✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
When Threats Collide: 2025's Multi-Vector Breach Exposes Gaps from Database to Wallet
In December 2025, a rapid succession of cyber incidents targeted multiple sectors, blending attacks on exposed MongoDB instances, large-scale cryptocurrency wallet breaches, Android device spyware campaigns, and insider threat activity within enterprises. Attackers exploited both unpatched vulnerabilities and legitimate remote access mechanisms, leveraging high-speed lateral movements and targeting cloud infrastructures, regulated data, and financial assets. The breaches compromised sensitive customer data and business-critical systems, highlighting a coordinated pivot between vectors such as cloud misconfiguration, mobile malware, and abuse of internal access privileges. This wave underscores a growing convergence of threat vectors and the urgent need for unified defense frameworks. With attackers accelerating their use of automation, targeting east-west traffic, and blending traditional and emerging attack paths, organizations face mounting pressure to enhance multicloud visibility, segmentation, and real-time anomaly response.
6 months ago
Kill Chain
Salt Typhoon’s 2025 Onslaught: How a Nation-State Breached US Telecoms
In 2025, the Chinese state-sponsored APT group Salt Typhoon (Operator Panda) executed a series of sophisticated cyber-espionage operations targeting major US telecom companies and government agencies, including Verizon, AT&T, Lumen Technologies, Viasat, and the US National Guard. Exploiting vulnerabilities in internet-exposed network devices—such as routers, VPN appliances, and security gear—Salt Typhoon bypassed traditional endpoint defenses and established persistent access over the course of nearly a year. Their campaigns involved targeting wiretapping infrastructure and internal communications, enabling data exfiltration and pre-positioning for further attacks. This incident underscores the escalating risk posed by advanced nation-state attackers exploiting unpatched edge devices. With a surge in supply-chain attacks, east-west lateral movement, and strain on government cyber resources following budget cuts, organizations must prioritize zero trust segmentation, unified network visibility, and proactive threat detection to combat evolving cross-domain adversaries.
6 months ago
Kill Chain
Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign
Between November 2022 and November 2024, the China-linked Evasive Panda APT group conducted a sophisticated cyber espionage campaign targeting entities in Türkiye, China, and India. The attackers leveraged DNS poisoning techniques to redirect requests for popular software updates (such as SohuVA and Tencent QQ) to attacker-controlled infrastructure. Through adversary-in-the-middle attacks, victims received trojanized loaders, which proceeded to fetch and decrypt highly targeted MgBot backdoors. The attack chain involved supply chain and AitM vectors, advanced encryption and obfuscation methods, and allowed persistent compromise and broad data theft, including keylogging and credential exfiltration. This campaign highlights the growing sophistication of APT operations exploiting core network infrastructure such as DNS to evade perimeter defenses. The increased prevalence of similar DNS-manipulation campaigns and targeted malware delivery emphasizes the urgent need for robust segmentation, encrypted traffic, and thorough network and endpoint visibility.
6 months ago
Kill Chain
How a Latvian Insider Hacked an Italian Ferry's IoT Systems in 2025
In December 2025, an Italian ferry operator experienced a significant cybersecurity breach when a Latvian national was arrested for installing malware directly onto the vessel's onboard systems. Unlike a remote attack, the malware was physically introduced, potentially via a compromised insider or unauthorized access point. This compromised the ferry's IoT devices, impacting operational systems and potentially exposing sensitive data in transit. The incident raised immediate safety and privacy concerns and temporarily disrupted critical ferry services, drawing attention to the security of maritime transportation and IoT infrastructure. This event illustrates the mounting risks associated with connected operational technology in critical transportation sectors. As attackers increasingly target IoT and cyber-physical systems — particularly with the rise of insider-enabled methods — organizations must prioritize endpoint hardening, east-west traffic monitoring, and full-stack threat detection to safeguard vital infrastructure.
6 months ago
Kill Chain
Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)
Between November 2022 and November 2024, the Evasive Panda APT group executed a sophisticated campaign targeting victims primarily in Türkiye, China, and India. Leveraging adversary-in-the-middle (AitM) techniques and DNS poisoning, the attackers delivered a unique MgBot malware implant through fake software updates and stealthy loaders. The operation employed hybrid encryption, memory injection in signed executables, and evaded traditional defenses to maintain long-term persistence. Multiple new and legacy C2 infrastructures enabled sustained access while attackers tailored payloads based on the victim’s OS. This incident showcases the ongoing evolution of nation-state threat actors, utilizing advanced evasion, supply chain impersonation, and DNS manipulation to bypass security controls. It reflects a broader surge in attacks exploiting trust in software supply chains and underlines the need for continuously adaptive security strategies as actor sophistication grows.
6 months ago
Kill Chain
npm Supply-Chain Breach: Malicious Package Steals WhatsApp Accounts and Messages
In June 2024, security researchers uncovered a malicious npm package masquerading as a legitimate WhatsApp Web API library. The package, downloaded from the Node Package Manager (NPM) registry, surreptitiously executed code to hijack WhatsApp accounts by stealing authentication credentials, intercepting messages, and exfiltrating contact information. Attackers leveraged this supply-chain compromise to gain unauthorized access to WhatsApp accounts, putting personal messages and sensitive user data at risk. The incident underscores growing threats targeting developer ecosystems and open-source repositories, demonstrating how a single compromised package can have widespread impact across organizations and individuals relying on shared libraries. This attack is particularly significant as adversaries increasingly exploit the software supply chain to distribute malware through trusted open-source ecosystems. Organizations face heightened regulatory scrutiny over software integrity, and similar tactics are quickly proliferating, prompting urgent calls for enhanced dependency management and real-time code vetting across the industry.
6 months ago
Kill Chain
Uzbekistan 2025: Wonderland Android Malware Campaign Steals Millions via Mobile Banking Fraud
In late 2025, a sophisticated cybercrime operation in Uzbekistan targeted Android users through the deployment of advanced dropper apps that installed the Wonderland malware. Disguised as legitimate Google Play or popular media files, these malicious APKs leveraged social engineering and fake landing pages to trick users into installation after enabling 'unknown sources.' The threat actor group, TrickyWonders, coordinated their campaign via Telegram, using heavily obfuscated droppers (MidnightDat and RoundRift) and dynamic C2 infrastructure. Once on a device, Wonderland enabled real-time SMS and OTP theft, phone number hijacking, lateral propagation via Telegram session compromise, and banking fraud, resulting in significant financial losses for victims. This incident underscores a broader trend: attackers are rapidly iterating their methods, shifting towards deceptive dropper-based infection chains, robust C2 agility, and hierarchically structured cybercrime operations. The campaign’s evolution, paired with similar threats like Cellik, Frogblight, and NexusRoute, signals an urgent need for improved mobile endpoint security, user awareness, and regulatory vigilance.
6 months ago
Kill Chain
Uzbekistan Telegram Users Hit by Sophisticated Android SMS-Stealer Campaign in 2024
In early 2024, Android users in Uzbekistan experienced a surge of targeted attacks as cybercriminals deployed SMS-stealer malware through phishing campaigns delivered via Telegram. The attackers leveraged fake and malicious applications purpose-built to intercept and exfiltrate SMS messages, enabling unauthorized access to multi-factor authentication codes and banking credentials. Threat actors demonstrated increasing sophistication and adaptability by iterating on malware variants, incorporating obfuscation tactics, and exploiting the popularity of Telegram as a distribution channel. This resulted in significant risks of financial theft and compromised user privacy across a large segment of Uzbek Android device users. This incident highlights the evolving landscape of mobile infostealer attacks in Central Asia, with a marked uptick in the use of instant messaging platforms as malware delivery vectors. The swift adaptation of criminal tactics underscores the necessity for organizations and individuals to strengthen mobile endpoint security and remain vigilant against increasingly convincing phishing and sideloading threats.
6 months ago
Kill Chain
Iranian Infy APT Returns: 2025 Malware Campaign Exposes New Espionage Threats
In December 2025, the Iranian nation-state APT group known as Infy ("Prince of Persia") resurfaced after years of dormancy, launching a covert cyber espionage campaign using upgraded versions of its Foudre and Tonnerre malware. The attack targeted high-value individuals and organizations across Iran, Iraq, Turkey, India, Canada, and several European countries. Entry was achieved primarily via malicious Excel attachments in phishing campaigns, enabling long-term surveillance, data exfiltration, and direct access to encrypted communications such as Telegram chats. The attackers employed advanced tactics such as a Domain Generation Algorithm for resilient C2, RSA-based C2 validation, and selective victim targeting to remain undetected and persist in victim environments. The Infy resurgence illuminates how persistent APT actors adapt tools and methods for stealth operations, leveraging social engineering and technical innovation. This case illustrates the increasing threat of highly-targeted, identity-driven espionage attacks that undermine both personal privacy and organizational security.
6 months ago
Kill Chain
Cisco VPNs and Email Service Campaigns: How Multi-Vector Attacks Are Changing the Cyber Risk Landscape
In early 2024, Cisco VPN appliances and various enterprise email services were targeted in two distinct but nearly simultaneous cyber campaigns. The first, a highly coordinated attack, leveraged zero-day vulnerabilities and credential harvesting to infiltrate corporate VPNs, granting attackers lateral access to sensitive networks. Around the same period, a separate 'spray-and-pray' phishing wave indiscriminately targeted a wide swath of business email services, seeking to exploit weak authentication and unpatched systems. Combined, the incidents led to multiple business disruptions, credential leaks, and prompted extensive incident response efforts across affected organizations. This incident is part of a larger trend where cybercriminals simultaneously exploit both remote-access infrastructure and cloud-based email, reflecting a shift toward multi-vector, blended attacks. Organizations are facing heightened regulatory and operational pressure to defend against ever more sophisticated and opportunistic threats targeting identity, access points, and critical communications systems.
6 months ago
Kill Chain
FBI Reveals Years-Long Deepfake Impersonation Campaign Against U.S. Officials
From 2023 onward, unknown threat actors used AI-powered voice cloning and deepfake techniques to impersonate senior U.S. government officials, including members of the White House and Congress. These attacks targeted officials, their families, and associates via initial SMS contact, escalating to encrypted messaging platforms such as Signal, WhatsApp, and Telegram. Once rapport was established, attackers used tailored pretexts to request sensitive personal information, passport photos, device syncing, introductions, or even funds transfers, posing as, or on behalf of, high-profile government leaders. The campaign enabled further impersonation by harvesting victims’ contact lists and executing subsequent rounds of targeted smishing and vishing attacks. This incident underscores the escalation of social engineering campaigns powered by generative AI, as adversaries blend deepfake technologies with encrypted communications to evade detection and amplify deception. The evolving tactics, targeting highly sensitive circles, highlight both the sophistication of modern impersonation attacks and the urgent need for updated identity verification protocols.
6 months ago
Kill Chain
Cloud Atlas 2025: APT Espionage Hits Russian and Belarusian Organizations via Cloud-Based Implants
In the first half of 2025, the persistent threat group Cloud Atlas launched a series of sophisticated cyber-espionage campaigns targeting organizations in Russia and Belarus. Attackers employed spear-phishing emails with weaponized Microsoft Office documents exploiting CVE-2018-0802, initiating a complex multi-stage infection chain. Custom implants such as VBShower, VBCloud, CloudAtlas, and PowerShower enabled attackers to establish persistent access, exfiltrate sensitive data, steal credentials, and abuse cloud-based C2 channels. Multiple sectors were affected, including telecommunications, construction, government, and manufacturing, with operations characterized by stealthy lateral movement, DLL hijacking, and multi-layered payload delivery. This incident is significant due to Cloud Atlas's use of novel, previously undocumented toolsets and cloud service abuse, reflecting a trend among APT actors toward cloud-based, modular attacks. It highlights the urgent need for heightened east-west security, advanced threat visibility, and multi-layered cloud controls, amid continued evolution of state-sponsored threat tactics.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports