✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Unveiling the 2026 Fake CAPTCHA IRSF Scam
In April 2026, cybersecurity researchers uncovered a sophisticated telecommunications fraud campaign leveraging fake CAPTCHA verifications to deceive users into sending international SMS messages. This scheme, active since at least June 2020, exploits social engineering tactics and browser vulnerabilities to generate illicit revenue through International Revenue Share Fraud (IRSF). Victims, believing they are completing standard CAPTCHA tests, unknowingly send multiple SMS messages to premium-rate international numbers, incurring significant charges on their mobile bills. This incident highlights the evolving nature of cyber threats, where attackers combine traditional social engineering with technical exploitation to achieve financial gain. The use of familiar web elements like CAPTCHAs in fraudulent schemes underscores the need for heightened user awareness and robust security measures to detect and prevent such deceptive practices.
3 months ago
Kill Chain
Toronto Authorities Dismantle SMS Blaster Operation, Arrest Three
In April 2026, Canadian authorities arrested three individuals in Toronto for operating an 'SMS blaster' device that impersonated legitimate cellular towers to send phishing text messages to nearby mobile phones. These devices tricked phones into connecting by emitting stronger signals, allowing operators to distribute fraudulent messages appearing to come from trusted entities like banks or government agencies. The investigation, dubbed 'Project Lighthouse,' revealed that the operation led to 13 million instances of mobile network entrapment, temporarily disconnecting devices from their legitimate networks and potentially blocking access to emergency services. This incident underscores the evolving tactics of cybercriminals in exploiting mobile network vulnerabilities. The use of mobile SMS blasters represents a significant escalation in smishing attacks, highlighting the need for enhanced security measures and public awareness to mitigate such threats.
3 months ago
Kill Chain
Scattered Spider Hacker Arrested in Finland Faces U.S. Charges
In April 2026, a 19-year-old dual U.S. and Estonian citizen, known online as "Bouquet," was arrested at Helsinki Airport in Finland while attempting to board a flight to Japan. U.S. federal prosecutors have charged him with wire fraud, conspiracy, and computer intrusion, alleging his involvement in at least four cyberattacks orchestrated by the Scattered Spider hacking group. These attacks, dating back to March 2023, targeted multiple large corporations, resulting in millions of dollars in ransom payments and significant operational disruptions. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-reportedly-charges-scattered-spider-hacker-arrested-in-finland/?utm_source=openai)) This arrest underscores the persistent threat posed by cybercriminal groups like Scattered Spider, which employ sophisticated social engineering tactics to infiltrate organizations. The incident highlights the critical need for robust cybersecurity measures, including advanced threat detection and employee training, to mitigate the risks associated with such attacks.
2 months ago
Kill Chain
UK Issues Warning on Chinese Hackers Using Botnets to Evade Detection
In April 2026, the UK's National Cyber Security Centre (NCSC) and international partners issued a warning about Chinese state-sponsored hackers employing large-scale proxy networks composed of hijacked consumer devices to evade detection. These botnets, primarily consisting of compromised small office/home office (SOHO) routers and Internet of Things (IoT) devices, enable attackers to route malicious traffic through multiple nodes, obscuring their origins and complicating attribution. This tactic has been linked to groups such as Flax Typhoon and Volt Typhoon, which have targeted critical infrastructure sectors including military, government, telecommunications, and IT. The increasing use of such covert networks signifies a strategic shift in cyber operations, highlighting the need for enhanced security measures. Organizations are advised to implement multifactor authentication, monitor network edge devices, utilize dynamic threat intelligence feeds, and adopt zero-trust architectures to mitigate the risks posed by these evolving threats.
3 months ago
Kill Chain
GopherWhisper APT Group's 2026 Cyber Espionage Campaign
In April 2026, cybersecurity researchers identified a previously undocumented state-sponsored threat actor named GopherWhisper, active since at least 2023 and linked to China. This group targeted governmental institutions, notably in Mongolia, deploying a suite of custom malware primarily written in Go. GopherWhisper's toolkit includes backdoors such as LaxGopher, RatGopher, and BoxOfFriends, which exploit legitimate services like Slack, Discord, and Microsoft 365 Outlook for command-and-control communications. Additionally, the group utilized the CompactGopher tool to exfiltrate data via the file-sharing service file.io. These sophisticated tactics enabled the attackers to blend malicious activities with normal network traffic, complicating detection efforts. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-gopherwhisper-apt-group-abuses-outlook-slack-discord-for-comms/?utm_source=openai)) The discovery of GopherWhisper underscores a growing trend among threat actors to abuse widely used communication platforms for cyber espionage. This incident highlights the necessity for organizations to implement robust monitoring and anomaly detection systems to identify unauthorized use of legitimate services, as traditional security measures may be insufficient against such covert operations.
3 months ago
Kill Chain
The Rise of AI-Driven Cyber Attacks in 2026
In 2026, organizations worldwide faced a significant surge in AI-driven cyberattacks, with adversaries leveraging advanced AI tools to automate and scale their operations. These attacks included hyper-personalized phishing campaigns, AI-enhanced malware, and rapid exploitation of vulnerabilities, leading to substantial financial losses and operational disruptions. The integration of AI into cyberattack methodologies has drastically reduced the time between vulnerability discovery and exploitation, challenging traditional cybersecurity defenses. This escalation underscores the urgent need for organizations to adopt AI-powered defensive measures, enhance threat intelligence capabilities, and implement robust security frameworks to mitigate the evolving risks posed by AI-enhanced cyber threats.
3 months ago
Kill Chain
GopherWhisper APT Exploits Go-Based Backdoors to Target Mongolian Government
In January 2025, ESET researchers identified a previously undocumented China-aligned advanced persistent threat (APT) group named GopherWhisper targeting Mongolian governmental institutions. The group employs a suite of tools primarily written in Go, including injectors and loaders, to deploy various backdoors such as LaxGopher, RatGopher, and BoxOfFriends. GopherWhisper leverages legitimate services like Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control (C&C) communications and data exfiltration. The group's activities have been ongoing since at least November 2023, compromising at least 12 systems within a Mongolian government entity. ([globenewswire.com](https://www.globenewswire.com/news-release/2026/04/23/3279634/0/en/ESET-Research-discovers-new-China-aligned-group-GopherWhisper-It-abuses-messaging-services-Discord-Slack-and-Outlook-to-spy.html?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored threat actors who exploit widely used communication platforms to evade detection. The use of Go-based malware highlights a trend towards more versatile and cross-platform attack tools, posing significant challenges for traditional security measures. Organizations must adapt their defenses to address these sophisticated techniques.
3 months ago
Kill Chain
Chinese APT GopherWhisper Exploits Cloud Services in Mongolian Cyber Espionage
In April 2026, ESET researchers uncovered a Chinese advanced persistent threat (APT) group named GopherWhisper targeting Mongolian government institutions. Active since at least November 2023, GopherWhisper deployed multiple custom backdoors—LaxGopher, CompactGopher, RatGopher, BoxOfFriends, and SSLORDoor—each utilizing different cloud services like Slack, Discord, Microsoft Outlook, and file.io for command-and-control communications and data exfiltration. This campaign compromised at least 12 systems within a Mongolian governmental institution, with indications of broader impact across the region. This incident underscores a growing trend of APT groups leveraging legitimate cloud services to evade detection and maintain persistent access. Organizations must enhance their monitoring of cloud-based communications and implement robust security measures to detect and mitigate such sophisticated threats.
3 months ago
Kill Chain
Harvester's Linux GoGra Backdoor Exploits Microsoft Graph API
In April 2026, the state-sponsored Harvester group deployed a Linux variant of its GoGra backdoor, utilizing the Microsoft Graph API and Outlook mailboxes for covert command-and-control communications. This sophisticated malware exploits legitimate Microsoft infrastructure to evade detection, targeting telecommunications, government, and IT organizations in South Asia. The Linux GoGra backdoor shares significant code similarities with its Windows counterpart, indicating a concerted effort by Harvester to expand its cross-platform capabilities. The emergence of this Linux variant underscores a growing trend among threat actors to develop multi-platform malware that leverages trusted cloud services for stealthy operations. Organizations must enhance their monitoring of cloud API interactions and implement robust security measures to detect and mitigate such advanced threats.
3 months ago
Kill Chain
Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process
In April 2026, cybersecurity researchers uncovered a sophisticated 'Caller-as-a-Service' (CaaS) fraud operation, where cybercriminals have structured their activities to mirror legitimate call centers. These operations involve specialized roles such as malware developers, phishing kit builders, infrastructure operators, and scam callers, all working in concert to execute large-scale social engineering attacks. This professionalization has led to a significant increase in the efficiency and impact of fraudulent phone calls, resulting in substantial financial losses and emotional distress for victims. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-caller-as-a-service-fraud-the-scam-economy-has-a-hiring-process/?utm_source=openai)) The emergence of CaaS highlights a critical evolution in cybercrime, emphasizing the need for enhanced security measures and public awareness. As these fraudulent operations become more organized and effective, individuals and organizations must adopt proactive strategies to detect and prevent such sophisticated social engineering attacks.
3 months ago
Kill Chain
Mirai Botnet Exploits D-Link Router Vulnerability CVE-2025-29635
In March 2026, Akamai's Security Intelligence and Response Team (SIRT) identified active exploitation of CVE-2025-29635, a command injection vulnerability in D-Link DIR-823X routers, by a new Mirai-based malware campaign. Attackers are sending POST requests to the vulnerable endpoint, executing remote commands to download and install a Mirai variant named "tuxnokill," which enables the compromised devices to perform distributed denial-of-service (DDoS) attacks. This marks the first observed in-the-wild exploitation of this vulnerability since its disclosure in March 2025. ([akamai.com](https://www.akamai.com/blog/security-research/cve-2025-29635-mirai-campaign-targets-d-link-devices?utm_source=openai)) The exploitation of end-of-life (EoL) devices underscores the critical need for organizations to replace outdated hardware and apply security patches promptly. The resurgence of Mirai variants targeting unpatched IoT devices highlights the ongoing threat posed by botnets leveraging known vulnerabilities. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-mirai-campaign-exploits-rce-flaw-in-eol-d-link-routers/?utm_source=openai))
3 months ago
Kill Chain
Harvester's Linux GoGra Backdoor: A New Threat in South Asia
In April 2026, the Harvester threat actor deployed a new Linux variant of its GoGra backdoor targeting entities in South Asia. The malware utilizes the Microsoft Graph API and Outlook mailboxes as covert command-and-control channels, enabling it to bypass traditional network defenses. Initial access is achieved through social engineering tactics, tricking victims into executing ELF binaries disguised as PDF documents. Once installed, the backdoor communicates with a specific Outlook mailbox folder named "Zomato Pizza," executing commands received via emails with subjects starting with "Input" and sending execution results back with the subject "Output." ([thehackernews.com](https://thehackernews.com/2026/04/harvester-deploys-linux-gogra-backdoor.html?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors like Harvester, who are expanding their toolsets to include cross-platform capabilities and leveraging legitimate cloud services to evade detection. The use of Microsoft's cloud infrastructure for command-and-control highlights the need for organizations to monitor and secure their cloud environments against such sophisticated threats.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports