TF-MAL-elf.silent_raid
📛 Threat Title
Malware family: SilentRaid
Description
ThreatFox malware family `elf.silent_raid`. Printable name: SilentRaid. Aliases: MystRodX.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bearyangry.com
The group deploys a Linux‑based malware suite (RushDrop, DriveSwitch, SilentRaid ) and leverages Operational Relay Box (ORB) nodes to relay traffic for other actors. Attacks rely on one‑day exploits of edge networking devices and SSH brute‑force against public‑facing infrastructure. How It Might Effect You
-
web:blog.talosintelligence.com
UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop, DriveSwitch, and SilentRaid . Our findings indicate that UAT-7290 conducts extensive technical reconnaissance of target organizations before carrying out intrusions.
-
web:capalearning.com
A recent report by Cisco Talos has linked a China-nexus threat actor known as UAT-7290 to espionage-focused intrusions targeting entities in South Asia and Southeastern Europe. The group, active since at least 2022, conducts extensive technical reconnaissance before deploying malware families like RushDrop, DriveSwitch, and SilentRaid .
-
web:cybersecuritynews.com
UAT-7290's toolkit includes sophisticated malware designed to work on Linux systems, which powers many edge networking devices. The malware families tracked by Cisco Talos include RushDrop, a dropper that starts the infection process; DriveSwitch, which helps execute the main malicious software; and SilentRaid , the central program that ...
-
web:hivepro.com
The infection chain starts with RushDrop, a dropper that performs anti-analysis checks before deploying the DriveSwitch loader and the SilentRaid backdoor. SilentRaid establishes persistent command-and-control access, enabling remote shell execution, port forwarding, file manipulation, and credential theft.
-
web:industrialcyber.co
Researchers from Cisco Talos disclosed a sophisticated threat actor, tracked as UAT-7290, which has been active since at least 2022. The group is assessed as responsible for gaining initial access and conducting espionage-focused intrusions against critical infrastructure entities in South Asia. These hackers employ a dedicated malware arsenal that includes a family of implants referred to as ...
-
web:malpedia.caad.fkie.fraunhofer.de
According to Cisco Talos, SilentRaid is a primary implant used by UAT-7290 in intrusions meant to establish persistent access to compromised endpoints. It communicates with its command-and-control server (C2) and carries out tasks defined in the malware .
-
web:news.backbox.org
Cisco Talos is disclosing a sophisticated threat actor we track as UAT-7290, who has been active since at least 2022. UAT-7290 is tasked with gaining initial access as well as conducting espionage focused intrusions against critical infrastructure entities in South Asia. UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop, DriveSwitch, and SilentRaid . Our ...
-
web:securityaffairs.com
The role of DriveSwitch is to launch SilentRaid , the main backdoor. SilentRaid is modular malware that contacts a command-and-control server and executes tasks through built-in plugins. These plugins enable remote shells, file access, port forwarding, command execution, and data collection, including system files and certificate details.
-
web:www.toddpigram.com
UAT-7290's arsenal includes a malware family consisting of implants we call RushDrop, DriveSwitch, and SilentRaid . Our findings indicate that UAT-7290 conducts extensive technical reconnaissance of target organizations before carrying out intrusions.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.