SilentRaid, also known as MystRodX, is a modular C++ Linux backdoor used as the principal persistent implant in UAT-7290 intrusions. It targets compromised edge devices and telecommunications infrastructure, principally in South Asia and more recently Southeastern Europe. UAT-7290 is assessed as a China-nexus espionage actor; reported overlaps with other China-linked activity do not establish that SilentRaid is operated by those other groups.
SilentRaid establishes command-and-control access and exposes a compile-time selectable plugin architecture. Observed capabilities include arbitrary shell command execution, reverse-shell access, file operations, port forwarding, socket management, network monitoring, collection of local account and X.509 certificate information, and credential-related data collection. It performs anti-virtualization and anti-analysis checks and can resolve command-and-control infrastructure through public DNS resolvers. MystRodX variants also support TCP or HTTP command-and-control, optional encrypted traffic, and a passive activation mode triggered by crafted DNS or ICMP traffic, enabling operation without a conventional listening port. Persistence can be maintained through a paired-process watchdog arrangement in which launcher and backdoor components restart one another.
In UAT-7290 operations, SilentRaid is deployed after the RushDrop dropper and DriveSwitch execution component following compromise of exposed edge devices. Reported actor access methods include exploitation of publicly disclosed vulnerabilities and targeted SSH brute-force activity; these are intrusion vectors for the associated actor rather than confirmed standalone distribution methods for SilentRaid.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SilentRaid (also known as MystRodX) ... is built around a modular plugin architecture that enables the threat actor to compose a tailored capability set at compile time.
SilentRaid (aka MystRodX), a C++-based implant that establishes persistent access ... plugin-like approach to communicate with an external server, open a remote shell, set up port forwarding, and perform file operations
32 distinct techniques documented for this family, organized by ATT&CK tactic.
...support capabilities such as command execution, file management, and reverse shell establishment... any evidence of spawned reverse shells. | ...support capabilities such as command execution... Monitor for anomalous DNS behavior... along with unusual BusyBox command usage...
C2 address is stored in an encoded configuration file in the /tmp directory, with the same filename as the malware binary and a '.cfg' extension appended.
Creates a hidden directory named '.pkgdb' in the working directory and decodes three embedded binaries into it.
T1016: System Network Configuration Discovery – Telecommunications network mapping
T1082: System Information Discovery – Telecommunications system enumeration
SilentRaid communicates with its C2 server, usually in the form of a domain and can carry out action as instructed by the C2.
Annex B - MITRE ATT&CK Tactics and Techniques ... Command and Control | T1071.001 | Application Layer Protocol: Web Protocols.
Plugin: my_socks_mgr This plugin handles communication to C2 server. It obtains the C2 IP by resolving a domain using “8[.]8[.]8[.]8” and passes commands received from the C2 to the appropriate plugin.
SilentRaid operates using a modular plugin system that gives attackers multiple capabilities. The malware can open remote shells, forward internet ports, and manage files on infected systems.
RushDrop then decodes and drops three binaries to the “.pkgdb” folder: “daytime” ... tracked as DriveSwitch. “chargen” ... tracked as SilentRaid. “busybox” - Busybox is a legitimate Linux utility that can be used to execute arbitrary commands on the system.
SilentRaid is the main implant in the intrusion meant to establish persistent access to compromised endpoints. It communicates with its command-and-control server (C2) and carries out tasks defined in the malware.
When SilentRaid starts, it communicates with its control server using a domain name and Google’s public DNS service (8.8.8.8) to find the server’s address.
T1572: Protocol Tunneling – Traffic tunneling through telecommunications infrastructure
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An implant/backdoor from an earlier campaign whose infrastructure overlaps with the current activity, though attribution overlap remains unconfirmed.
A C++-based implant from prior attacks that shares infrastructure overlaps with the current campaign, suggesting possible linkage across multiple OS-targeting operations.
C++ backdoor supporting file management, port forwarding, reverse shell, and socket management; uses DNS/ICMP triggers for stealthy control (per excerpt).
A malware family referenced as being used in espionage-focused intrusions by UAT-7290.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.