UAT-7290 targets high value telecommunications infrastructure in South Asia
AI Summary
Cisco Talos has identified a sophisticated China-nexus APT group tracked as UAT-7290, active since at least 2022, targeting high-value telecommunications infrastructure in South Asia and recently expanding into Southeastern Europe. The group conducts espionage and establishes Operational Relay Box (ORB) nodes using a suite of custom and open-source malware, including RushDrop, DriveSwitch, SilentRaid, and Bulbature. UAT-7290 leverages one-day exploits, SSH brute-forcing, and publicly available proof-of-concept code to compromise edge devices and gain initial access. Technical overlaps with APT10 and Red Foxtrot, as well as shared infrastructure and malware traits, suggest ties to Chinese state-sponsored actors.
AI-extracted · verify before operational use
Extracted Entities 7 found
Indicators of Compromise 12 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 723c1e59accbb781856a8407f1e64f36038e324d3f0bdb606d35c359ade08200 | Details → |
| SHA-256 | 59568d0e2da98bad46f0e3165bcf8adadbf724d617ccebcfdaeafbb097b81596 | Details → |
| SHA-256 | 961ac6942c41c959be471bd7eea6e708f3222a8a607b51d59063d5c58c54a38d | Details → |
| Domain | 8[.]8[.]8[.]8 | Details → |
| Filename | .pkgdb | Details → |
| Filename | daytime | Details → |
| Filename | chargen | Details → |
| Filename | busybox | Details → |
| Filename | RushDrop | Details → |
| Filename | DriveSwitch | Details → |
| Filename | SilentRaid | Details → |
| Filename | Bulbature | Details → |