RushDrop Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
January 9, 2026
Last Seen
January 12, 2026

RushDrop is a malware family tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed January 9, 2026; most recent activity January 12, 2026.

Overview

RushDrop is a malware family associated with the UAT threat cluster, described in recent reporting as using Linux implants to compromise telecommunications targets. The activity is attributed to a China-linked espionage operation and highlights a shift toward Linux-based intrusions in critical telecom infrastructure, underscoring significant risk to regional networks and security operations.

Related Threat Clusters

  • China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign

    Telecommunications providers in South Asia and Southeastern Europe have been targeted by the China-linked threat operation UAT-7290 in a series of cyberespionage attacks. The intrusions involved extensive reconnaissance…

    1 article · Updated January 9, 2026
  • UAT-7290 Cyber Espionage Targets South Asian Telecoms

    UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…

    2 articles · Updated January 12, 2026
  • China-Linked UAT-7290 Targets Telecoms in South Asia and Southeastern Europe

    The China-linked threat actor UAT-7290 has been conducting espionage attacks since at least 2022, primarily targeting telecom providers in South Asia and Southeastern Europe. The group employs various tools, including…

    2 articles · Updated January 9, 2026

Recent Intelligence Reports

  • UAT-7290 Targets South Asian Telecoms with Linux Implants — Socprime · January 12, 2026
  • Telcos subjected to China-linked cyberespionage campaign — Scworld · January 9, 2026
  • Cisco Talos uncovers UAT — Industrialcyber.Co · January 9, 2026
  • China-linked UAT — Securityaffairs.Co · January 9, 2026

CVSS v3.1 Breakdown