DriveSwitch is a Linux loader component used by the China-nexus espionage actor UAT-7290. It is deployed by the RushDrop dropper in a staged infection chain and executes the SilentRaid primary implant on compromised edge-networking systems. UAT-7290 has used this tooling primarily in intrusions against telecommunications providers and other critical-infrastructure organizations in South Asia, with later activity affecting Southeastern Europe. The actor commonly obtains access to exposed edge devices through exploitation of publicly available vulnerabilities and targeted SSH brute-force activity before deploying its Linux malware suite.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DriveSwitch is a peripheral component whose sole function is to execute the SilentRaid implant ("chargen") on the infected system.
DriveSwitch, a peripheral malware that's used to execute SilentRaid on the infected system
20 distinct techniques documented for this family, organized by ATT&CK tactic.
UAT-7290 leverages one-day exploits and target-specific SSH brute force to compromise public-facing edge devices to gain initial access...
...support capabilities such as command execution... Monitor for anomalous DNS behavior... along with unusual BusyBox command usage... | These components use DNS resolution through public resolvers to reach command-and-control and support capabilities such as command execution, file management, and reverse shell establishment... any evidence of spawned reverse shells.
UAT-7290 leverages one-day exploits and target-specific SSH brute force to compromise public-facing edge devices to gain initial access...
UAT-7290 typically leverages public proof-of-concepts (PoCs) for various vulnerabilities and SSH brute force attacks to compromise public-facing devices.
UAT-7290 leverages one-day exploits and target-specific SSH brute force to compromise public-facing edge devices to gain initial access...
T1027: Obfuscated Files or Information – UAT-7290 malware obfuscation
UAT-7290 leverages one-day exploits and target-specific SSH brute force to compromise public-facing edge devices to gain initial access...
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family referenced as being used in espionage-focused intrusions by UAT-7290.
A specialized Linux-based loader used in UAT-7290's telecommunications malware stack to help deploy or support follow-on payloads on compromised edge devices.
An intermediate Linux stage in the infection chain that is deployed after RushDrop and before SilentRaid.
Malware family used in cyber-espionage campaigns targeting telecommunications infrastructure, attributed to the UAT-7290 threat actor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.