China-Nexus Actor UAT-7290 Caught Targeting Telecoms in South Asia and Europe
ID: 99b294fc-ec8c-5145-aaec-fb97eade65d0
STIX ID: report--99b294fc-ec8c-5145-aaec-fb97eade65d0
Feed Name: securityonline.info
Threat Score
Cisco Talos identifies UAT-7290 as a China-nexus advanced persistent threat actor active since at least 2022 that targets telecommunications and critical infrastructure in South Asia and has recently expanded into Southeastern Europe; the group conducts deep reconnaissance, deploys custom implants (RushDrop, DriveSwitch, SilentRaid) and a resilient backdoor (Bulbature), and builds Operational Relay Box (ORB) infrastructure that can be reused by other threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
