ANAVEM
Reference
Languagefr
Telecommunications tower with red warning lights against stormy dark sky

China APT Targets South American Telecom Infrastructure

China-linked UAT-9244 threat group compromises telecommunications networks across South America using three custom implants since 2024.

Emanuel DE ALMEIDAEmanuel DE ALMEIDA
6 Mar 2026, 09:22 2 min read 0

Last updated 16 Mar 2026, 00:31

SEVERITYHigh
EXPLOITActive Exploit
PATCH STATUSUnavailable
VENDORCisco Talos
AFFECTEDWindows systems, Linux systems...
CATEGORYCyber Attacks

Key Takeaways

UAT-9244 APT Campaign Targets Critical Telecom Networks

Cisco Talos researchers discovered a China-linked advanced persistent threat group designated UAT-9244 conducting sustained attacks against telecommunications infrastructure across South America. The campaign began in 2024 and continues to target critical network systems. CISA's vulnerability catalog tracks similar infrastructure-focused threats.

The threat group deploys three distinct malware implants designed to compromise different system types. Researchers identified connections between UAT-9244 and another known cluster called FamousSparrow, suggesting coordinated operations.

South American Telecom Operators Under Attack

The attacks specifically target telecommunications companies operating critical infrastructure in South America. Both Windows and Linux systems face compromise, along with network edge devices that handle routing and switching functions.

The broad targeting approach indicates the attackers seek persistent access to telecommunications networks rather than focusing on specific vendors or technologies.

Three-Pronged Malware Strategy Deployed

UAT-9244 employs three separate implants tailored for different system architectures. The Windows implant targets desktop and server environments, while the Linux variant focuses on network infrastructure systems.

A third implant specifically targets edge devices, allowing attackers to maintain persistence at critical network chokepoints. Organizations should monitor network traffic for unusual patterns and implement security updates across all infrastructure components.

Frequently Asked Questions

What is UAT-9244 and who is behind it?+
UAT-9244 is a China-linked advanced persistent threat group identified by Cisco Talos researchers. The group has connections to another known cluster called FamousSparrow and specifically targets telecommunications infrastructure.
Which systems are targeted by UAT-9244 attacks?+
UAT-9244 targets Windows systems, Linux systems, and telecommunications edge devices across South American networks. The group uses three different implants tailored for each system type.
How long has UAT-9244 been active in South America?+
UAT-9244 has been conducting attacks against South American telecommunications infrastructure since 2024. The campaign represents an ongoing threat to critical network infrastructure in the region.
Emanuel DE ALMEIDA
About the Author

Emanuel DE ALMEIDA

Senior IT Journalist & Cloud Architect

Microsoft MCSA-certified Cloud Architect | Fortinet-focused. I modernize cloud, hybrid & on-prem infrastructure for reliability, security, performance and cost control - sharing field-tested ops & troubleshooting.

Discussion

Share your thoughts and insights

You must be logged in to comment.

Loading comments...