DriveSwitch is a malware family tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed January 9, 2026; most recent activity January 12, 2026.
DriveSwitch is a malware family linked to the China-connected threat actor UAT. Reports describe UAT deploying Linux-based implants against telecom operators in South Asia, framing DriveSwitch as a toolset for espionage-focused intrusions into critical telecommunications infrastructure. The campaigns underscore risk to telecom networks and the involvement of state-aligned threat activity.
Telecommunications providers in South Asia and Southeastern Europe have been targeted by the China-linked threat operation UAT-7290 in a series of cyberespionage attacks. The intrusions involved extensive reconnaissance…
UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…
The China-linked threat actor UAT-7290 has been conducting espionage attacks since at least 2022, primarily targeting telecom providers in South Asia and Southeastern Europe. The group employs various tools, including…