Bulbature Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
January 8, 2026
Last Seen
January 12, 2026

Bulbature is a malware family tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed January 8, 2026; most recent activity January 12, 2026.

Overview

Bulbature is a Linux-based malware family implicated in campaigns against South Asian telecom operators. The reports connect Bulbature to the UAT-7290 operation and to China-linked espionage activity (China Nexus/New China), highlighting its use as a Linux implant in critical telecom infrastructure intrusions and underscoring a shift toward Linux-based tooling in regional cyber-espionage.

Related Threat Clusters

Recent Intelligence Reports

  • UAT-7290 Targets South Asian Telecoms with Linux Implants — Socprime · January 12, 2026
  • Cisco Talos uncovers UAT — Industrialcyber.Co · January 9, 2026
  • China-Nexus Espionage APT Targets South Asia Telecoms — Technadu · January 9, 2026
  • New China — Bleepingcomputer · January 8, 2026

CVSS v3.1 Breakdown