Bulbature is a malware family tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed January 8, 2026; most recent activity January 12, 2026.
Bulbature is a Linux-based malware family implicated in campaigns against South Asian telecom operators. The reports connect Bulbature to the UAT-7290 operation and to China-linked espionage activity (China Nexus/New China), highlighting its use as a Linux implant in critical telecom infrastructure intrusions and underscoring a shift toward Linux-based tooling in regional cyber-espionage.
A sophisticated threat actor known as UAT-7290, tracked by Cisco Talos, has expanded its operations to target telecommunications providers in Southeastern Europe. This group, which has been active since at least 2022,…
A new threat actor, UAT-7290, has been identified conducting cyberattacks on telecommunications infrastructure in South Asia. This operation is linked to a China-Nexus state-sponsored advanced persistent threat (APT)…
UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…