UAT-7290 Hackers Attacking Critical Infrastructure Entities in South Asia
The UAT-7290 hacker group has been targeting telecommunications companies and critical infrastructure in South Asia since at least 2022. This advanced threat actor shows indications of connections to the Chinese government, posing significant risks to…
The UAT-7290 hacker group has been targeting telecommunications companies and critical infrastructure in South Asia since at least 2022. This advanced threat actor shows indications of connections to the Chinese government, posing significant risks to communication networks within the region. Recently, the group expanded operations into Southeastern Europe.
According to Cisco Talos researchers, UAT-7290 employs a strategic methodology to penetrate targeted systems. Their approach involves extensive planning and technical reconnaissance to gather intelligence on their targets. They utilize a combination of attack vectors, including exploiting known vulnerabilities and executing brute force attacks on internet-facing systems. Additionally, UAT-7290 acts as an initial access provider, compromising systems for other hacking groups to exploit.
The group utilizes a sophisticated set of malware designed for Linux systems, which are prevalent in edge networking devices. Cisco Talos has tracked several malware families used by UAT-7290, including:
RushDrop: A dropper initiating the infection process. DriveSwitch: Facilitates the execution of the primary malware. SilentRaid: Maintains persistent access within compromised networks.
The UAT-7290 hacker group has been targeting telecommunications companies and critical infrastructure in South Asia since at least 2022.
These tools demonstrate the group's technical capabilities and their focus on establishing deep network control.
The infection process highlights UAT-7290's technical expertise. RushDrop initiates by verifying its execution environment to avoid detection. If successful, it establishes a hidden folder named ".pkgdb" and unpacks three components, including:
SilentRaid implant: Extracted as "chargen." BusyBox: A legitimate Linux tool utilized for system command execution.
This method allows attackers to conceal their tools and maintain control without immediate detection.
SilentRaid uses a modular plugin system, providing attackers with various functionalities such as remote shell access, internet port forwarding, and file management on infected systems. Once active, SilentRaid communicates with its control server using a domain name and Google's public DNS service (8.8.8.8) to locate the server's address. This communication strategy helps conceal malicious activities within normal internet traffic, complicating detection for network defenders. The plugin system offers attackers the flexibility to tailor attacks for specific targets by integrating different tools.
Based on reporting by Cyber Security News.
