SYMBOLCOMMON_NAMEaka. SYNONYMS

UAT-8616  (Back to overview)


UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.


Associated Families

There are currently no families associated with this actor.


References
2026-02-25Cisco TalosCisco Talos
Active exploitation of Cisco Catalyst SD-WAN by UAT-8616
UAT-8616

Credits: MISP Project