logo

China-Linked UAT-7290 Targets Telecom Networks in South Asia

ID: d1ef8cf0-0ddb-52a8-b400-591d9315003e

STIX ID: report--d1ef8cf0-0ddb-52a8-b400-591d9315003e

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

...
...

Cisco Talos attributes a long-running China-linked espionage campaign (UAT-7290) to operators targeting telecommunications providers in South Asia and, more recently, Southeastern Europe since at least 2022; the group exploits one-day vulnerabilities and SSH brute-force against edge devices, deploys Linux-based implants (RushDrop, DriveSwitch, SilentRaid) and uses Bulbature to convert compromised systems into relay infrastructure (ORB), enabling persistent access and potential facilitation of other China-nexus groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.