STORM-1849 logo

STORM-1849

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: UAT4356
Ver en IntelTracker → APTTrail →
STORM-1849, also tracked as UAT4356, is a state-sponsored cyber espionage group assessed with high confidence to be China-aligned. The group's capabilities were observed in development as early as July 2023, with initial exploitation activity detected in January 2024, marking its formal emergence. This actor is distinguished by its meticulous focus on compromising perimeter network devices, particularly Cisco Adaptive Security Appliances (ASA) and Firepower Threat Defense (FTD), by exploiting zero-day vulnerabilities to deploy custom implants for long-term intelligence gathering and persistent access. Its operations, notably the "ArcaneDoor" campaign, demonstrate an in-depth understanding of target systems and sophisticated anti-forensic measures, setting it apart from other threat actors.
Tecnicas MITRE
T1059, T1566.002, T1210, T1071.001, T1078.003
CVEs relacionadas
CVE-2025-30333, CVE-2025-20363, CVE-2025-20362, CVE-2025-20352, CVE-2025-20333, CVE-2024-40766

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
40
Actualizado
Sat, 27 Ap

Sectores objetivo (SOCRadar)

Public AdministrationExecutive, Legislative, and Other General Government SupportComputer Systems Design and Related Services