✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
BeatBanker Malware: A New Threat to Android Devices in 2026
In March 2026, cybersecurity researchers identified a new Android malware named BeatBanker, which masquerades as a legitimate Starlink application to infiltrate devices. Once installed, BeatBanker combines banking trojan functionalities with Monero cryptocurrency mining capabilities. It can steal user credentials, manipulate cryptocurrency transactions, and grant attackers full remote control over the infected device. The malware employs sophisticated evasion techniques, including playing an inaudible audio file on a loop to maintain persistence and monitoring device conditions to optimize its operations without raising suspicion. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/?utm_source=openai)) This incident underscores the evolving sophistication of mobile malware, highlighting the need for heightened vigilance among users and organizations. The use of legitimate app disguises and advanced persistence mechanisms signifies a trend towards more covert and resilient cyber threats targeting mobile platforms.
4 months ago
Kill Chain
BeatBanker: The Dual-Mode Android Malware Threatening Brazilian Users in 2026
In March 2026, cybersecurity researchers identified 'BeatBanker,' a sophisticated Android malware campaign targeting users in Brazil. Disguised as legitimate applications, including a fake Google Play Store and a counterfeit Starlink app, BeatBanker employs phishing tactics to infiltrate devices. Once installed, it operates as both a cryptocurrency miner and a banking Trojan, enabling attackers to hijack devices, steal financial credentials, and manipulate cryptocurrency transactions. Notably, the malware maintains persistence by continuously playing an inaudible audio file, preventing system termination. The campaign has evolved to deploy the BTMOB remote administration tool, granting attackers full control over compromised devices. This incident underscores the escalating complexity of mobile malware threats and the critical need for users to download apps exclusively from official sources, scrutinize app permissions, and keep their systems updated to mitigate such risks.
4 months ago
Kill Chain
KadNap Malware: Over 14,000 Asus Routers Hijacked into Stealth Botnet
In August 2025, cybersecurity researchers identified a new malware strain named KadNap, which primarily targets Asus routers to conscript them into a botnet used for proxying malicious traffic. By March 2026, over 14,000 devices had been infected, with more than 60% located in the United States. KadNap employs a customized version of the Kademlia Distributed Hash Table (DHT) protocol, enabling it to conceal command-and-control (C2) infrastructure within a peer-to-peer network, thereby evading traditional network monitoring and enhancing resilience against detection and disruption efforts. The malware is distributed through a shell script that establishes persistence via cron jobs, downloads a malicious ELF file, and executes it, effectively integrating the compromised device into the botnet. ([thehackernews.com](https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html?utm_source=openai)) The emergence of KadNap underscores a growing trend of sophisticated malware targeting edge networking devices, exploiting their vulnerabilities to build resilient botnets. This incident highlights the critical need for organizations and individuals to secure their network infrastructure, as such compromised devices can be leveraged for various malicious activities, including anonymizing cybercriminal operations and facilitating large-scale attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/?utm_source=openai))
4 months ago
Kill Chain
Odido's 2026 Data Breach: A Case Study in Social Engineering Attacks
In February 2026, Dutch telecom provider Odido experienced a significant data breach affecting over 6 million customer accounts. Attackers employed social engineering tactics, including phishing emails and impersonation of IT staff, to gain unauthorized access to Odido's customer relationship management system. This breach exposed sensitive personal information such as names, addresses, telephone numbers, bank account details, dates of birth, and government-issued ID numbers. The incident underscores the critical need for robust employee training and advanced security measures to prevent similar attacks. ([cybernews.com](https://cybernews.com/security/odido-hackers-phishing-attack/?utm_source=openai)) This breach highlights a growing trend of cybercriminals leveraging sophisticated social engineering techniques to infiltrate organizations. As these methods become more prevalent, companies must enhance their security protocols and employee awareness programs to mitigate the risk of such attacks.
4 months ago
Kill Chain
Ericsson US Data Breach: Lessons in Third-Party Risk Management
In April 2025, Ericsson Inc., the U.S. subsidiary of the Swedish telecommunications company, experienced a data breach through one of its service providers. Unauthorized access occurred between April 17 and April 22, 2025, compromising sensitive personal information of employees and customers, including names, addresses, Social Security numbers, driver's license numbers, financial data, medical information, and dates of birth. The breach was detected on April 28, 2025, prompting an investigation that concluded on February 23, 2026, confirming the extent of the data exposure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/?utm_source=openai)) This incident underscores the critical importance of robust third-party risk management and supply chain security. As organizations increasingly rely on external service providers, ensuring these partners adhere to stringent cybersecurity standards is essential to prevent similar breaches and protect sensitive data.
4 months ago
Kill Chain
Chinese Cyber Threat Targets Asian Critical Infrastructure
Since at least 2020, a Chinese-speaking threat actor identified as CL-UNK-1068 has been conducting cyber-espionage campaigns targeting critical infrastructure sectors across South, Southeast, and East Asia. The sectors affected include aviation, energy, government, law enforcement, pharmaceuticals, technology, and telecommunications. The attackers exploit vulnerabilities in public-facing web servers to gain initial access, deploying web shells like GodZilla and AntSword to maintain control. They employ tools such as Mimikatz and LsaRecorder for credential theft, and utilize custom malware alongside open-source utilities to facilitate lateral movement and data exfiltration. ([darkreading.com](https://www.darkreading.com/threat-intelligence/chinese-cyber-threat-critical-asian-sectors?utm_source=openai))This incident underscores the persistent and evolving nature of cyber threats from state-sponsored actors, particularly those linked to China. The use of sophisticated tools and techniques highlights the need for organizations to enhance their cybersecurity measures to detect and mitigate such threats effectively. ([darkreading.com](https://www.darkreading.com/threat-intelligence/chinese-cyber-threat-critical-asian-sectors?utm_source=openai))
4 months ago
Kill Chain
FBI's Surveillance Systems Breached in 2026 by Salt Typhoon
In March 2026, the FBI confirmed a breach affecting systems used to manage surveillance and wiretap warrants. The agency identified and addressed suspicious activities on its networks, leveraging all technical capabilities to respond. While the FBI did not disclose the full scope or impact, the incident underscores the vulnerability of critical law enforcement infrastructure to cyber threats. This breach is part of a broader pattern of cyber espionage activities attributed to state-sponsored actors, notably the Chinese group known as Salt Typhoon. In 2024, Salt Typhoon compromised U.S. federal government systems used for court-authorized network wiretapping requests, highlighting the persistent and evolving nature of cyber threats targeting sensitive government operations.
4 months ago
Kill Chain
China-Linked Hackers Target South American Telecoms with TernDoor, PeerTime, BruteEntry
Since 2024, a China-linked advanced persistent threat (APT) group, identified as UAT-9244, has been targeting critical telecommunications infrastructure in South America. The attackers have deployed three previously undocumented malware implants: TernDoor, a Windows backdoor; PeerTime, a Linux-based peer-to-peer backdoor; and BruteEntry, a brute-force scanner installed on network edge devices. These tools enable the threat actors to gain persistent access, execute arbitrary commands, and expand their reach within compromised networks. ([blog.talosintelligence.com](https://blog.talosintelligence.com/uat-9244/?utm_source=openai)) This campaign underscores the evolving tactics of state-sponsored cyber espionage groups, highlighting the need for robust security measures in the telecommunications sector. The use of diverse malware targeting multiple platforms indicates a sophisticated approach to infiltrating and maintaining access to critical infrastructure. ([blog.talosintelligence.com](https://blog.talosintelligence.com/uat-9244/?utm_source=openai))
4 months ago
Kill Chain
Cisco Firewall Vulnerabilities March 2026: Critical Security Update
In March 2026, Cisco disclosed 48 vulnerabilities across its Secure Firewall product line, including Adaptive Security Appliance (ASA), Firewall Management Center (FMC), and Firewall Threat Defense (FTD) software. Notably, two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20131, both with a CVSS score of 10.0, were identified in the FMC's web interface. CVE-2026-20079 allows unauthenticated attackers to bypass authentication and execute scripts, potentially gaining root access to the underlying operating system. CVE-2026-20131 involves insecure deserialization, enabling remote code execution with root privileges. Cisco has released patches for these vulnerabilities and strongly recommends immediate updates to mitigate potential exploitation. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) The disclosure of these critical vulnerabilities underscores the persistent targeting of network infrastructure by threat actors. Organizations are urged to prioritize patching and review their security postures to defend against potential exploits targeting firewall management interfaces.
4 months ago
Kill Chain
Iran's Integration of Cyber and Kinetic Warfare in 2026
In early 2026, Iranian threat actors intensified cyber operations targeting internet-connected surveillance cameras across the Middle East, including Israel, Qatar, Bahrain, Kuwait, the UAE, and Cyprus. These attacks, which began on February 28, coincided with missile strikes in the region, suggesting a coordinated effort to use compromised cameras for operational planning and battle damage assessment. The targeted devices, primarily from manufacturers Hikvision and Dahua, were exploited using known vulnerabilities, aligning with Iran's established military doctrine of integrating cyber and kinetic warfare. This incident underscores the evolving nature of cyber threats, where digital intrusions are increasingly used to support and enhance physical military operations. Organizations must recognize the strategic use of cyber capabilities in modern conflicts and bolster their defenses accordingly.
4 months ago
Kill Chain
Cisco 2026 Unauthenticated Remote Code Execution Vulnerabilities
In March 2026, Cisco disclosed two critical vulnerabilities in its Secure Firewall Management Center (FMC) software, identified as CVE-2026-20079 and CVE-2026-20131. These flaws allow unauthenticated, remote attackers to execute arbitrary code with root privileges on affected devices via the web-based management interface. CVE-2026-20079 arises from an improper system process created at boot time, enabling authentication bypass and script execution. CVE-2026-20131 results from insecure deserialization of user-supplied Java byte streams, permitting arbitrary Java code execution. Cisco has released software updates to address these vulnerabilities and recommends immediate application to mitigate potential risks. ([cisco.com](https://www.cisco.com/content/en/us/support/docs/csa/cisco-sa-fmc-rce-NKhnULJh.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the persistent threat posed by unauthenticated remote code execution flaws in critical infrastructure. Organizations are urged to assess their exposure, apply patches promptly, and review access controls to prevent exploitation. This incident highlights the importance of proactive vulnerability management and the need for continuous monitoring of security advisories from vendors.
4 months ago
Kill Chain
FBI's Surveillance Network Breached in 2026: Potential Link to Salt Typhoon
In early March 2026, the Federal Bureau of Investigation (FBI) identified and addressed suspicious cyber activities targeting its internal networks. The affected system, known as the Digital Collection Systems Network, is utilized for managing surveillance data, including wiretaps and pen registers. While the FBI has not publicly disclosed the extent of the breach or the actors involved, the incident raises significant concerns about the security of sensitive law enforcement information. ([cbsnews.com](https://www.cbsnews.com/news/fbi-confirms-its-networks-were-targeted-by-suspicious-cyber-activities/?utm_source=openai)) This breach underscores the persistent threat posed by state-sponsored hacking groups, notably China's Salt Typhoon, which has a history of infiltrating U.S. telecommunications and surveillance systems. The incident highlights the urgent need for enhanced cybersecurity measures to protect critical infrastructure from sophisticated cyber espionage campaigns. ([techcrunch.com](https://techcrunch.com/2025/02/13/chinas-salt-typhoon-hackers-continue-to-breach-telecom-firms-despite-us-sanctions/?utm_source=openai))
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports