SilentRaid, also known as MystRodX and in some reporting TrustFall, is a C++-based modular backdoor used in China-nexus espionage activity. It has been associated with intrusions attributed to UAT-7290, a threat actor active since at least 2022 that has targeted telecommunications providers and other critical infrastructure, primarily in South Asia with more recent activity in Southeastern Europe. Separate reporting also noted infrastructure overlap between SilentRaid activity and later espionage campaigns against government and public-sector organizations in Central Asia and Syria, although common operator attribution was not confirmed.
SilentRaid functions as the primary persistent implant in a staged Linux infection chain that also includes RushDrop and DriveSwitch. It is designed to establish long-term command-and-control access on compromised endpoints and edge devices, receive attacker tasking, and extend functionality through a plugin-based architecture. Reported capabilities include remote shell access, command execution, file management and manipulation, port forwarding, socket management, reverse shell establishment, and collection of credential-related or system data from telecommunications environments. Some analyses also describe access to local account information and collection of X.509 certificate attributes. The malware incorporates anti-analysis measures and is intended to minimize exposure while maintaining durable access.
MystRodX-focused analysis additionally describes flexible command-and-control options, including TCP or HTTP transport with optional encrypted communications, as well as a stealthy passive activation mode using specially crafted DNS or ICMP traffic rather than a continuously exposed listening service. A dual-process watchdog-style persistence mechanism has also been reported in samples linked to MystRodX, in which launcher and backdoor components restart one another.
SilentRaid primarily targets Linux and Unix-like systems common in telecommunications and edge-networking environments. It has been deployed after initial access obtained through exploitation of public-facing edge-device vulnerabilities and SSH brute-force activity. In observed operations, the malware supported deep post-compromise access and persistence within strategically significant network infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SilentRaid establishes persistent command-and-control access to telecommunications infrastructure, enabling remote shell execution, port forwarding, file manipulation, and credential theft from telecommunications systems.
SilentRaid (aka MystRodX), a C++-based implant that establishes persistent access ... plugin-like approach to communicate with an external server, open a remote shell, set up port forwarding, and perform file operations
34 distinct techniques documented for this family, organized by ATT&CK tactic.
...support capabilities such as command execution, file management, and reverse shell establishment... any evidence of spawned reverse shells. | ...support capabilities such as command execution... Monitor for anomalous DNS behavior... along with unusual BusyBox command usage...
UAT-7290 typically leverages public proof-of-concepts (PoCs) for various vulnerabilities and SSH brute force attacks to compromise public-facing devices.
SilentRaid communicates with its C2 server, usually in the form of a domain and can carry out action as instructed by the C2.
Plugin: my_socks_mgr This plugin handles communication to C2 server. It obtains the C2 IP by resolving a domain using “8[.]8[.]8[.]8” and passes commands received from the C2 to the appropriate plugin.
SilentRaid operates using a modular plugin system that gives attackers multiple capabilities. The malware can open remote shells, forward internet ports, and manage files on infected systems.
These plugins enable remote shells, file access, port forwarding, command execution, and data collection
RushDrop then decodes and drops three binaries to the “.pkgdb” folder: “daytime” ... tracked as DriveSwitch. “chargen” ... tracked as SilentRaid. “busybox” - Busybox is a legitimate Linux utility that can be used to execute arbitrary commands on the system.
SilentRaid is the main implant in the intrusion meant to establish persistent access to compromised endpoints. It communicates with its command-and-control server (C2) and carries out tasks defined in the malware.
When SilentRaid starts, it communicates with its control server using a domain name and Google’s public DNS service (8.8.8.8) to find the server’s address.
T1572: Protocol Tunneling – Traffic tunneling through telecommunications infrastructure
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An implant/backdoor from an earlier campaign whose infrastructure overlaps with the current activity, though attribution overlap remains unconfirmed.
A C++-based implant from prior attacks that shares infrastructure overlaps with the current campaign, suggesting possible linkage across multiple OS-targeting operations.
C++ backdoor supporting file management, port forwarding, reverse shell, and socket management; uses DNS/ICMP triggers for stealthy control (per excerpt).
A malware family referenced as being used in espionage-focused intrusions by UAT-7290.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.