s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.rush_drop

📛 Threat Title

Malware family: RushDrop

Category: RushDrop First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.rush_drop`. Printable name: RushDrop. Aliases: ChronosRAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:bearyangry.com

    China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes Date of Data Posted: 2026‑01‑08 What You Need to Be Aware Of UAT‑7290 is a China‑linked threat actor focused on espionage against telecom operators in South Asia and Southeast Europe. The group deploys a Linux‑based malware suite ( RushDrop , DriveSwitch, SilentRaid) and leverages Operational Relay Box (ORB) nodes ...

  • web:blog.talosintelligence.com

    UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop , DriveSwitch, and SilentRaid. Our findings indicate that UAT-7290 conducts extensive technical reconnaissance of target organizations before carrying out intrusions.

  • web:hivepro.com

    The infection chain starts with RushDrop , a dropper that performs anti-analysis checks before deploying the DriveSwitch loader and the SilentRaid backdoor. SilentRaid establishes persistent command-and-control access, enabling remote shell execution, port forwarding, file manipulation, and credential theft.

  • web:industrialcyber.co

    These hackers employ a dedicated malware arsenal that includes a family of implants referred to as RushDrop , DriveSwitch, and SilentRaid. RushDrop functions as the initial dropper that kickstarts the infection chain and is also known as ChronosRAT.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Cisco Talos, RushDrop is a dropper used by UAT-7290 for deploying SilentRaid

  • web:news.backbox.org

    Cisco Talos is disclosing a sophisticated threat actor we track as UAT-7290, who has been active since at least 2022. UAT-7290 is tasked with gaining initial access as well as conducting espionage focused intrusions against critical infrastructure entities in South Asia. UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop , DriveSwitch, and SilentRaid. Our ...

  • web:socprime.com

    China-linked UAT-7290 targets telecoms via edge devices, deploying RushDrop , DriveSwitch, SilentRaid, and ORB nodes. Key detection, mitigation , and IR steps.

  • web:www.broadcom.com

    Once inside, they deploy a diverse arsenal of tools, including custom Linux malware variants such as RushDrop , DriveSwitch, and SilentRaid (the primary implant for persistence). Symantec protects you from this threat, identified by the following: Carbon Black-based

  • web:www.linkedin.com

    These hackers employ a dedicated malware arsenal that includes a family of implants referred to as RushDrop , DriveSwitch, and SilentRaid.

  • web:www.toddpigram.com

    UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop , DriveSwitch, and SilentRaid. Our findings indicate that UAT-7290 conducts extensive technical reconnaissance of target organizations before carrying out intrusions.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.