static-urls · Crawled Jul 31, 2026

UAT-7290 targets high value telecommunications infrastructure in South Asia

12 IoCs 2 Actors 5 Malware
Read original article ↗

AI Summary

Cisco Talos has identified a sophisticated China-nexus APT group tracked as UAT-7290, active since at least 2022, targeting high-value telecommunications infrastructure in South Asia and recently expanding into Southeastern Europe. The group conducts espionage and establishes Operational Relay Box (ORB) nodes using a suite of custom and open-source malware, including RushDrop, DriveSwitch, SilentRaid, and Bulbature. UAT-7290 leverages one-day exploits, SSH brute-forcing, and publicly available proof-of-concept code to compromise edge devices and gain initial access. Technical overlaps with APT10 and Red Foxtrot, as well as shared infrastructure and malware traits, suggest ties to Chinese state-sponsored actors.

AI-extracted · verify before operational use

Extracted Entities 7 found

Indicators of Compromise 12 extracted

Type Value Detail
SHA-256 723c1e59accbb781856a8407f1e64f36038e324d3f0bdb606d35c359ade08200 Details →
SHA-256 59568d0e2da98bad46f0e3165bcf8adadbf724d617ccebcfdaeafbb097b81596 Details →
SHA-256 961ac6942c41c959be471bd7eea6e708f3222a8a607b51d59063d5c58c54a38d Details →
Domain 8[.]8[.]8[.]8 Details →
Filename .pkgdb Details →
Filename daytime Details →
Filename chargen Details →
Filename busybox Details →
Filename RushDrop Details →
Filename DriveSwitch Details →
Filename SilentRaid Details →
Filename Bulbature Details →

MITRE ATT&CK TTPs 51 techniques

T1027 Obfuscated Files or Information · Defense Evasion T1057 Process Discovery · Discovery T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1124 System Time Discovery · Discovery T1133 External Remote Services · Persistence T1566 Phishing · Initial Access T1001 Data Obfuscation · Command And Control T1001.002 Steganography · Command And Control T1001.003 Protocol or Service Impersonation · Command And Control T1003 OS Credential Dumping · Credential Access T1012 Query Registry · Discovery T1018 Remote System Discovery · Discovery T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1027.002 Software Packing · Defense Evasion T1041 Exfiltration Over C2 Channel · Exfiltration T1048 Exfiltration Over Alternative Protocol · Exfiltration T1055 Process Injection · Defense Evasion T1055.001 Dynamic-link Library Injection · Defense Evasion T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1059.003 Windows Command Shell · Execution T1070.001 Clear Windows Event Logs · Defense Evasion T1070.002 Clear Linux or Mac System Logs · Defense Evasion T1070.003 Clear Command History · Defense Evasion T1070.004 File Deletion · Defense Evasion T1070.005 Network Share Connection Removal · Defense Evasion T1070.006 Timestomp · Defense Evasion T1071 Application Layer Protocol · Command And Control T1075 T1075 T1081 T1081 T1090.001 Internal Proxy · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1210 Exploitation of Remote Services · Lateral Movement T1555 Credentials from Password Stores · Credential Access T1566.001 Spearphishing Attachment · Initial Access T1003.001 LSASS Memory · Credential Access T1078 Valid Accounts · Defense Evasion T1087.002 Domain Account · Discovery T1558 Steal or Forge Kerberos Tickets · Credential Access T1036 Masquerading · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1204.002 Malicious File · Execution