S A.I CyberSecurity Scoring
S
Company Information
Website:http://www.selec.org
Employees number:7
Number of followers:1,673
NAICS:92212
Industry Type:Law Enforcement
Homepage:selec.org
S Risk Score (AI oriented)
Between 700 and 749
SLaw Enforcement
Updated:
07/05/2026
07/05/2026
738/1000
Moderate
Ba
S Global Score (TPRM)
xxxx
SLaw Enforcement
Score locked

SModerate
Current Score
738Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
739
JUNE 2026
739
MAY 2026
738
APRIL 2026
738
MARCH 2026
737
FEBRUARY 2026
737
JANUARY 2026
737
DECEMBER 2025
736
NOVEMBER 2025
736
OCTOBER 2025
735
SEPTEMBER 2025
735
AUGUST 2025
734
JANUARY 2025
757
Cyber Attack
01 Jan 2025 • S
Government Agencies in Southeastern Europe and Government Agencies in South America: UAT-8302 Uses Custom Malware and Open-Source Tools to Steal Data From Government Agencies
China-Linked UAT-8302 Hackers Target Government Agencies in South America and Southeastern Europe
730
CRITICAL-27
SOUSOU1778164084
China-Linked UAT-8302 Hackers Target Government Agencies in South America and Southeastern Europe
A sophisticated China-linked advanced persistent threat (APT) group, tracked as UAT-8302, has been conducting covert cyberespionage campaigns against government agencies in South America and southeastern Europe since at least late 2024, with operations intensifying through 2025. The group’s primary objective is long-term access and data exfiltration, employing a blend of custom malware and open-source tools to evade detection.
### Tactics and Techniques
UAT-8302 distinguishes itself through stealth and patience, leveraging legitimate cloud services (e.g., Microsoft Graph API, OneDrive, GitHub) and open-source reconnaissance tools (gogo, naabu, httpx, PortQry) to blend malicious activity with normal network traffic. Their approach includes:
- Deep reconnaissance of compromised endpoints before lateral movement.
- Credential harvesting via tools like adconnectdump.py and SharpGetUserLoginRDP.
- DLL side-loading to deploy malware while avoiding detection.
- Proxy tunneling (e.g., Stowaway, SoftEther VPN) to maintain persistent access.
### Malware Arsenal
The group deploys a diverse toolkit, including:
- NetDraft: A .NET-based backdoor using OneDrive for command-and-control (C2) communication, tracked by Cisco Talos as FringePorch.
- CloudSorcerer v3: A shape-shifting backdoor that alters behavior based on the host process (e.g., dnapimg.exe for system profiling, spoolsv.exe for GitHub-based C2).
- VSHELL, SNAPPYBEE, ZingDoor: Additional implants observed in intrusions, with overlaps in tooling linked to other China-nexus clusters like LongNosedGoblin.
- SNOWRUST: A Rust-based stager variant of SNOWLIGHT, previously attributed to Chinese APTs.
### Attribution and Operational Links
Cisco Talos researchers assessed high confidence that UAT-8302 is a China-nexus group, citing shared infrastructure and tooling with other known clusters. The group’s methodical, state-sponsored-style operations align with objectives targeting high-value government infrastructure for intelligence gathering.
### Indicators of Compromise (IoCs)
Key artifacts include:
- Domains: drivelivelime[.]com, msiidentity[.]com, trafficmanagerupdate[.]com
- IPs: 85.209.156[.]3, 185.238.189[.]41, 45.140.168[.]62
- Malware hashes: NetDraft (SHA256: 1139b39d3cc151ddd3d574617cf113608127850197e9695fef0b6d78df82d6ca), VSHELL (SHA256: 35b2a5260b21ddb145486771ec2b1e4dc1f5b7f2275309e139e4abc1da0c614b)
The campaign underscores the evolving sophistication of state-backed cyberespionage, combining custom malware with legitimate services to bypass traditional defenses.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for S ??
What was S's A.I Rankiteo Cyber Score in June 2026 ??
What was S's A.I Rankiteo Cyber Score in May 2026 ??
What was S's A.I Rankiteo Cyber Score in April 2026 ??
What was S's A.I Rankiteo Cyber Score in March 2026 ??
What was S's A.I Rankiteo Cyber Score in February 2026 ??
What was S's A.I Rankiteo Cyber Score in January 2026 ??
What was S's A.I Rankiteo Cyber Score in December 2025 ??
What was S's A.I Rankiteo Cyber Score in November 2025 ??
What was S's A.I Rankiteo Cyber Score in October 2025 ??
What was S's A.I Rankiteo Cyber Score in September 2025 ??
What was S's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on S's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with S ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view S's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?