China-Linked UAT-7290 Cyber-Espionage Campaign Targets Telecom Infrastructure Across South Asia and Europe

Listen to this Post

Featured Image

Introduction: A Quiet but Persistent Telecom Espionage Operation

Telecommunications networks have long been prime targets for state-aligned cyber-espionage, and a newly detailed campaign highlights just how deeply these environments remain exposed. Security researchers have uncovered a multi-year operation aimed at gaining long-term, stealthy access to high-value telecom infrastructure, particularly in South Asia. The campaign, attributed to a sophisticated threat actor known as UAT-7290, reflects a methodical and highly strategic approach to cyber intrusion—one that prioritizes persistence, infrastructure control, and operational reuse over noisy exploitation or rapid monetization.

Summary of the Original Report: Inside the UAT-7290 Campaign

Cisco Talos has attributed a long-running cyber-espionage campaign to a threat actor tracked as UAT-7290, assessing with high confidence that the group is linked to the China-nexus of advanced persistent threat operations. The activity has been ongoing since at least 2022 and primarily targets telecommunications providers, a sector widely regarded as critical national infrastructure due to its role in data transmission, surveillance potential, and emergency communications.

Before initiating intrusions, UAT-7290 performs extensive technical reconnaissance, carefully mapping network environments to identify optimal access points and maximize operational impact. The group focuses on public-facing edge devices, exploiting one-day vulnerabilities in commonly deployed networking hardware and using target-specific SSH brute-force techniques. Rather than relying on zero-day exploits, the actors leverage publicly available proof-of-concept code, demonstrating a pragmatic and resource-efficient tradecraft.

In addition to South Asia, recent activity shows an expansion into Southeastern Europe, suggesting either a broadening mission scope or opportunistic exploitation of similarly exposed telecom environments. Beyond traditional espionage objectives, researchers observed that UAT-7290 has begun establishing Operational Relay Box (ORB) infrastructure. By converting compromised systems into relay nodes, the group enables other China-aligned threat actors to route traffic through these assets, positioning itself as both an intelligence collector and an initial access facilitator.

Technical analysis revealed overlaps with known China-linked operations, including similarities to RedLeaves malware associated with APT10 and ShadowPad, a widely shared malware platform across Chinese threat groups. Victimology and infrastructure patterns also intersect with Red Foxtrot, a group previously tied to a People’s Liberation Army unit. UAT-7290’s tooling is predominantly Linux-based and optimized for edge devices, featuring malware families such as RushDrop, DriveSwitch, and SilentRaid. SilentRaid, the primary backdoor, is modular and supports capabilities like remote shell access, file manipulation, and port forwarding. Another implant, Bulbature, is used to transform compromised devices into relay infrastructure, with recent variants identified on over 140 systems located mainly in China and Hong Kong.

What Undercode Say: Strategic Implications and Threat Actor Evolution

The UAT-7290 campaign reflects a mature evolution in state-aligned cyber operations, where access itself has become a strategic commodity. Rather than focusing solely on intelligence collection from compromised telecom networks, this group appears to be building shared infrastructure that can be reused across multiple operations and even multiple threat actors. This shift toward ORB-style relay networks suggests a longer-term vision centered on resilience, deniability, and scalability.

Telecommunications environments are uniquely valuable because they sit at the intersection of data, metadata, and national security. Persistent access allows threat actors to monitor traffic flows, identify secondary targets, and potentially enable future offensive or coercive actions. By compromising edge devices—often under-monitored and slow to be patched—UAT-7290 exploits a structural weakness common across global telecom deployments.

The reliance on publicly available PoC exploits is also telling. It indicates confidence that defenders will lag behind disclosure cycles and that operational success does not always require advanced exploit development. This lowers costs, accelerates deployment, and makes attribution more complex, as similar techniques are accessible to many actors. However, the consistent victimology, tooling overlap, and infrastructure reuse strongly point to a centralized tasking authority rather than disparate criminal activity.

The overlaps with RedLeaves, ShadowPad, and Red Foxtrot further reinforce the idea of a shared malware ecosystem within the China-nexus. Tool reuse and modular backdoors allow different teams to operate with familiar frameworks while maintaining operational separation. In this context, UAT-7290 may represent a specialized access and infrastructure unit, feeding compromised assets into a broader intelligence and cyber-operations pipeline.

For defenders, the campaign underscores the urgent need to prioritize edge device visibility, credential hygiene, and rapid patch management. Telecom providers, particularly in geopolitically sensitive regions, remain high-value targets not because of what they store, but because of what they enable. UAT-7290’s activity is less about immediate exploitation and more about shaping the digital terrain for future strategic advantage.

Fact Checker Results

✅ Cisco Talos publicly attributed UAT-7290 to China-nexus APT activity with high confidence.

✅ The campaign has been active since at least 2022 and targets telecom infrastructure using edge-device exploits.

❌ No evidence suggests the operation is financially motivated or ransomware-related.

Prediction

🔮 UAT-7290 or similar China-aligned groups will continue expanding ORB infrastructure to support broader regional operations.
🔮 Telecommunications providers in emerging markets will face increased pressure as preferred initial access points.
🔮 Future campaigns are likely to emphasize infrastructure reuse over novel malware development.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon