China-Linked UAT-7290 Targets Telecom Networks in South Asia
ID: d1ef8cf0-0ddb-52a8-b400-591d9315003e
STIX ID: report--d1ef8cf0-0ddb-52a8-b400-591d9315003e
Feed Name: Infosecurity Magazine (News)
Cisco Talos attributes a long-running China-linked espionage campaign (UAT-7290) to operators targeting telecommunications providers in South Asia and, more recently, Southeastern Europe since at least 2022; the group exploits one-day vulnerabilities and SSH brute-force against edge devices, deploys Linux-based implants (RushDrop, DriveSwitch, SilentRaid) and uses Bulbature to convert compromised systems into relay infrastructure (ORB), enabling persistent access and potential facilitation of other China-nexus groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
