logo

China-Nexus Actor UAT-7290 Caught Targeting Telecoms in South Asia and Europe

ID: 99b294fc-ec8c-5145-aaec-fb97eade65d0

STIX ID: report--99b294fc-ec8c-5145-aaec-fb97eade65d0

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco Talos identifies UAT-7290 as a China-nexus advanced persistent threat actor active since at least 2022 that targets telecommunications and critical infrastructure in South Asia and has recently expanded into Southeastern Europe; the group conducts deep reconnaissance, deploys custom implants (RushDrop, DriveSwitch, SilentRaid) and a resilient backdoor (Bulbature), and builds Operational Relay Box (ORB) infrastructure that can be reused by other threat actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.