✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Tomiris APT 2025: Abuse of Telegram, Discord & Multi-Language Toolkit in Advanced Government Attacks
In early 2025, the Tomiris APT group launched a sophisticated cyberespionage campaign targeting foreign ministries, intergovernmental organizations, and government entities across Russia and Central Asia. Using spear-phishing emails with password-protected malicious archives, Tomiris delivered a diverse toolkit of implants written in C/C++, Rust, Go, C#, and Python. Their malware leveraged public services like Telegram and Discord for command-and-control (C2), employed open-source frameworks such as Havoc and AdaptixC2, and enabled attackers to perform reconnaissance, maintain persistence, and exfiltrate sensitive data, while evading traditional network defenses by blending illicit traffic with legitimate channels. This incident highlights a clear evolution in APT tradecraft: rapid adoption of multi-language toolchains, creative lateral movement, and the abuse of popular cloud-based services for covert operations. With the continued rise of lawful-shadow C2 channels and open-source post-exploitation kits, organizations face heightened risks from identity-driven, stealthy attacks that challenge conventional segmentation and anomaly detection strategies.
6 months ago
Kill Chain
2025 Multi-Vector Attack: AI Malware, Voice Bots, Crypto Laundering & IoT Breach
In November 2025, threat analysts observed a coordinated, multi-vector cyberattack campaign targeting enterprises across finance, healthcare, and IoT-heavy sectors. Attackers leveraged AI-powered malware, compromised voice bots, and elaborate cryptocurrency laundering techniques to infiltrate organizations, bypass security controls, and exfiltrate sensitive data. Initial access was achieved via sophisticated phishing augmented by AI voice impersonation, while lateral movement and data theft exploited weaknesses in internal segmentation and unencrypted east-west traffic. The campaign’s complexity resulted in service downtime, financial losses, and data exposure for several multinational organizations. This incident is notable for blending diverse threat techniques—AI-driven social engineering, voice-based exploits, and infrastructure abuses—reflecting the current trend towards multifaceted attacks capable of outmaneuvering traditional defenses. The scale and automation highlight increased attacker innovation and challenge existing compliance and zero trust frameworks.
6 months ago
Kill Chain
Bloody Wolf's NetSupport RAT Campaign Breaches Kyrgyzstan and Uzbekistan: 2025 Analysis
In mid-2025, the threat actor known as Bloody Wolf launched a targeted cyber campaign against government and enterprise entities in Kyrgyzstan, later expanding its operations to Uzbekistan by October 2025. Utilizing sophisticated phishing lures, attackers delivered Java-based loaders that deployed the NetSupport Remote Access Trojan (RAT), allowing persistent access and potential data exfiltration. The campaign featured advanced evasion tactics, encrypted command-and-control traffic, and was attributed by Group-IB and local cybersecurity agencies. Affected organizations faced risks of unauthorized network access and potential compromise of sensitive information. This incident highlights ongoing regional cybercrime escalation, especially the trend of weaponizing legitimate tools like NetSupport RAT through creative malware loaders. With cross-border expansion and zero-day techniques, the event exemplifies how remote access trojans are reshaping threat landscapes and driving demand for advanced network and east-west traffic controls.
6 months ago
Kill Chain
ASUS Issues Urgent Patch for Critical AiCloud Authentication Bypass Flaw in Routers
In June 2024, ASUS disclosed a critical authentication bypass vulnerability (CVE-2024-3080) affecting several router models running AiCloud. Attackers could exploit this flaw remotely, without authentication, to gain administrative access and potentially control router functions—enabling unauthorized changes, interception of network traffic, and further lateral movement within home or small business networks. The flaw was one of nine vulnerabilities addressed by an urgent firmware patch released by ASUS, after receiving responsible disclosure and industry warnings. Although there are no major reports of exploitation in the wild yet, affected users were strongly urged to update immediately to prevent potential compromise. This incident highlights the increasing targeting of network infrastructure and IoT devices by attackers seeking easy entry points into corporate and personal environments. With a surge in authentication bypasses and router-based exploits, organizations and individuals must prioritize timely patching and implement additional network segmentation and anomaly detection controls.
6 months ago
Kill Chain
ShadowV2 Botnet Turns AWS Outage into Opportunity: 2024 IoT and Hybrid Cloud Attacks Surge
In June 2024, a new botnet malware known as ShadowV2 emerged, leveraging Mirai source code to target IoT devices, particularly from D-Link and TP-Link, exploiting known vulnerabilities for large-scale infection. Security researchers observed the malware operators using the widespread AWS outage as an opportunity to test command and control resilience, evade detection, and enhance lateral spread across hybrid and cloud networks. Initial access occurred via unpatched vulnerabilities in internet-facing devices, leading to rapid compromise and recruitment of thousands of endpoints, posing heightened risks to corporate and critical infrastructure systems. Detection was challenged by the use of encrypted and east-west traffic, with attackers adapting quickly to shifting network topologies. This incident highlights the increasing sophistication of IoT-focused botnets and their opportunistic exploitation of cloud service disruptions. Organizations with hybrid or cloud-connected assets are strongly urged to reassess east-west traffic controls, segmentation, and anomaly detection, as automated threats now more readily exploit both vulnerable devices and network instability.
6 months ago
Kill Chain
Comcast Fined After 2024 Vendor Data Breach Hits 270,000 Customers
In February 2024, Comcast, one of the largest U.S. telecommunications providers, suffered a significant data breach due to a third-party vendor's security lapse. The incident resulted in unauthorized access to the personally identifiable information (PII) of nearly 275,000 Comcast customers. Exposed data included names, addresses, and partial account credentials. The breach was traced to vulnerabilities in the vendor's security infrastructure, highlighting risks posed by supply chain and vendor relationships. Following the breach, the Federal Communications Commission fined Comcast $1.5 million as part of its investigation into the company's responsibilities and controls over customer data. This case underscores the persistent and growing threat of supply chain breaches, which are increasingly targeted by cyber adversaries seeking to exploit trust relationships between organizations and their service providers. Regulatory bodies are intensifying scrutiny and penalties around third-party risk management following a pattern of similar high-impact incidents.
6 months ago
Kill Chain
Executive Breach Brief: Scattered LAPSUS$ Hunters’ 2025 Salesforce Ransomware Campaign
In May 2025, the Scattered LAPSUS$ Hunters (SLSH) cybercriminal group orchestrated a wide-scale ransomware and data extortion campaign targeting the Salesforce environments of over thirty major corporations, including brands like Toyota, FedEx, Disney/Hulu, and UPS. Leveraging sophisticated voice phishing for initial access, SLSH tricked employees into connecting malicious apps to internal Salesforce portals, facilitating rapid exfiltration of sensitive corporate data. Public threats of mass data leaks via their extortion site, insider recruitment, and the deployment of the new ShinySp1d3r ransomware further amplified organizational and reputational risk, prompting companies and regulators to respond swiftly. This incident exemplifies the convergence of advanced social engineering and ransomware-as-a-service models, alongside a growing ecosystem of cybercrime collaboration. Attackers’ use of collaboration platforms, custom malware, and drive to monetize breaches through both data theft and extortion spotlights the need for zero trust and enhanced compliance controls in identity, SaaS, and egress security.
6 months ago
Kill Chain
How Iran Blended Cyber and Kinetic Strikes: The 2024 Critical Infrastructure Attack
In early 2024, Iranian state-sponsored threat actors coordinated sophisticated cyber-attacks in parallel with kinetic strikes targeting maritime and land-based assets in the Middle East. Leveraging advanced reconnaissance and lateral movement within targeted networks, attackers exploited encrypted and unencrypted traffic flows to identify critical systems and facilitate precision missile and drone attacks. These operations, often timed to coincide with physical assaults, compromised internal infrastructure, leading to service disruption, operational delays, and data exfiltration impacting both regional governments and commercial enterprises. This incident highlights a rapidly evolving threat landscape where nation-state adversaries integrate cyber intrusions with physical warfare. The tactical use of data from east-west traffic, paired with real-time targeting for kinetic operations, signals the urgent need for organizations to elevate network segmentation, encryption standards, and visibility to meet new regulatory and threat actor challenges.
6 months ago
Kill Chain
CISA Uncovers 2025 Spyware Assaults on Signal and WhatsApp Users
In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert regarding active espionage campaigns exploiting commercial spyware and remote access trojans (RATs) to compromise high-value users on secure messaging apps including Signal and WhatsApp. Attackers utilized sophisticated social engineering techniques—such as phishing and malicious links—to covertly deliver malware, enabling unauthorized access to users' encrypted chats, sensitive attachments, and even device controls. The victims ranged from executives and journalists to government officials, highlighting the background emergence of advanced social engineering paired with novel spyware kit deployment. The incident triggered heightened scrutiny of both messaging app security and endpoint defense controls. This event is emblematic of a growing surge in targeted surveillance operations against individuals using encrypted communication platforms. It raises concern over the effectiveness of endpoint security, user awareness, and the need for proactive threat intelligence, while highlighting an evolution in adversary tactics toward cloud-based and identity-driven infiltration.
6 months ago
Kill Chain
How Online Formatting Tools Exposed Thousands of Credentials: The JSONFormatter & CodeBeautify Leak
In late 2025, researchers uncovered that thousands of sensitive credentials, including passwords and API keys from governments, telecoms, and critical infrastructure organizations, were exposed after being pasted into public web-based code formatting tools such as JSONFormatter and CodeBeautify. This inadvertent data exposure occurred over several years, as users leveraged these tools for convenience, unaware that information was being logged and stored without proper security. Security experts at watchTowr Labs discovered over 80,000 files containing this data, raising alarm over the significant risk posed to organizations relying on manual and unsecured workflows. This incident has highlighted the growing risks of shadow IT and insecure use of web utilities in enterprise environments. It mirrors a broader trend of misconfigured third-party tools creating substantial vulnerabilities, elevating concerns amid regulatory crackdowns and increased exploitation of exposed secrets by attackers.
6 months ago
Kill Chain
Zenitel TCIV-3+ 2025: Critical ICS Vulnerabilities Enable Remote Attacks
In November 2025, Zenitel disclosed multiple critical vulnerabilities affecting its TCIV-3+ intercom systems, widely deployed in communications-critical infrastructure worldwide. Security researchers from Claroty Team82 identified three separate OS command injection flaws (CVE-2025-64126, -64127, -64128), as well as a severe out-of-bounds write and a reflected cross-site scripting vulnerability. These issues allowed threat actors to remotely execute arbitrary code or cause denial-of-service conditions without authentication, putting operational technology environments at significant risk of disruption or compromise. The vulnerabilities require only low-complexity attacks and no user interaction, amplifying their business impact. This incident highlights the ongoing critical importance of securing industrial control system components exposed to remote exploitation. With threat actors increasingly targeting IoT and OT devices in critical communications infrastructure, these types of vulnerabilities are seeing a dramatic rise globally, and patching urgency is at an all-time high.
6 months ago
Kill Chain
Chinese APTs Target Russian IT Firms via Cloud: Inside the 2024 Espionage Breach
In early 2024, Chinese state-sponsored threat actors leveraged commercial cloud services as command-and-control channels to conduct covert cyber espionage against leading Russian IT organizations. The sophisticated attackers evaded detection by hiding their communications within encrypted cloud traffic, enabling them to obtain sensitive data and intelligence from critical Russian technology infrastructure. The breach underscores the risks posed by advanced persistent threats (APTs) operating stealthily in hybrid, multicloud environments using legitimate cloud tools. The incident heightened tensions between China and Russia due to the exposure of confidential communications and potentially proprietary technologies. This breach demonstrates a growing trend of nation-state actors blending in with legitimate cloud activity, making detection far more challenging for defenders. It signals a shift in cyber espionage tactics, intensifying the urgency for organizations to strengthen east-west visibility, enforce zero trust principles, and monitor cloud infrastructure for anomalous behavior.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports