China-linked actor targets telecom infrastructure
Cisco Talos has published an analysis of the threat actor UAT-7290, linked to China and active since at least 2022. The actor primarily targets telecommunications infrastructure, with a focus on South Asia, for espionage and strategic network access. Its toolkit combines custom and open-source malware, and it exploits vulnerabilities to establish persistence and conduct reconnaissance.
What this means for your organisation
Telecom infrastructure underpins nearly all other operations. Talos notes the actor may operate operational relay boxes, that is compromised devices used as intermediaries in other operations. A Norwegian organisation can therefore be affected in two ways: through its provider, or by having its own equipment used to mask attacks on others. The overlap with known China-nexus malware ecosystems suggests access may be reused by several actors over time.
Berigo recommends
- Map which communications providers the organisation depends on, and require notification of security incidents in their infrastructure.
- Monitor outbound traffic from routers, firewalls and other network equipment, not only from clients and servers.
- Keep network equipment firmware current and ensure management interfaces are not exposed to the internet.
- Include long-running, quiet espionage as a distinct scenario in the risk assessment, not only incidents that cause immediate downtime.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch