Chinese APT UAT-7810 Expands Malware Arsenal
The investigation into UAT-7810 shows significant evolution in their toolkit, specifically the development of a successor to their previously documented SHORTLEASH backdoor.
Editor
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.
The investigation into UAT-7810 shows significant evolution in their toolkit, specifically the development of a successor to their previously documented SHORTLEASH backdoor.
It’s a pre-July 4th extravaganza! To celebrate, we dive into a little cybersecurity history with a story about the MySpace Samy worm, then we jumpe into the news of the week, including an update on the Fable 5 export control drama, and the emergence of the ARToken operator panel. Links ARTokens story: https://decipher.sc/2026/06/26/new-turla-stockstay-backdoor-emerges/ Scattered Spider […]
This new ARToken operator panel has a clear lineage going back to the EvilTokens framework, which emerged in early 2026.
Hacker and legendary vulnerability disclosure expert Katie Moussouris of Luta Security joins Dennis to talk about the Fable 5 munitions classification controversy, the recent re-emergence of the disclosure debate, how AI-assisted bug hunting is reshaping the defensive landscape, and what the future holds for attackers and defenders.
Known historically for its tight ties to Russia’s FSB and its development of the Snake implant, Turla has leveraged STOCKSTAY to target sensitive government and military organizations.
It’s a non-AI podcast! This week we dig into the new Gaslight macOS implant that tries to trick security researchers with some anti-forensics techniques, then we discuss the Operation Endgame takedown of some malware infrastructure, and finally we discuss a Cisco Catalyst SD-WAN bug that was exploited as a zero day. Links Google analysis of […]