UAT-8302 Targets Government Entities Across Regions | MSSP Advisory

Critical
DateMay 5, 2026
📋Executive Summary
China-linked APT group UAT-8302 actively targets government entities across South America and southeastern Europe using custom malware families for post-exploitation activities. Cisco Talos tracks this threat as ongoing since late 2024, with the group deploying sophisticated toolsets after initial compromise. The attacks focus on government infrastructure with regional targeting patterns suggesting coordinated intelligence collection operations.
⚠️Why It Matters for MSSPs
Government clients represent high-value targets for nation-state actors, and any compromise creates immediate compliance and contract liability for MSSPs managing these environments. Your own infrastructure becomes a secondary target once threat actors identify you as the service provider for compromised government accounts. Client retention depends on demonstrating proactive threat awareness before incidents occur.
Recommended Action
Contact all government clients within 24 hours to brief them on UAT-8302 targeting patterns and validate their endpoint detection coverage against custom malware deployment techniques.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Nation-State

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.