UAT-7290 is a China-nexus, likely state-sponsored cyber-espionage and initial-access actor active since at least 2022. It primarily targets telecommunications providers and other critical-infrastructure entities in South Asia, with more recent activity against organizations in Southeastern Europe. Palo Alto Networks Unit 42 tracks related activity as CL-STA-0969. UAT-7290 has demonstrated overlap in victimology, infrastructure, tooling, and tradecraft with other China-nexus activity, including Red Foxtrot; observed tooling and infrastructure also overlap with activity involving RedLeaves and ShadowPad, but these overlaps do not establish that UAT-7290 is synonymous with those groups. The actor conducts extensive pre-intrusion technical reconnaissance and compromises public-facing edge networking devices through exploitation of publicly disclosed one-day vulnerabilities and targeted SSH brute-force attacks. Its operations principally employ a Linux-focused malware suite for edge devices: RushDrop (also known as ChronosRAT) acts as a staged dropper; DriveSwitch launches the primary implant; and SilentRaid (also known as MystRodX) is a modular C++ backdoor supporting persistent access, remote shell execution, file operations, and port forwarding. RushDrop and SilentRaid use anti-analysis and virtual-machine checks, and RushDrop removes itself following payload deployment to reduce forensic evidence. UAT-7290 has also been associated with Windows implants including RedLeaves and ShadowPad. UAT-7290 deploys Bulbature to convert compromised systems into Operational Relay Boxes, providing anonymized relay infrastructure that has subsequently been reused by other China-nexus actors. This activity indicates a dual operational role: collecting intelligence from victim networks while establishing access and relay infrastructure that can support additional operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A splinter unit associated with APT 41 that reportedly maintained covert access in North American developer environments for over a year while observing and preparing for native-looking follow-on activity.
China-linked activity cluster associated with access acquisition and espionage operations (details not expanded in the provided content).
China-nexus threat actor conducting espionage-focused intrusions against entities in South Asia and Southeastern Europe.
Conducting sustained cyber-espionage operations against telecommunications infrastructure, extracting sensitive network intelligence, and converting compromised telecom systems into covert relay nodes supporting broader state-aligned operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.