and Active Directory data.

UAT-8837's tactics involve disabling security features like RestrictedAdmin for RDP and using cmd.exe for direct interaction on compromised systems.

The group exfiltrated DLL-based shared libraries from victims, potentially setting the stage for future supply chain attacks and reverse engineering efforts.

This activity aligns with broader concerns about Chinese cyber threats to critical infrastructure, prompting alerts from Western cybersecurity agencies.

Recent guidance from global cybersecurity agencies emphasizes securing operational technology environments, highlighting the risks posed by exposed and insecure OT connectivity.

The ongoing threat landscape reflects both state-sponsored and opportunistic attacks on critical national infrastructure, underscoring the need for robust security measures.