The Containment Era is here. →Explore

Executive Summary

In early 2026, a sophisticated China-linked threat actor designated UAT-7290 orchestrated targeted espionage campaigns against telecommunications providers across South Asia and Southeastern Europe. The attackers conducted meticulous intelligence gathering before leveraging one-day vulnerabilities and SSH brute-forcing to compromise exposed edge devices. Malicious payloads—including RushDrop, DriveSwitch, and the advanced SilentRaid—enabled persistent access, covert lateral movement, and deployment of Operational Relay Box (ORB) infrastructure, which can be used by other threat groups. Their arsenal blends open-source tools and bespoke Linux implants, demonstrating mature tradecraft and adaptability.

This campaign reflects the increasing frequency and complexity of transnational espionage assaults on critical infrastructure, exploiting modern hybrid networks and advanced malware suites. Organizations in telecom and related sectors face mounting pressure to enhance east-west traffic controls, patch velocity, and incident response capabilities to defend against evolving APT operations.

Why This Matters Now

The recent UAT-7290 intrusions highlight the urgency of advanced east-west security controls and zero trust strategies for organizations with distributed and hybrid networks. As attackers exploit edge device vulnerabilities with open-source exploits and tailor-made malware, immediate action is critical to reduce dwell time, prevent lateral movement, and limit exposure to coordinated espionage threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

They exploited one-day vulnerabilities and performed targeted SSH brute-forcing against public-facing edge devices, leveraging both open-source exploits and custom Linux malware.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Implementing Zero Trust segmentation, egress enforcement, encrypted traffic controls, and centralized visibility as defined in CNSF would have significantly reduced the success and reach of each kill chain stage—limiting attacker lateral movement, detecting anomalous activity, and blocking C2 and data exfiltration attempts.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocking of unauthorized inbound traffic and scanning attempts.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Detection and alerting on suspicious privilege escalation behavior.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Containment of attacker movement through granular segmentation and least privilege policy.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Prevention and detection of unauthorized outbound C2 traffic.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Visibility into encrypted flows and enforcement of data-in-transit policies to block exfiltration.

Impact (Mitigations)

Early detection of adversary dwell time and infrastructure abuse.

Impact at a Glance

Affected Business Functions

  • Network Operations
  • Customer Data Management
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $1,000,000

Data Exposure

Potential exposure of sensitive customer data, including personal information and communication records.

Recommended Actions

  • Deploy Zero Trust segmentation and microsegmentation to block lateral movement and restrict workload access.
  • Enforce strong egress filtering and outbound policy to disrupt C2 and data exfiltration attempts.
  • Integrate threat detection and behavioral analytics for rapid identification of privilege escalation and dwell time.
  • Secure all edge and hybrid connectivity with encrypted traffic inspection (MACsec/IPsec/VPN) and minimize attack surface.
  • Centralize multicloud visibility and automate network policy orchestration to quickly detect and respond to anomalous activity.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image