Historical intelligence backfill. This assessment covers reporting originally published on 2026-01-15 and was added to the RWP archive on 2026-09-07.
UAT-8837 is an access team on North American critical infrastructure — Sitecore 0-day, then SharpHound
Talos 15 January 2026 — medium-confidence China-nexus. Initial access for high-value orgs, CI sectors in North America since at least 2025. CVE-2025-53690 Sitecore ViewState deserialization. Earthworm, SharpHound, DWAgent, Certipy. Not confirmed Stage 2 ICS.
Bottom line up front
CONFIRMED as Talos 15 January 2026: UAT-8837, medium confidence China-nexus (TTP overlap, not a named MSS). Medium confidence the job is initial access into high-value orgs, not the encryptor. Targeting since at least 2025: North American critical infrastructure sectors. Doors: n-days, creds, and CVE-2025-53690 — pre-auth ViewState deserialization RCE on internet Sitecore (DXP/CMS). Post-compromise LOTL: Earthworm, SharpHound, DWAgent, Certipy — credentials, security config, AD, extra access channels. Same TTPs/infra seen on that Sitecore 0-day, so Talos infers 0-day access.
ASSESSED “Critical infrastructure” here is the sector of the IT estate (CMS on the WAN). Talos did not show ladder logic. Do not upgrade this to FrostyGoop.
What happened
Sitecore on the internet is a beachhead. BloodHound-class mapping is the rest of week one.
Why it matters
Utilities and manufacturers run Sitecore for the public site. That is an IT-to-reputation problem and, if the same AD is used for engineering, an IT-to-OT exposure — ASSESSED, not confirmed process impact.
What is confirmed vs not
CONFIRMED Talos cluster, Sitecore CVE, tool list, CI-sector focus.
UNKNOWN named CI victims or OT effect.
What defenders should do
- Patch/isolate Sitecore per SC2025-005; no CMS on the WAN without WAF+auth.
- Hunt SharpHound/Certipy/DWAgent as CI-IR, not “IT noise.”
- Keep Purdue language honest.
RWP assessment
Confidence: High on Talos TTPs. Medium on China. Low on confirmed ICS compromise.
Historical intelligence backfill. This assessment covers reporting originally published on 2026-01-15 and was added to the RWP archive on 2026-09-07.
Sources
- Cisco Talos — UAT-8837 critical infrastructure
- FortiGuard — UAT-8837 threat signal CVE-2025-53690
- Industrial Cyber — Sitecore exploitation summary