China-linked UAT-7290 spies on telco in South Asia and Europe using modular malware
ID: 6c9a0394-a738-5809-96a7-09c94a8ddf81
STIX ID: report--6c9a0394-a738-5809-96a7-09c94a8ddf81
Feed Name: Security Affairs
Threat Score
China-linked UAT-7290 has conducted espionage since at least 2022 against telecom providers in South Asia and Southeastern Europe, deploying modular Linux and Windows malware (RushDrop, DriveSwitch, SilentRaid, Bulbature), exploiting one-day flaws and SSH brute force, and operating ORB infrastructure that is reused by other China-nexus actors; the report includes detailed TTPs and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
