UAT-7290 Hackers Attacking Critical Infrastructure Entities in South Asia
ID: 0b1282a5-8c1b-5420-ae1f-be97e3eb81a4
STIX ID: report--0b1282a5-8c1b-5420-ae1f-be97e3eb81a4
Feed Name: cybersecurityNews.com
UAT-7290, a suspected Chinese government-linked APT active since at least 2022, is conducting targeted operations against telecommunications and critical infrastructure in South Asia and has expanded into Southeastern Europe; Cisco Talos analysts attribute a Linux-centric toolkit—RushDrop (dropper), DriveSwitch (execution helper), and SilentRaid (modular implant)—used to gain initial access, establish persistence, and maintain covert C2 communications (including DNS resolution via 8.8.8.8).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
