Bulbature is a Linux-based, UPX-packed backdoor implant used to convert compromised edge devices into Operational Relay Boxes (ORBs). It listens on configurable ports, supports command-and-control rotation, and provides a reverse shell for arbitrary command execution. Recent variants use self-signed TLS certificates for encrypted command-and-control communications. Bulbature employs obfuscation and anti-analysis measures, including encrypted strings and control-flow flattening. It has been associated with China-linked activity, including UAT-7290 operations targeting telecommunications providers in South Asia and Southeastern Europe. It has also been deployed against Linux routers and NAS devices, including multi-architecture builds for x86-64, ARM, and MIPS systems, to provide anonymized relay and proxy infrastructure for subsequent operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bulbature is an additional implant deployed on compromised devices for the specific purpose of converting them into Operational Relay Boxes (ORBs).
Bulbature, an implant that was not yet documented in open source, seems to be only used to transform the compromised edge device into an ORB to relay attacks against final victims networks.
Bulbature, an implant that was not yet documented in open source, seems to be only used to transform the compromised edge device into an ORB to relay attacks against final victims networks.
Also deployed by UAT-7290 is a backdoor called Bulbature that's engineered to transform a compromised edge device into an ORBs. It was first documented ... by Sekoia in October 2024.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
their tactics, techniques and procedures (TTPs) and tooling suggest that this actor also establishes Operational Relay Box (ORBs) nodes... The ORB infrastructure may then be used by other China-nexus actors in their malicious operations
Bulbature obtains the local network interface’s name by executing the command: cat /proc/net/route | awk '{print $1,$2}' | awk '/00000000/ {print $1}'
It also obtains basic system information and the current user using the command: echo $(whoami) $(uname -nrm)
Bulbature functions as an ORB node, listening on configurable ports...
Another tool, Bulbature, provides additional backdoor capabilities, gathers system info, manages multiple C2 addresses, and opens reverse shells.
SilentRaid communicates with its C2 server, usually in the form of a domain and can carry out action as instructed by the C2.
Annex B - MITRE ATT&CK Tactics and Techniques ... Command and Control | T1071.001 | Application Layer Protocol: Web Protocols.
UAT-7290 establishes ORB infrastructure on compromised devices. The ORB infrastructure serves as anonymised relay nodes for command-and-control (C2) communications.
Des contrats de marchés publics de l’APL confirment que Guangdong Chanming fournit un « Anonymous Network System » (identifié comme RedRelay) à une unité militaire du district de Haidian à Pékin... T1090.003 — Proxy: Multi-hop Proxy (Command and Control)
SilentRaid – The main implant in the intrusion meant to establish persistent access to compromised endpoints.
Usually UPX compressed, Bulbature can bind to and listen to either a random port of its choosing or one specified via command line via the “-d <port_number>” switch.
T1572: Protocol Tunneling – Traffic tunneling through telecommunications infrastructure
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An implant used to convert compromised telecommunications systems into Operational Relay Boxes that anonymize and route traffic for subsequent cyber operations.
A Linux tool that functions as an Operational Relay Box node, listening on configurable ports and relaying traffic as part of ORB infrastructure.
Backdoor used to convert compromised devices into Operational Relay Boxes (ORBs) for reuse as relay infrastructure by other espionage groups.
Implant used to convert infected systems into operational relay boxes (ORBs).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.