UAT-7290
UAT-7290 is a China-linked threat actor tracked by Cisco Talos, assessed with high confidence to be part of the China-nexus APT ecosystem and active since at least 2022. The group conducts espionage-focused intrusions and initial access operations, primarily targeting telecommunications providers and other critical infrastructure entities in South Asia, with more recent activity extending into Southeastern Europe. Cisco Talos assessed that UAT-7290 may serve a dual role as both an espionage operator and an initial access provider by establishing Operational Relay Box (ORB) infrastructure that can later be reused by other China-nexus actors. The actor prioritizes public-facing edge networking devices for initial access. Reported access methods include extensive pre-intrusion technical reconnaissance, exploitation of one-day vulnerabilities in popular edge networking products, use of publicly available proof-of-concept exploit code, and target-specific SSH brute-force attacks against exposed devices. Talos reported that UAT-7290 burrows deeply into victim enterprise and telecommunications infrastructure during espionage operations. UAT-7290 primarily uses a Linux-focused malware suite including RushDrop, DriveSwitch, SilentRaid, and Bulbature. RushDrop, also referred to as ChronosRAT, functions as a dropper and performs anti-VM checks, creates a hidden .pkgdb directory, and drops components including daytime, chargen, and BusyBox. DriveSwitch is used to execute the main implant. SilentRaid, also known as MystRodX, is the primary persistent implant; it is described as a modular C++ backdoor that communicates with command-and-control infrastructure, including via DNS resolution using 8.8.8.8, and supports remote shell access, command execution, port forwarding, file management, reverse shell capability, and x509 certificate attribute parsing. Bulbature is used to convert compromised devices into ORB nodes; it can listen on configurable ports, store configuration in /tmp with a .cfg extension, and open reverse shells. Talos reported a recurring self-signed certificate associated with Bulbature observed on numerous hosts in China or Hong Kong. The reporting also states that UAT-7290 may use Windows implants including RedLeaves and ShadowPad. Cisco Talos observed overlaps in tooling, infrastructure, victimology, and TTPs with other China-nexus activity, including RedLeaves activity associated with APT10, ShadowPad-associated infrastructure, and the cluster known as Red Foxtrot, which prior reporting linked to PLA Unit 69010. Other reporting cited overlaps with Stone Panda, and Palo Alto Networks Unit 42 tracks related activity as CL-STA-0969. Known aliases and related names directly mentioned in the content include UAT 7290, UAT-7290, ChronosRAT for RushDrop, MystRodX for SilentRaid, and CL-STA-0969 for related tracking by Unit 42.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇨🇦 Canada
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Observables
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A splinter unit associated with APT 41 that reportedly maintained covert access in North American developer environments for over a year while observing and preparing for native-looking follow-on activity.
China-linked activity cluster associated with access acquisition and espionage operations (details not expanded in the provided content).
China-nexus threat actor conducting espionage-focused intrusions against entities in South Asia and Southeastern Europe.
Conducting sustained cyber-espionage operations against telecommunications infrastructure, extracting sensitive network intelligence, and converting compromised telecom systems into covert relay nodes supporting broader state-aligned operations.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.