New China-linked hackers breach telcos using edge device exploits
ID: 7f9c9672-f334-5e68-b718-50c06fbe81f3
STIX ID: report--7f9c9672-f334-5e68-b718-50c06fbe81f3
Feed Name: Bleeping Computer
UAT-7290, a China-linked threat actor active since at least 2022, has been observed targeting telecommunications providers—previously focused on South Asia and now expanding into Southeastern Europe—by exploiting public-facing edge devices (one-day flaws and SSH brute force) to deploy a Linux malware suite (including RushDrop/DriveSwitch/SilentRaid and Bulbature) and establish Operational Relay Boxes that facilitate further intrusions; Cisco Talos provides technical details and IoCs to aid defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
