The Containment Era is here. →Explore

Industry Category

Telecommunications

Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.

751 threat reports
Page 43 of 63

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Telecommunications Threat Reports

Showing 505516 / 751 reports
2025 Multi-Vector Breach: WhatsApp Hijacks, MCP Leaks & AI Threats Signal New Era of Cyber Attacks
Impact· medium

2025 Multi-Vector Breach: WhatsApp Hijacks, MCP Leaks & AI Threats Signal New Era of Cyber Attacks

In December 2025, adversaries leveraged multiple cyberattack vectors—including WhatsApp account hijacking, major control plane (MCP) data leaks, generative AI reconnaissance, and the React2Shell exploit—to target organizations worldwide. Attackers combined social engineering, exploitation of unpatched vulnerabilities, and east-west traffic movement for lateral compromise. The orchestration of these tactics led to large-scale credential theft, successful ransomware deployment, and significant data exfiltration across cloud and on-premise environments. Notably, sophisticated evasion and automation tools hindered early detection and response, increasing operational disruption and risk exposure for affected enterprises. This incident exemplifies how weaponized AI, hybrid cloud vulnerabilities, and multi-vector attacks are converging. Organizations face growing urgency for zero trust segmentation, improved encrypted traffic controls, and comprehensive threat detection as attackers exploit interconnected infrastructure weaknesses and automation gaps.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Dormant No More: Prince of Persia APT's Sophisticated Espionage Tactics Unveiled in 2025
Impact· medium

Dormant No More: Prince of Persia APT's Sophisticated Espionage Tactics Unveiled in 2025

In December 2025, security researchers revealed that the dormant Iranian advanced persistent threat (APT) group "Prince of Persia" (also known as "Infy") had remained operational for years, despite perceived inactivity. Leveraging upgraded versions of their Foudre and Tonnerre malware families, the group engaged in persistent cyber espionage targeting Iranian dissidents, as well as individuals in Iraq, Turkey, India, Europe, and Canada. The attackers employed advanced cryptographic techniques for command-and-control (C2) communication—such as RSA signature verification for dynamically generated C2 domains and Telegram-based channels—enabling stealthy, resilient infrastructure and evading traditional detection or takedown efforts. The group’s sophisticated use of operational security, government support, and resilient infrastructure sets it apart from typical regional APTs. This incident underscores increasing sophistication among state-backed APT groups and highlights modern approaches to persistence and evasion, particularly as threat actors adopt novel uses of cryptography and messaging platforms for infrastructure protection. It warns organizations worldwide to review their readiness against stealthy advanced campaigns that evade known countermeasures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
China-Linked Ink Dragon Breaches Governments With ShadowPad and FINALDRAFT Malware
Impact· medium

China-Linked Ink Dragon Breaches Governments With ShadowPad and FINALDRAFT Malware

Between July and October 2025, a sophisticated cyber-espionage campaign orchestrated by the China-linked group 'Ink Dragon' (a.k.a. Jewelbug, CL-STA-0049, Earth Alux, REF7707) targeted multiple European, Southeast Asian, and South American governments. The attackers leveraged advanced tools such as ShadowPad and FINALDRAFT malware to infiltrate official networks, move laterally through compromised systems, and exfiltrate sensitive government data via encrypted channels. Their operations exhibited a high degree of stealth, blending custom malware with legitimate administrative tools and exploiting trust in east-west network flows, putting confidential geopolitical and citizen information at direct risk. This incident underscores the increasing frequency and sophistication of state-sponsored espionage operations against government entities worldwide. It marks a significant trend where threat actors are adopting modular malware and advanced lateral movement techniques, emphasizing the urgent need for stronger east-west security controls and real-time anomaly detection in critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
APT28 Targeted Ukrainian UKR.net Users in Sophisticated Credential Phishing Campaign (2024–2025)
Impact· high

APT28 Targeted Ukrainian UKR.net Users in Sophisticated Credential Phishing Campaign (2024–2025)

Between June 2024 and April 2025, the Russian state-sponsored group APT28 orchestrated a prolonged credential harvesting operation targeting users of UKR.net, one of Ukraine’s most popular webmail and news platforms. Threat intelligence from Recorded Future’s Insikt Group indicates that the attackers leveraged spear-phishing emails, cleverly masquerading as legitimate UKR.net communications, to deceive victims into disclosing their login details on malicious lookalike sites. This campaign continued APT28’s longstanding focus on geopolitical and military targets associated with Ukraine, and raises serious concerns about national security and the exposure of sensitive communications during a period of heightened regional conflict. The incident spotlights a surge in state-sponsored credential theft using advanced social engineering, capitalization on trusted local brands, and persistent, evolving methodologies. As phishing techniques become more adept at bypassing basic controls, organizations are under pressure to bolster identity protection, phishing awareness, and multifactor authentication while aligning closely with regulatory guidance for detection and response.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Inside Kimwolf: How 1.8 Million Android TVs Became a DDoS Botnet Army
Impact· high

Inside Kimwolf: How 1.8 Million Android TVs Became a DDoS Botnet Army

In December 2025, cybersecurity researchers discovered the Kimwolf botnet had hijacked over 1.8 million Android-based smart TVs, set-top boxes, and tablets globally. The attackers leveraged the NDK (Native Development Kit) to compile malware that turned these consumer devices into a massive botnet used primarily for launching large-scale distributed denial-of-service (DDoS) attacks. The infected endpoints were recruited silently and spread across both residential and enterprise networks, enabling the attackers to conduct coordinated, high-bandwidth attacks and evade conventional network defenses. Initial findings also suggest a link between Kimwolf and the previously observed AISURU botnet, indicating possible collaboration or shared tooling between threat actors. This incident highlights a disturbing trend: threat actors increasingly targeting loosely protected IoT and smart device ecosystems for botnet creation. The scale and performance of Kimwolf underscore the growing risk posed by unpatched consumer electronics, calling for urgent improvements in east-west traffic security, segmentation, and network visibility across hybrid environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How BlueDelta (APT28) Targeted UKR.NET with Persistent Credential Harvesting (2024-2025)
Impact· medium

How BlueDelta (APT28) Targeted UKR.NET with Persistent Credential Harvesting (2024-2025)

Between June 2024 and April 2025, Russian state-sponsored threat group BlueDelta (APT28) orchestrated a persistent credential-harvesting campaign targeting users of UKR.NET, a leading Ukrainian webmail and news service. The threat actor employed convincing UKR.NET-lookalike login portals hosted on free services like Mocky, DNS EXIT, ngrok, and Serveo to steal usernames, passwords, and two-factor authentication codes. Phishing lures, primarily PDF attachments embedded with malicious links, were distributed to evade email scanning and sandboxing. Attackers continuously evolved their infrastructure—moving from compromised routers to anonymized tunneling platforms and adding new operational layers—reflecting increasing sophistication and resilience in support of GRU intelligence goals. This campaign exemplifies ongoing adaptations by nation-state actors to Western infrastructure takedowns and detection mechanisms, highlighting escalating risks to critical digital identities. Its advanced evasion techniques, modular infrastructure, and creative abuse of free online services signal a new phase in credential theft, underscoring the urgent need for organizations to reassess their defenses, particularly in the face of targeted phishing and lateral movement threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Sandworm Shifts Tactics: How Misconfigured AWS Edge Devices Enabled State Espionage in 2025
Impact· low

Sandworm Shifts Tactics: How Misconfigured AWS Edge Devices Enabled State Espionage in 2025

In early 2025, Amazon Threat Intelligence disclosed a sustained campaign by Russia's GRU-linked Sandworm (APT44) targeting Western critical infrastructure, with a focus on the energy sector. The threat actors shifted tactics from exploiting software vulnerabilities to exploiting misconfigured network edge devices hosted on AWS as their primary entry vector. Once inside, attackers intercepted sensitive network traffic to steal credentials and leveraged these to expand and maintain access across enterprise and critical infrastructure environments, including electric utilities, energy providers, and managed security providers. Remediation included notification of affected customers, removal of compromised AWS EC2 instances, and intelligence sharing with partners. This incident marks a concerning evolution in nation-state attack tradecraft: adversaries are prioritizing misconfigurations over traditional exploits, highlighting the need for organizations to reassess cloud and hybrid network security. The prevalence of cloud-hosted infrastructure increases urgency around identity and segmentation defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
European Authorities Dismantle Major Call Center Fraud Ring in Ukraine (2024)
Impact· medium

European Authorities Dismantle Major Call Center Fraud Ring in Ukraine (2024)

In mid-2024, European law enforcement agencies succeeded in dismantling a major organized fraud ring operating out of Ukraine. This network used illicit call centers to impersonate financial institutions, manipulating victims across Europe—especially in Germany—into divulging sensitive information or making fraudulent investments. Through sophisticated social engineering techniques and well-structured scripts, the group defrauded thousands of individuals of over 10 million euros. The operation also seized electronic equipment and led to at least five arrests. This incident highlights the ongoing evolution of transnational cybercrime syndicates that exploit human vulnerability through social engineering. Call center fraud, often leveraging modern technologies and cross-border coordination, continues to surge even as regulatory and enforcement actions intensify across Europe.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unisoc Vehicle Modem Breach Exposes Automotive Risks in 2024
Impact· medium

Unisoc Vehicle Modem Breach Exposes Automotive Risks in 2024

In 2024, security researchers uncovered a critical hardware and firmware vulnerability (CVE-2024-39432, CVE-2024-39431) affecting Unisoc UIS7862A modems widely used in modern vehicle head units. Attackers exploited a stack-based buffer overflow in the 3G RLC protocol to achieve unauthenticated remote code execution on the modem, bypassing standard mobile network security. Through this initial access, researchers leveraged hardware vulnerabilities to pivot laterally within the SoC, ultimately gaining privileged control over the Android Application Processor and demonstrating full system compromise—including running arbitrary code on the vehicle's infotainment system. This exposure places vehicle safety, user data privacy, and potentially road safety at significant risk. The incident highlights the urgent and real-world impact of modem and embedded system vulnerabilities as vehicles become increasingly connected. With the proliferation of IoT in critical and mobile environments, attackers are targeting lower-level protocols and hardware integration points, complicating detection and remediation while amplifying the severity of breaches.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Turkey Hit by Advancing Android Banking Trojan: Inside the Frogblight Campaign
Impact· medium

Turkey Hit by Advancing Android Banking Trojan: Inside the Frogblight Campaign

In August 2025, researchers identified a sophisticated Android banking Trojan dubbed "Frogblight" targeting users in Turkey. Distributed primarily through smishing campaigns and phishing sites masquerading as official government portals, Frogblight lured victims by posing as legitimate court case or Chrome browser apps. Once installed, it harvested banking credentials, SMS, contact lists, call logs, and device data, while providing remote device control and persistence mechanisms for operators. The malware communicated via REST API and later WebSockets to exfiltrate stolen data to attacker-controlled C2 servers and was frequently updated with new spyware features, indicating ongoing development and potential adoption as Malware-as-a-Service (MaaS). Frogblight exemplifies the rapid evolution and increasing capabilities of mobile banking malware. The campaign underscores the rising threat to mobile users—particularly in markets where banks and government digital services are trusted attack vectors—and reflects a broader trend toward commoditized MaaS offerings and advanced evasion techniques. Effective mobile security controls and user awareness remain critical as adversaries refine their payloads.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Amazon Reveals Years-Long GRU Cyber Espionage on Critical Cloud & Energy Infrastructure
Impact· low

Amazon Reveals Years-Long GRU Cyber Espionage on Critical Cloud & Energy Infrastructure

Between 2021 and 2025, Amazon's threat intelligence team uncovered a multi-year cyber campaign attributed to Russia's Main Intelligence Directorate (GRU), specifically associated with APT44/Sandworm. The attackers targeted Western energy sector organizations, critical infrastructure providers, and cloud-hosted network environments by exploiting vulnerabilities and, increasingly, leveraging misconfigured network edge devices. This facilitated credential interception and lateral movement through persistent network access, with efforts focused on credential harvesting and replay against victim organizations. Amazon responded by notifying affected customers and disrupting active operations, limiting further impact. This incident underscores the sophistication and persistence of nation-state actors in targeting vital infrastructure by adapting TTPs to minimize exposure. The campaign signals an urgent shift towards exploiting cloud and network misconfigurations rather than relying solely on zero-day vulnerabilities—a trend that broadens risk for organizations across sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Flags Fortinet CVE-2025-59718: Improper Signature Verification Under Active Exploitation
Impact· medium

CISA Flags Fortinet CVE-2025-59718: Improper Signature Verification Under Active Exploitation

In December 2025, CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog, citing confirmed active exploitation targeting Fortinet's multiple products. This vulnerability involves improper verification of cryptographic signatures, allowing attackers to bypass security controls, execute unauthorized code, or escalate privileges on affected devices. Federal agencies, per BOD 22-01, must remediate this critical issue by the mandated deadline to protect their networks. The flaw’s exploitation risks device compromise and potential lateral movement by sophisticated threat actors, with broad implications for data integrity and operational continuity across affected organizations. This alert reflects the escalating trend of attackers rapidly weaponizing supply chain or cryptographic flaws in core network infrastructure. As organizations increasingly rely on complex integrations and encrypted communications, such vulnerabilities underscore persistent challenges in managing risk and ensuring trust in critical systems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports