Skip to content
China-Linked UAT-7290 Targets Telecoms in South Asia and Southeastern Europe

China-Linked UAT-7290 Targets Telecoms in South Asia and Southeastern Europe

First seen 9 Jan 2026, 11:48 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The China-linked threat actor UAT-7290 has been conducting espionage attacks since at least 2022, primarily targeting telecom providers in South Asia and Southeastern Europe. The group employs various tools, including RushDrop, DriveSwitch, and SilentRaid, to deeply embed itself in victim networks for espionage purposes.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 194d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Uat-7290 and DriveSwitch in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed