Quick Summary
The Securityish Brief
The threat actor UAT-7290, associated with China, has been active since at least 2022, primarily targeting telecommunications providers in South Asia and more recently in Southeastern Europe. Their operations involve extensive technical reconnaissance of organizations before launching attacks, which often lead to the deployment of various malware families including RushDrop, DriveSwitch, and SilentRaid.
UAT-7290 employs a combination of open-source malware, custom tools, and exploits for one-day vulnerabilities in popular edge networking products. Notably, the group uses Linux-based malware such as RushDrop, which acts as a dropper to initiate infections, and SilentRaid, a C++ implant that maintains persistent access and executes various commands.
Additionally, the group has been known to establish Operational Relay Box (ORB) nodes, which can be utilized by other China-linked actors for malicious operations. This dual role as both an espionage actor and an initial access group increases the complexity of the threat landscape.
Among the malware utilized by UAT-7290 are RedLeaves and ShadowPad, both linked to Chinese hacking groups. The threat actor’s tradecraft is diverse, relying on publicly available proof-of-concept exploit code rather than developing their own, which may make their methods more accessible to other malicious actors.
Key Malware Used by UAT-7290
- RushDrop: A dropper that initiates the infection chain.
- DriveSwitch: A peripheral malware that executes SilentRaid on infected systems.
- SilentRaid: A C++ implant that establishes persistent access to compromised endpoints.
- Bulbature: A backdoor that transforms compromised devices into ORBs.
The implications of UAT-7290’s activities are significant for organizations in the telecommunications sector, as they must remain vigilant against sophisticated cyber threats that exploit vulnerabilities in their infrastructure.
Key Takeaways
- Regularly update and patch all network devices to mitigate vulnerabilities that could be exploited by threat actors.
- Implement robust monitoring systems to detect unusual network activity indicative of malware infections.
- Conduct regular security audits to identify and address potential weaknesses in your organization’s cybersecurity posture.
- Educate employees about phishing and other social engineering tactics that may precede a cyber attack.
- Consider employing advanced threat detection solutions that can identify and respond to sophisticated malware like those used by UAT-7290.
Key Terms & Concepts
- Operational Relay Box (ORB): In this article, ORB refers to a node established by threat actors to facilitate malicious operations.
- RushDrop: RushDrop is a dropper malware that initiates the infection chain on compromised systems.
- SilentRaid: SilentRaid is a C++ implant used by UAT-7290 to maintain persistent access to infected endpoints.
- DriveSwitch: DriveSwitch is a peripheral malware that executes SilentRaid on infected systems.
- Bulbature: Bulbature is a backdoor designed to convert compromised edge devices into ORBs.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.