Chinese APT Espionage Turns Telecom Systems Into Covert Relay Nodes

Amber | Attack Report
Download PDF

Summary

UAT-7290, a China-linked advanced persistent threat actor, has conducted sustained cyber-espionage operations targeting telecommunications infrastructure since at least 2022. This Chinese APT campaign combines sophisticated telecommunications espionage with strategic infrastructure abuse, extracting sensitive network intelligence while simultaneously converting compromised telecommunications systems into covert relay nodes supporting broader state-aligned cyber operations. UAT-7290 deploys specialized malware including RushDrop, DriveSwitch, SilentRaid, and Bulbature to establish persistent access and transform telecommunications assets into Operational Relay Boxes. The telecommunications attack campaign targets critical infrastructure across South Asia and Southeastern Europe, with recent geographic expansion into Southeastern Europe marking increased strategic reach and operational intent. UAT-7290 demonstrates high operational discipline through extensive pre-intrusion reconnaissance, exploitation of publicly disclosed vulnerabilities in edge networking devices, and deployment of custom Linux-based malware frameworks designed specifically for telecommunications infrastructure. The dual-use approach maximizes intelligence value while strengthening offensive cyber infrastructure, with compromised telecommunications systems serving both espionage collection and traffic anonymization purposes for subsequent Chinese cyber operations.

Attack Details

UAT-7290 Telecommunications Espionage Campaign Overview

Since at least 2022, the China-linked advanced persistent threat known as UAT-7290 has conducted sustained cyber-espionage campaigns against high-value telecommunications infrastructure worldwide. This Chinese APT group pursues two tightly integrated operational goals: penetrating telecommunications networks to extract sensitive intelligence and converting compromised telecommunications systems into covert relay infrastructure supporting wider state-aligned cyber activity. UAT-7290 telecommunications operations reflect sophisticated understanding of telecommunications architecture and strategic value of telecommunications infrastructure for both intelligence collection and operational support.

UAT-7290 Operational Discipline and Geographic Expansion

UAT-7290 telecommunications operations reflect exceptionally high operational discipline and strategic planning. The Chinese APT actor performs extensive reconnaissance before intrusion attempts, exploits publicly disclosed vulnerabilities in telecommunications edge networking devices, and deploys custom malware frameworks built primarily for Linux environments common in telecommunications infrastructure. UAT-7290's recent expansion into Southeastern European telecommunications networks marks a clear increase in geographic reach and strategic intent, demonstrating the group's evolving targeting priorities beyond traditional South Asian telecommunications targets.

UAT-7290 Telecommunications Attack Methodology

UAT-7290 follows a structured telecommunications attack sequence demonstrating methodical approach to telecommunications infrastructure compromise. The Chinese APT begins with detailed technical mapping of targeted telecommunications environments, identifying vulnerable edge devices and network architecture. UAT-7290 then exploits recently disclosed vulnerabilities in telecommunications edge devices, frequently leveraging publicly available proof-of-concept exploit code. These telecommunications exploitation efforts are reinforced with targeted SSH brute-force attacks against exposed telecommunications systems, providing multiple access vectors into telecommunications networks.

UAT-7290 Linux Malware Stack for Telecommunications Persistence

Once telecommunications access is achieved, UAT-7290 installs a specialized Linux-based malware stack designed specifically for persistence on telecommunications edge devices. The telecommunications infection chain starts with RushDrop, a dropper performing anti-analysis checks before deploying the DriveSwitch loader and SilentRaid backdoor components. SilentRaid establishes persistent command-and-control access to telecommunications infrastructure, enabling remote shell execution, port forwarding, file manipulation, and credential theft from telecommunications systems. This modular telecommunications malware architecture provides UAT-7290 with comprehensive control over compromised telecommunications assets.

UAT-7290 Operational Relay Box Infrastructure Creation

After telecommunications infrastructure stabilization, UAT-7290 repurposes compromised telecommunications systems as Operational Relay Boxes through deployment of the Bulbature implant. These telecommunications relay nodes anonymize and route traffic for subsequent Chinese cyber operations, effectively masking origin and attribution for attacks launched through compromised telecommunications infrastructure. This dual-use telecommunications approach maximizes both intelligence and operational value of each compromised telecommunications asset while strengthening the broader Chinese offensive cyber infrastructure through expanded telecommunications relay capabilities.

Recommendations

Strengthen Telecommunications Edge Device Security

Organizations must patch internet-facing telecommunications networking appliances immediately after vulnerability disclosure to prevent UAT-7290 exploitation. Disable unnecessary services on telecommunications edge devices and restrict management interfaces to trusted networks only. Implement robust change management for telecommunications infrastructure to detect unauthorized modifications indicative of UAT-7290 compromise attempts targeting telecommunications systems.

Improve Telecommunications Network Visibility and Monitoring

Deploy continuous monitoring specifically focused on telecommunications infrastructure for abnormal outbound traffic patterns, port forwarding behavior, and persistent command-and-control communications, especially on edge and Linux-based telecommunications systems. Enhanced telecommunications monitoring enables early detection of UAT-7290 relay node establishment and data exfiltration from telecommunications infrastructure before significant intelligence loss occurs.

Restrict Lateral Movement and Persistence in Telecommunications Networks

Apply least-privilege principles rigorously on telecommunications network devices to limit UAT-7290 lateral movement capabilities. Regularly audit startup scripts, cron jobs, and firmware integrity on telecommunications systems to detect implanted persistence mechanisms characteristic of UAT-7290 malware deployment. Implement network segmentation isolating telecommunications management networks from operational infrastructure to contain potential UAT-7290 compromises.

MITRE ATT&CK TTPs

Reconnaissance (TA0043)
  • T1595: Active Scanning - UAT-7290 telecommunications network scanning
  • T1595.002: Vulnerability Scanning - Identification of vulnerable telecommunications systems
Resource Development (TA0042)
  • T1587: Develop Capabilities - UAT-7290 custom telecommunications malware development
  • T1587.001: Malware - RushDrop, DriveSwitch, SilentRaid, Bulbature creation
  • T1588: Obtain Capabilities - Acquisition of telecommunications exploitation tools
  • T1588.005: Exploits - Public exploit code for telecommunications vulnerabilities
  • T1588.006: Vulnerabilities - Telecommunications vulnerability intelligence gathering
Initial Access (TA0001)
  • T1190: Exploit Public-Facing Application - Exploitation of telecommunications edge devices
  • T1110: Brute Force - SSH brute-force against telecommunications systems
  • T1110.001: Password Guessing - Credential attacks on telecommunications infrastructure
Execution (TA0002)
  • T1059: Command and Scripting Interpreter - Command execution on telecommunications systems
  • T1059.004: Unix Shell - Linux shell execution on telecommunications devices
Persistence (TA0003)
  • T1543: Create or Modify System Process - Telecommunications system persistence establishment
Defense Evasion (TA0005)
  • T1027: Obfuscated Files or Information - UAT-7290 malware obfuscation
  • T1027.002: Software Packing - Packed telecommunications malware
  • T1140: Deobfuscate/Decode Files or Information - Runtime malware unpacking
  • T1497: Virtualization/Sandbox Evasion - Anti-analysis capabilities
  • T1497.001: System Checks - Environment detection in telecommunications systems
  • T1564: Hide Artifacts - Concealment of telecommunications compromise
  • T1564.001: Hidden Files and Directories - Hidden malware on telecommunications devices
Credential Access (TA0006)
  • T1552: Unsecured Credentials - Credential theft from telecommunications systems
  • T1552.001: Credentials In Files - Harvesting telecommunications configuration credentials
Discovery (TA0007)
  • T1082: System Information Discovery - Telecommunications system enumeration
  • T1016: System Network Configuration Discovery - Telecommunications network mapping
  • T1083: File and Directory Discovery - Telecommunications file system reconnaissance
Collection (TA0009)
  • T1005: Data from Local System - Intelligence collection from telecommunications infrastructure
Command and Control (TA0011)
  • T1071: Application Layer Protocol - C2 communications with telecommunications infrastructure
  • T1071.001: Web Protocols - HTTP/HTTPS C2 channels
  • T1132: Data Encoding - Encoded telecommunications C2 traffic
  • T1573: Encrypted Channel - Encrypted telecommunications C2 communications
  • T1573.002: Asymmetric Cryptography - Public key cryptography for telecommunications C2
  • T1090: Proxy - Telecommunications proxy infrastructure
  • T1090.002: External Proxy - Operational Relay Box functionality
  • T1572: Protocol Tunneling - Traffic tunneling through telecommunications infrastructure
Exfiltration (TA0010)
  • T1041: Exfiltration Over C2 Channel - Data exfiltration from telecommunications networks

Indicators of Compromise (IOCs)

SHA256 Hashes Associated with UAT-7290 Telecommunications Malware
  • 723c1e59accbb781856a8407f1e64f36038e324d3f0bdb606d35c359ade08200
  • 59568d0e2da98bad46f0e3165bcf8adadbf724d617ccebcfdaeafbb097b81596
  • 961ac6942c41c959be471bd7eea6e708f3222a8a607b51d59063d5c58c54a38d

References