✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Asian State-Backed Group TGR-STA-1030 Breaches 70 Government, Infrastructure Entities
Between January 2024 and February 2026, the cyber espionage group TGR-STA-1030, assessed to be state-aligned and operating out of Asia, compromised at least 70 government and critical infrastructure organizations across 37 countries. The group employed phishing emails and exploited known software vulnerabilities to gain initial access, subsequently deploying tools like the Diaoyu Loader and the ShadowGuard rootkit to maintain persistence and exfiltrate sensitive data. Notable targets included national law enforcement agencies, ministries of finance, and departments focusing on trade and diplomacy. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/?utm_source=openai)) This incident underscores the escalating sophistication and reach of state-sponsored cyber espionage activities, highlighting the urgent need for enhanced cybersecurity measures and international cooperation to protect critical infrastructure and sensitive governmental data.
5 months ago
Kill Chain
DKnife AitM Framework: A New Threat to Network Security
In February 2026, cybersecurity researchers uncovered 'DKnife,' a sophisticated adversary-in-the-middle (AitM) framework operated by China-linked threat actors since at least 2019. This Linux-based toolkit comprises seven implants designed for deep packet inspection, traffic manipulation, and malware delivery via compromised routers and edge devices. DKnife primarily targets Chinese-speaking users by hijacking binary downloads and Android application updates to deploy backdoors like ShadowPad and DarkNimbus. ([thehackernews.com](https://thehackernews.com/2026/02/china-linked-dknife-aitm-framework.html?utm_source=openai)) The discovery of DKnife underscores the escalating threat posed by AitM attacks leveraging compromised network infrastructure. This incident highlights the need for enhanced security measures to protect routers and edge devices from sophisticated exploitation techniques. ([thehackernews.com](https://thehackernews.com/2026/02/china-linked-dknife-aitm-framework.html?utm_source=openai))
5 months ago
Kill Chain
CISA's 2026 Directive: Strengthening Federal Network Security by Removing Unsupported Edge Devices
In February 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-02, mandating Federal Civilian Executive Branch agencies to identify and remove unsupported edge devices—such as routers, firewalls, and switches—that no longer receive security updates. This directive aims to mitigate risks posed by state-sponsored threat actors exploiting these vulnerable devices to gain unauthorized access to federal networks. Agencies are required to update, catalog, and decommission these devices within specified timeframes, culminating in the establishment of a continuous lifecycle management process within 24 months. This initiative underscores the critical need for proactive asset management and the elimination of technical debt to enhance national cybersecurity resilience.
5 months ago
Kill Chain
Ransomware Gangs Exploit ISPsystem VMs for Stealthy Payload Delivery
In early 2026, cybersecurity researchers uncovered that multiple ransomware groups, including LockBit, Qilin, Conti, BlackCat/ALPHV, and Ursnif, were exploiting virtual machines (VMs) provisioned by ISPsystem's VMmanager to host and deliver malicious payloads. These attackers utilized default Windows VM templates with identical hostnames, allowing them to blend malicious infrastructure with legitimate systems, thereby complicating detection and takedown efforts. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-ispsystem-vms-for-stealthy-payload-delivery/?utm_source=openai)) This incident highlights a growing trend where cybercriminals leverage legitimate virtualization platforms to obfuscate their operations. The ease of deploying VMs with default configurations presents a significant security risk, emphasizing the need for organizations to scrutinize and secure their virtual infrastructure to prevent such abuses. ([sophos.com](https://www.sophos.com/en-us/blog/malicious-use-of-virtual-machine-infrastructure?utm_source=openai))
5 months ago
Kill Chain
Infy APT 2026: Iranian State-Sponsored Cyber Espionage Resurfaces
In early 2026, the Iranian state-sponsored Advanced Persistent Threat (APT) group known as Infy, or 'Prince of Persia,' resumed operations following a period of inactivity during Iran's internet blackout in January. The group deployed updated versions of their malware tools, Foudre and Tonnerre, to target entities across Iran, Iraq, Turkey, India, Canada, and Europe. Notably, Infy utilized a new command-and-control (C2) infrastructure, incorporating both HTTP and Telegram for communication, and exploited a 1-day vulnerability in WinRAR to deliver their payloads. This resurgence underscores Infy's continued commitment to cyber espionage activities aligned with Tehran's strategic interests. ([thehackernews.com](https://thehackernews.com/2026/02/infy-hackers-resume-operations-with-new.html?utm_source=openai)) The re-emergence of Infy highlights the persistent threat posed by state-sponsored cyber actors who continuously evolve their tactics to evade detection. Organizations, especially those in the targeted regions, must remain vigilant and enhance their cybersecurity measures to defend against such sophisticated threats.
5 months ago
Kill Chain
Aisuru/Kimwolf Botnet's Unprecedented 31.4 Tbps DDoS Attack in 2025
In December 2025, the Aisuru/Kimwolf botnet launched a record-breaking distributed denial-of-service (DDoS) attack, peaking at 31.4 terabits per second (Tbps) and 200 million requests per second. This unprecedented assault targeted multiple companies, primarily in the telecommunications sector, and Cloudflare's own infrastructure. The attack, part of a campaign dubbed "The Night Before Christmas," was successfully mitigated by Cloudflare's automated systems, preventing significant disruptions. ([techradar.com](https://www.techradar.com/pro/security/the-biggest-ddos-attack-ever-has-been-detected-but-fortunately-you-probably-barely-noticed-it?utm_source=openai)) This incident underscores the escalating scale and sophistication of DDoS attacks, highlighting the urgent need for robust cybersecurity measures. The rapid growth of botnets like Aisuru/Kimwolf, which exploit vulnerabilities in IoT devices, poses a significant threat to global internet infrastructure. ([tomshardware.com](https://www.tomshardware.com/service-providers/network-providers/botnet-smashes-ddos-traffic-record-at-31-4-tb-s-equivalent-to-streaming-2-2-million-netflix-4k-movies-at-once-attack-was-large-enough-to-take-entire-countries-offline?utm_source=openai))
5 months ago
Kill Chain
CISA's 2025 KEV Catalog Expansion: A Wake-Up Call for Cybersecurity
In 2025, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) catalog by 245 entries, marking a 20% increase and bringing the total to 1,484 vulnerabilities. Notably, 24 of these newly added vulnerabilities were actively exploited in ransomware attacks, targeting products from vendors such as Microsoft, Apple, and Oracle. This surge underscores the escalating threat landscape where attackers rapidly exploit both new and legacy vulnerabilities. The inclusion of older vulnerabilities, some dating back to 2007, highlights the persistent risk posed by unpatched systems. The rapid weaponization of these vulnerabilities by threat actors emphasizes the critical need for organizations to prioritize timely patching and robust vulnerability management practices to mitigate potential breaches and operational disruptions.
5 months ago
Kill Chain
Salt Typhoon 2025: Unveiling the Global Espionage Campaign
In 2025, the Chinese state-sponsored cyber group known as Salt Typhoon orchestrated a sophisticated global espionage campaign, compromising government and critical infrastructure across 37 countries and conducting reconnaissance in 155 nations. The attackers exploited unpatched vulnerabilities in networking equipment, including those from Ivanti, Palo Alto, and Cisco, to gain initial access. Once inside, they established persistent access by modifying access control lists, creating privileged accounts, and enabling remote management on unusual high ports. This allowed them to monitor communications, harvest administrator credentials, and exfiltrate sensitive data through covert tunnels, all while remaining undetected for extended periods. The campaign's targets included telecommunications networks, government systems, transportation hubs, lodging networks, and military infrastructure, enabling continuous surveillance of individuals, communications, and movements globally. ([forbes.com](https://www.forbes.com/sites/emilsayegh/2025/08/30/us-and-allies-declare-salt-typhoon-hack-a-national-defense-crisis/?utm_source=openai)) The Salt Typhoon campaign underscores the escalating threat posed by state-sponsored cyber actors and the vulnerabilities within critical infrastructure. The attackers' ability to exploit known vulnerabilities and maintain long-term access highlights the urgent need for organizations to prioritize timely patching, robust access controls, and comprehensive monitoring to detect and mitigate such sophisticated threats.
5 months ago
Kill Chain
Chronus Hack Exposes Millions in Mexican Government Data Breach 2026
In January 2026, the Mexican government faced a significant data breach when the hacker group Chronus infiltrated at least twenty public institutions, including the Mexican Tax Administration Service (SAT) and the Mexican Social Security Institute's Welfare Program (IMSS-Bienestar). The attackers exfiltrated sensitive data encompassing tax records, personal information, and professional details of millions of citizens. This breach exposed critical vulnerabilities in the government's digital infrastructure, leading to heightened risks of identity theft, fraud, and extortion. Despite the severity of the incident, official responses have been limited, raising concerns about the state's preparedness and transparency in handling cybersecurity threats. This incident underscores a troubling trend of escalating cyberattacks targeting Mexican governmental entities. The increasing sophistication and frequency of such breaches highlight the urgent need for robust cybersecurity measures and proactive strategies to safeguard sensitive public data against evolving digital threats.
5 months ago
Kill Chain
CISA Highlights Four Actively Exploited Vulnerabilities in February 2026
In February 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2019-19006 and CVE-2025-64328 in Sangoma FreePBX, CVE-2021-39935 in GitLab Community and Enterprise Editions, and CVE-2025-40551 in SolarWinds Web Help Desk. The vulnerabilities range from improper authentication and OS command injection to server-side request forgery and deserialization of untrusted data, posing significant risks to affected systems. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation efforts to mitigate potential exploitation, as these vulnerabilities are actively targeted by malicious actors.
5 months ago
Kill Chain
Notepad++ Supply Chain Attack: A 2025 Case Study
In June 2025, the Chinese state-sponsored group Lotus Blossom compromised the update infrastructure of Notepad++, a widely used open-source text editor. By infiltrating the hosting provider's server, the attackers selectively redirected update requests from targeted users to malicious servers, delivering trojanized installers embedded with a custom backdoor named Chrysalis. This sophisticated supply chain attack persisted until December 2025, affecting users in sectors such as government, telecommunications, and financial services. ([cyberscoop.com](https://cyberscoop.com/china-espionage-group-lotus-blossom-attacks-notepad/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks, where trusted software distribution channels are exploited to infiltrate targeted systems. Organizations must enhance their software supply chain security measures to mitigate such risks. ([orca.security](https://orca.security/resources/blog/notepad-plus-plus-supply-chain-attack/?utm_source=openai))
5 months ago
Kill Chain
Notepad++ Supply Chain Attack: A 2025 Case Study
Between June and December 2025, the update mechanism of Notepad++, a widely used text editor, was compromised by state-sponsored attackers. These adversaries infiltrated the shared hosting server of notepad-plus-plus.org, allowing them to intercept and redirect update traffic to malicious servers. This redirection led to the distribution of trojanized installers to select users, primarily targeting telecommunications and financial services organizations in East Asia. The attackers maintained access to internal services until December 2, 2025, enabling continued redirection of update traffic even after losing direct server access. ([arstechnica.com](https://arstechnica.com/security/2026/02/notepad-updater-was-compromised-for-6-months-in-supply-chain-attack/?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software infrastructure is exploited to distribute malware. Organizations must enhance their security measures, particularly in verifying the integrity of software updates, to mitigate such risks. ([cybernews.com](https://cybernews.com/security/state-sponsored-hackers-behind-notepad-plus-plus-hack/?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports