✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Salt Typhoon 2024: A Wake-Up Call for Telecom Cybersecurity
In 2024, the Chinese state-sponsored hacking group known as Salt Typhoon infiltrated the networks of at least nine major U.S. telecommunications companies, including AT&T, Verizon, and Lumen. The attackers exploited vulnerabilities in Cisco routers to gain access to sensitive metadata, such as call records and text message details, affecting millions of users. This breach enabled the hackers to monitor communications of high-profile individuals, including government officials and political figures, posing significant national security concerns. The Salt Typhoon campaign underscores the escalating threat of nation-state cyber espionage targeting critical infrastructure. Despite subsequent U.S. sanctions and regulatory efforts, the persistence of such sophisticated attacks highlights the urgent need for enhanced cybersecurity measures and international cooperation to safeguard sensitive communications and data.
4 months ago
Kill Chain
SocksEscort Botnet Dismantled in 2025: A Major Blow to Cybercrime
In May 2025, an international law enforcement operation dismantled the SocksEscort botnet, a vast network of compromised small office/home office (SOHO) routers infected with the AVrecon malware. This botnet, active since at least 2023, had infiltrated over 70,000 devices across 20 countries, creating a covert network used for various cybercriminal activities, including digital advertising fraud and password spraying. The takedown involved seizing 34 domains and 23 servers across seven countries, as well as freezing $3.5 million in cryptocurrency linked to the botnet's operations. The operation also led to the indictment of four foreign nationals charged with conspiracy and damage to protected computers. ([justice.gov](https://www.justice.gov/usao-ndok/pr/botnet-dismantled-international-operation-russian-and-kazakhstani-administrators?utm_source=openai)) The SocksEscort botnet's extensive reach and prolonged undetected activity underscore the critical need for enhanced security measures in SOHO routers. This incident highlights the growing trend of cybercriminals exploiting less secure devices to build large-scale botnets, emphasizing the importance of regular firmware updates, robust security configurations, and vigilant monitoring to prevent similar infiltrations.
4 months ago
Kill Chain
Telus Digital's 2026 Data Breach: A Wake-Up Call for Cloud Security
In March 2026, Telus Digital, the business process outsourcing arm of Canadian telecommunications provider Telus, confirmed a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited Google Cloud Platform credentials obtained from a previous breach, enabling them to access Telus Digital's systems over several months. This intrusion led to the exfiltration of nearly 1 petabyte of sensitive data, including customer support records, call logs, and internal corporate information. The breach not only compromised Telus Digital's data but also affected numerous client companies relying on their services. ShinyHunters attempted to extort Telus Digital for $65 million, threatening to release the stolen data publicly. Telus Digital has since engaged cybersecurity experts and law enforcement to investigate and mitigate the breach's impact. This incident underscores the escalating threat posed by sophisticated cybercriminal groups like ShinyHunters, who have been linked to multiple high-profile data thefts and extortion campaigns targeting major organizations worldwide. Their tactics often involve exploiting misconfigured cloud services and leveraging stolen credentials to infiltrate systems, highlighting the critical need for robust security configurations and vigilant monitoring of cloud environments.
4 months ago
Kill Chain
US Authorities Dismantle SocksEscort Proxy Network Exploiting Linux Malware
In March 2026, U.S. and European law enforcement agencies, in collaboration with private partners, dismantled the SocksEscort cybercrime proxy network, which had been operational for over a decade. This network utilized the AVRecon malware to compromise approximately 70,000 small office/home office (SOHO) routers, creating a botnet that offered cybercriminals access to 'clean' residential IP addresses from major ISPs. The service facilitated various illicit activities, including cryptocurrency thefts and financial frauds, resulting in significant monetary losses. ([securityaffairs.com](https://securityaffairs.com/149007/hacking/avrecon-bot-socksescort.html?utm_source=openai)) The disruption of SocksEscort underscores the persistent threat posed by malware targeting SOHO routers, which often lack regular security updates and monitoring. This incident highlights the critical need for enhanced security measures and vigilance in protecting network infrastructure to prevent similar exploitations in the future.
4 months ago
Kill Chain
Mirai Botnet 2016: A Wake-Up Call for IoT Security
In October 2016, the Mirai botnet exploited default credentials on IoT devices to orchestrate one of the largest Distributed Denial-of-Service (DDoS) attacks in history. By scanning the internet for devices with open Telnet ports and using a list of common default usernames and passwords, Mirai infected hundreds of thousands of devices, including routers and IP cameras. These compromised devices were then used to launch massive DDoS attacks, notably targeting DNS provider Dyn, which resulted in widespread internet outages affecting major websites like Twitter, Netflix, and Amazon. The incident underscored the critical security risk posed by default credentials in IoT devices and highlighted the need for manufacturers and users to implement stronger security practices. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Mirai_%28malware%29?utm_source=openai)) The Mirai attack remains relevant today as IoT device proliferation continues, with many devices still shipping with default credentials. Recent studies indicate that a significant percentage of IoT devices retain factory-default passwords, making them susceptible to similar exploitation. This ongoing vulnerability emphasizes the importance of changing default credentials and implementing robust security measures to protect against potential large-scale cyberattacks. ([vulnsy.com](https://www.vulnsy.com/vulnerabilities/default-and-weak-iot-credentials?utm_source=openai))
4 months ago
Kill Chain
Contagious Interview 2026: A Wake-Up Call for Developer Security
In early 2026, North Korean state-sponsored hackers launched the 'Contagious Interview' campaign, targeting software developers through fake job interviews. Posing as recruiters, they lured victims into cloning malicious repositories from platforms like GitHub and opening them in Visual Studio Code. Upon granting trust to these repositories, embedded malicious payloads executed automatically, establishing backdoors for data theft and persistent access. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/?utm_source=openai)) This incident underscores the evolving sophistication of social engineering attacks, particularly within trusted development environments. The exploitation of Visual Studio Code's trusted workspace feature highlights the need for heightened vigilance and security measures in developer workflows. ([csoonline.com](https://www.csoonline.com/article/4119927/contagious-interview-turns-vs-code-into-an-attack-vector.html?utm_source=openai))
4 months ago
Kill Chain
Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity
In March 2026, Stryker Corporation, a leading medical technology company, experienced a significant cyberattack attributed to the pro-Iranian hacktivist group Handala. The attackers claimed to have infiltrated Stryker's global network, exfiltrated 50 terabytes of sensitive data, and deployed wiper malware that erased data on over 200,000 systems, servers, and mobile devices. This attack led to widespread operational disruptions across Stryker's offices in 79 countries, severely impacting their ability to deliver medical products and services. ([investing.com](https://www.investing.com/news/stock-market-news/stryker-stock-falls-34-on-iranlinked-cyberattack-report-93CH-4554963?utm_source=openai)) This incident underscores the escalating threat posed by politically motivated cyberattacks targeting critical infrastructure sectors. Organizations in the healthcare and medical technology industries must enhance their cybersecurity measures to protect against such sophisticated and destructive attacks.
4 months ago
Kill Chain
Meta's 2026 Crackdown on Southeast Asia Scam Networks
In March 2026, Meta, in collaboration with international law enforcement agencies, disabled over 150,000 Facebook and Instagram accounts linked to sophisticated scam centers operating in Southeast Asia. This coordinated effort, involving authorities from countries including Thailand, the U.S., the U.K., and Singapore, also led to 21 arrests by the Royal Thai Police. The crackdown targeted criminal networks in countries like Cambodia, Myanmar, and Laos, which have been running large-scale scam operations designed to evade detection and cause significant harm to individuals globally. ([about.fb.com](https://about.fb.com/news/2026/03/meta-global-law-enforcement-disrupt-major-southeast-asia-criminal-scam-networks/?utm_source=openai)) This operation underscores the escalating threat posed by industrialized online scams and highlights the necessity for continuous collaboration between tech companies and global law enforcement to protect users from increasingly sophisticated fraudulent activities. ([about.fb.com](https://about.fb.com/news/2026/03/meta-global-law-enforcement-disrupt-major-southeast-asia-criminal-scam-networks/?utm_source=openai))
4 months ago
Kill Chain
Chinese APT Group Exploits Middle East Tensions to Target Qatar with PlugX Malware
In early March 2026, the Chinese-linked Advanced Persistent Threat (APT) group known as Camaro Dragon launched a cyber-espionage campaign targeting entities in Qatar. Within 24 hours of the escalation of Middle East tensions, the group deployed PlugX malware using war-themed lure documents that mimicked legitimate communications related to the regional conflict. The infection chain involved malicious LNK files leading to DLL hijacking of a legitimate Baidu NetDisk binary, ultimately installing the PlugX backdoor. This malware enables remote command execution, keystroke logging, screen capture, and data exfiltration. The rapid deployment and contextually relevant lures highlight the group's ability to swiftly adapt to geopolitical events for intelligence gathering purposes. This incident underscores the increasing trend of state-sponsored cyber actors exploiting current geopolitical crises to enhance the effectiveness of their campaigns. Organizations, especially those in geopolitically sensitive regions, must remain vigilant against such rapidly evolving threats and ensure robust cybersecurity measures are in place to detect and mitigate sophisticated intrusion attempts.
4 months ago
Kill Chain
Critical Vulnerabilities in Lantronix EDS3000PS and EDS5000 Devices Threaten Infrastructure Security
In March 2026, multiple critical vulnerabilities were identified in Lantronix EDS3000PS and EDS5000 devices, including OS command injection and authentication bypass issues. Exploitation of these vulnerabilities could allow attackers to execute code with root-level privileges, potentially compromising critical infrastructure sectors such as Communications, Information Technology, and Critical Manufacturing. ([cisa.gov](https://www.cisa.gov/news-events/bulletins/sb22-108?utm_source=openai)) This incident underscores the ongoing risks associated with unpatched vulnerabilities in network devices, highlighting the necessity for organizations to implement robust vulnerability management and regular system updates to mitigate potential threats.
4 months ago
Kill Chain
Critical Vulnerability in Ceragon and Siklu's EtherHaul and MultiHaul Devices (CVE-2025-57176)
In September 2025, a critical vulnerability (CVE-2025-57176) was identified in Ceragon Networks and Siklu Communication's EtherHaul and MultiHaul series devices. The 'rfpiped' service on TCP port 555 allowed unauthenticated file uploads to any writable location on the device. This flaw, present in firmware versions 7.4.0 through 10.7.3, utilized weak encryption for metadata and transmitted file contents in cleartext, lacking authentication and path validation. Exploitation could lead to unauthorized access and control over affected devices. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-57176?utm_source=openai)) This incident underscores the persistent risks associated with inadequate authentication mechanisms in network devices. Organizations must prioritize regular firmware updates and implement robust access controls to mitigate such vulnerabilities.
4 months ago
Kill Chain
KadNap Botnet: A New Threat Targeting ASUS Routers in 2026
In August 2025, cybersecurity researchers identified a new malware strain named KadNap, which primarily targets ASUS routers and other edge networking devices. The malware infiltrates these devices, transforming them into nodes within a botnet that proxies malicious traffic. KadNap employs a customized version of the Kademlia Distributed Hash Table (DHT) protocol, enabling decentralized communication and complicating efforts to detect and disrupt its command-and-control (C2) infrastructure. By March 2026, the botnet had expanded to over 14,000 infected devices, with approximately 60% located in the United States. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/?utm_source=openai)) The emergence of KadNap underscores a growing trend of sophisticated malware leveraging decentralized protocols to enhance resilience against traditional network monitoring and takedown efforts. This incident highlights the critical need for robust security measures in consumer-grade networking equipment, as such devices are increasingly exploited to facilitate large-scale cybercriminal operations.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports