logo

China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware

ID: 6c9a0394-a738-5809-96a7-09c94a8ddf81

STIX ID: report--6c9a0394-a738-5809-96a7-09c94a8ddf81

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

China-linked UAT-7290 has conducted espionage since at least 2022 against telecom providers in South Asia and Southeastern Europe, deploying modular Linux and Windows malware (RushDrop, DriveSwitch, SilentRaid, Bulbature), exploiting one-day flaws and SSH brute force, and operating ORB infrastructure that is reused by other China-nexus actors; the report includes detailed TTPs and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.