TF-MAL-elf.rush_drop
📛 Threat Title
Malware family: RushDrop
Description
ThreatFox malware family `elf.rush_drop`. Printable name: RushDrop. Aliases: ChronosRAT.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bearyangry.com
China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes Date of Data Posted: 2026‑01‑08 What You Need to Be Aware Of UAT‑7290 is a China‑linked threat actor focused on espionage against telecom operators in South Asia and Southeast Europe. The group deploys a Linux‑based malware suite ( RushDrop , DriveSwitch, SilentRaid) and leverages Operational Relay Box (ORB) nodes ...
-
web:blog.talosintelligence.com
UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop , DriveSwitch, and SilentRaid. Our findings indicate that UAT-7290 conducts extensive technical reconnaissance of target organizations before carrying out intrusions.
-
web:hivepro.com
The infection chain starts with RushDrop , a dropper that performs anti-analysis checks before deploying the DriveSwitch loader and the SilentRaid backdoor. SilentRaid establishes persistent command-and-control access, enabling remote shell execution, port forwarding, file manipulation, and credential theft.
-
web:industrialcyber.co
These hackers employ a dedicated malware arsenal that includes a family of implants referred to as RushDrop , DriveSwitch, and SilentRaid. RushDrop functions as the initial dropper that kickstarts the infection chain and is also known as ChronosRAT.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Cisco Talos, RushDrop is a dropper used by UAT-7290 for deploying SilentRaid
-
web:news.backbox.org
Cisco Talos is disclosing a sophisticated threat actor we track as UAT-7290, who has been active since at least 2022. UAT-7290 is tasked with gaining initial access as well as conducting espionage focused intrusions against critical infrastructure entities in South Asia. UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop , DriveSwitch, and SilentRaid. Our ...
-
web:socprime.com
China-linked UAT-7290 targets telecoms via edge devices, deploying RushDrop , DriveSwitch, SilentRaid, and ORB nodes. Key detection, mitigation , and IR steps.
-
web:www.broadcom.com
Once inside, they deploy a diverse arsenal of tools, including custom Linux malware variants such as RushDrop , DriveSwitch, and SilentRaid (the primary implant for persistence). Symantec protects you from this threat, identified by the following: Carbon Black-based
-
web:www.linkedin.com
These hackers employ a dedicated malware arsenal that includes a family of implants referred to as RushDrop , DriveSwitch, and SilentRaid.
-
web:www.toddpigram.com
UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop , DriveSwitch, and SilentRaid. Our findings indicate that UAT-7290 conducts extensive technical reconnaissance of target organizations before carrying out intrusions.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.