Skip to content
THE HUNTER’S LEDGER
Threat Actor
UTA-2026-019
Grey-market personal-data harvester running scores of LLM-assisted attack scripts against Chinese consumer platforms
Status
Active
Distinct actor
MODERATE 65%
Named actor
INSUFFICIENT
First observed
21 Jul 2026
Last updated
21 Jul 2026
Operator language
Chinese-language (HIGH for language and targeting)
Motivation
Customer PII harvest for resale; state nexus rejected (HIGH)
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-019 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.

Summary

An exposed staging directory showing how an ordinary operator now runs an intrusion campaign, with probably-generated attack scripts and an off-the-shelf agentic-AI framework wired in as the console. A build-host key comment shared across three key pairs and a reused account-naming series are the tracking anchors.

The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.

Targeting

Regions
China
Sectors
Consumer finance and e-commerce (installment, credit rental, loan referral)

Identity artifacts are deliberately withheld per the report's publish-the-finding-not-the-person boundary; only the reusable account-naming pattern is shown.

Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.

Reports

Actor identifiers

Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.

string redteam operator account-naming series reused across unrelated targets

Infrastructure and tooling

Primary host
192.3.1.116 (the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)
Tooling
Open-source agent frameworkSoftEther VPNcommodity exploitation scripts

MITRE ATT&CK

36 techniques across 11 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.

Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.