logo

UAT-7290 Hackers Attacking Critical Infrastructure Entities in South Asia

ID: 0b1282a5-8c1b-5420-ae1f-be97e3eb81a4

STIX ID: report--0b1282a5-8c1b-5420-ae1f-be97e3eb81a4

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-01-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

UAT-7290, a suspected Chinese government-linked APT active since at least 2022, is conducting targeted operations against telecommunications and critical infrastructure in South Asia and has expanded into Southeastern Europe; Cisco Talos analysts attribute a Linux-centric toolkit—RushDrop (dropper), DriveSwitch (execution helper), and SilentRaid (modular implant)—used to gain initial access, establish persistence, and maintain covert C2 communications (including DNS resolution via 8.8.8.8).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.