Skip to content
THE HUNTER’S LEDGER
Threat Actor
UTA-2026-023
Telecom-focused operator reaching a carrier's credential plane through a customer's managed router
Status
Active
Distinct actor
MODERATE 72%
Named actor
INSUFFICIENT
First observed
18 Aug 2026
Last updated
2 Sep 2026
Operator language
Spanish-speaking (MODERATE)
Motivation
Espionage-flavoured collection leans over access brokering; held as a lean
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-023 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.

Summary

An operator who made a carrier-managed customer-premises router upload its own firmware, crash dumps and configuration, manufacturing the crash dumps it then harvested for credentials. Hand-built exploitation tooling and a single-box fingerprint with no siblings anywhere anchor the designation; a China-nexus candidate was tested and rejected.

The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.

Targeting

Regions
Ecuador
Sectors
Telecommunications

Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.

Reports

Actor identifiers

Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.

domain radius-sync.com operator domain impersonating telecom AAA infrastructure
string hello_from_ldap operator callback-validation probe string
path %2577eb%2575i_%2577sma_Http operator-constructed double-encoded exploitation path
string netcraker carrier back-office name seeded into the operator wordlist

Infrastructure and tooling

Primary host
13.140.145.210 (the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)
Tooling
Custom WebLogic T3 suitehand-rolled LDAP exploitation serverchisel

MITRE ATT&CK

58 techniques across 13 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.

Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.