Purple Typhoon is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 9, 2026; most recent activity January 9, 2026.
Purple Typhoon is an APT group linked to the China Nexus espionage operation. It targets telecommunications operators in South Asia to conduct espionage, highlighting a focus on critical regional infrastructure and the ongoing risk of state-sponsored cyber-espionage against communications networks.
A new threat actor, UAT-7290, has been identified conducting cyberattacks on telecommunications infrastructure in South Asia. This operation is linked to a China-Nexus state-sponsored advanced persistent threat (APT)…