UAT-7290 targets high value telecommunications infrastructure in South Asia
ID: 564f610b-dbab-5c58-8c82-4782b06e4f51
STIX ID: report--564f610b-dbab-5c58-8c82-4782b06e4f51
Feed Name: Cisco Talos
Cisco Talos discloses a sophisticated China-nexus APT tracked as UAT-7290 that has targeted telecommunications and critical infrastructure in South Asia (with recent activity in Southeastern Europe) since at least 2022; the actor uses one-day exploits and SSH brute force to compromise edge devices and deploys a Linux-focused malware suite (RushDrop, DriveSwitch, SilentRaid, Bulbature) to establish persistence, convert hosts into Operational Relay Boxes (ORBs), and enable espionage and follow-on operations. The report details modular malware plugins, certificate and infrastructure overlaps with other China-linked malware families, IOCs (hashes and network indicators), and detection signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
