logo

New China-linked hackers breach telcos using edge device exploits

ID: 7f9c9672-f334-5e68-b718-50c06fbe81f3

STIX ID: report--7f9c9672-f334-5e68-b718-50c06fbe81f3

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-01-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

UAT-7290, a China-linked threat actor active since at least 2022, has been observed targeting telecommunications providers—previously focused on South Asia and now expanding into Southeastern Europe—by exploiting public-facing edge devices (one-day flaws and SSH brute force) to deploy a Linux malware suite (including RushDrop/DriveSwitch/SilentRaid and Bulbature) and establish Operational Relay Boxes that facilitate further intrusions; Cisco Talos provides technical details and IoCs to aid defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.