✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Superbox Android TV Botnet: The Silent Takeover of Consumer Home Networks
In June-November 2025, thousands of Superbox Android TV streaming devices sold through major U.S. retailers were discovered to be covertly enrolled in a global botnet and residential proxy service, relaying internet traffic for cybercriminals without explicit user consent. Forensic analysis revealed pre-installed or required third-party apps that hijacked consumers’ networks for malware distribution, ad fraud, and account takeover campaigns, while redirecting connections to Chinese servers and proxy aggregation services. The incident drew attention from cyber intelligence firms, Google, and law enforcement as a major example of pre-compromised consumer IoT supply chain risk, with impacts ranging from individual privacy invasions to the widescale abuse of residential IP addresses for criminal operations. This breach highlights the accelerating trend of consumer IoT and smart devices being targeted for botnet recruitment and criminal proxy operations, often by exploiting unofficial app ecosystems and distribution channels. The case underscores mounting regulatory scrutiny, the complexity of securing home networks, and the growing need for device supply chain and east-west traffic visibility in both enterprise and residential environments.
6 months ago
Kill Chain
WhatsApp’s 2024 API Flaw: 3.5 Billion Accounts Exposed via Automated Scraping
In early 2024, a significant data exposure incident affected WhatsApp when researchers discovered and exploited a vulnerability in the platform's contact-discovery API. The API lacked effective rate limiting and permitted mass enumeration of registered user accounts by automating queries, enabling adversaries to harvest data on approximately 3.5 billion mobile phone numbers and associated details. No evidence suggests the involvement of a deliberate threat actor beyond security researchers, but the scale and scope highlight serious privacy and operational risks for both users and WhatsApp’s business integrity. The incident underscores ongoing risks for messaging applications leveraging public-facing APIs without stringent access and abuse controls. This breach is highly relevant as API abuse and large-scale account enumeration techniques are increasingly exploited by attackers seeking personal data. Regulatory scrutiny is poised to intensify, and similar flaws are being reported across numerous communications platforms, making robust API security and anomaly detection critical in today’s threat landscape.
6 months ago
Kill Chain
Cox Enterprises Data Breach 2024: Oracle Zero-Day Exploit Compromises Sensitive Data
In June 2024, Cox Enterprises disclosed a significant data breach where attackers exploited a zero-day vulnerability in Oracle E-Business Suite to gain unauthorized access to the company’s network. The exploitation enabled the threat actors to bypass existing security controls, potentially exfiltrating sensitive personal data of customers and employees. The breach was detected after anomalous network activity was flagged, prompting a forensic investigation and subsequent notification to affected individuals. The incident underscores the ongoing risks associated with unpatched enterprise software and the increasing sophistication of threat actors in targeting supply-chain and business applications. This breach is particularly relevant amid a surge in zero-day exploits targeting enterprise management platforms, highlighting the urgency for robust vulnerability management, continuous monitoring, and rapid incident response. Organizations must reassess their exposure to similar risks due to heightened regulatory scrutiny and the evolving tactics used by cybercriminals.
6 months ago
Kill Chain
LINE Messaging Bugs Expose Millions to Asian Cyber Espionage in 2024
In June 2024, security researchers disclosed several critical vulnerabilities in the LINE messaging app, widely used across Asia, arising from its use of a proprietary and flawed cryptographic protocol. The bugs enable attackers to intercept and replay message traffic, impersonate users, and siphon sensitive chat data, despite the app's claims of end-to-end encryption. No specific threat actor has been confirmed, but the flaws create opportunities for state-sponsored espionage and criminal data compromise. The weaknesses persist in both in-app and network-level communication, putting millions of users’ private conversations at risk. This incident highlights the dangers of custom security implementations and is of urgent concern given LINE’s importance in business and personal use across Asia. With attackers increasingly targeting messaging platforms and governments ramping up regulatory scrutiny around privacy and secure communications, organizations must prioritize rigorous security architecture and compliance.
6 months ago
Kill Chain
Scattered Spider Strikes: 2024 Transport for London Cyber Breach
In August 2024, Transport for London (TfL), the body responsible for the UK's capital city transit system, suffered a major cyber incident allegedly orchestrated by members of the Scattered Spider cybercriminal group. Attackers exploited weaknesses in TfL's digital infrastructure to gain unauthorized access, compromising sensitive customer data and disrupting critical services. The breach, which resulted in millions of pounds in damages and regulatory scrutiny, underscored the growing threat that organized cybercriminal gangs pose to public-sector organizations. Two British teenagers have since been arrested and charged, though they have pleaded not guilty in court. This incident highlights the increasing trend of skilled threat actors leveraging sophisticated tactics—such as social engineering and lateral movement—to target essential services. Heightened regulatory pressure and public concern reinforce the urgent need for robust cybersecurity measures across critical infrastructure sectors.
6 months ago
Kill Chain
APT24’s BADAUDIO: Multi-Year Espionage Hits Taiwan and 1,000+ Domains
In late 2025, a Chinese state-linked threat actor identified as APT24 orchestrated a protracted cyber espionage campaign targeting over 1,000 organizations across Taiwan and neighboring regions. Utilizing a newly discovered malware strain dubbed BADAUDIO, APT24 gained undetected remote access by exploiting vulnerabilities in key infrastructure and moving laterally within networks, leveraging encrypted east-west and outbound traffic. The threat actors pivoted from broad web compromises to highly targeted tactics, establishing persistent footholds and exfiltrating sensitive data over nearly three years. The incident underscored the advanced methods and patience employed by APT groups against critical sectors. This campaign highlights a growing trend toward sustained, stealthy cyber operations by nation-state actors, using modular malware and cloud-oriented infrastructure to evade traditional security tools. The breach is prompting urgent reviews of segmentation, traffic encryption, and real-time detection capabilities across industries facing heightened geopolitical cyber risk.
6 months ago
Kill Chain
PlushDaemon Leverages Router Update Supply Chain in 2024 Chinese APT Attack
In 2024, a sophisticated Chinese state-sponsored group, tracked as PlushDaemon, exploited a unique supply chain tactic by compromising router firmware to hijack software update processes. These attackers covertly inserted malicious code into router updates, allowing them to intercept and manipulate network communications and deploy persistent malware within organizational networks—most notably targeting Chinese entities. Their approach leveraged trusted update channels, evading traditional detection methods and enabling infiltration with minimal immediate disruption, causing operational risk and potential data exposure on a wide scale. This technique underscores a growing trend of software supply chain attacks, where trusted network or infrastructure elements become the entry point for espionage or cyber sabotage. Organizations face mounting pressure to secure update mechanisms as attackers increasingly target foundational controls rather than endpoint devices.
6 months ago
Kill Chain
NSO Group Faces 2024 Injunction Over WhatsApp Targeting—Legal and Compliance Impacts Revealed
In early 2024, NSO Group—the Israeli surveillance technology vendor behind Pegasus spyware—faced a permanent injunction from a U.S. federal court barring it from targeting WhatsApp with its tools. The injunction, part of a high-profile legal battle stemming from NSO's alleged exploitation of WhatsApp vulnerabilities to surveil users, forces NSO to halt, destroy, or refrain from deploying code that interacts with the messaging platform. NSO's defense highlights the existential threat to their business as they appeal, arguing that this could irreparably harm the company and restrict potential U.S. government usage of Pegasus for authorized investigations. This case underscores ongoing global debates around the regulation of commercial spyware, lawful intercept technologies, and privacy rights. With increased legislative and compliance scrutiny, and rising governmental and private sector concerns about surveillance abuse, the outcome may set significant legal and operational precedents for the global spyware ecosystem.
6 months ago
Kill Chain
Google Uncovers BadAudio Malware in Chinese APT24 Espionage Campaign
In early 2024, Google’s Threat Analysis Group uncovered a sophisticated, years-long cyber espionage campaign orchestrated by the China-linked APT24 threat group. The attackers leveraged a newly discovered malware dubbed BadAudio to infiltrate government agencies, research institutions, and select private organizations. Initial access was obtained via spear-phishing campaigns, progressing to persistent lateral movement within compromised environments. BadAudio’s deployment enabled covert data exfiltration over encrypted channels, evading standard security controls and providing unmatched visibility and persistence for the attackers. The incident highlights the advanced tradecraft and evolving toolsets in use by nation-state threat actors, with business impacts centered on the loss of sensitive data and the undermining of critical organizational trust. The exposure of BadAudio signals a notable escalation in cyber espionage tactics, utilizing bespoke malware and encrypted traffic to circumvent modern defenses. Organizations across sectors are at risk as threat groups adopt similar methods, prompting increased scrutiny from regulators and heightened awareness around securing east-west traffic and anomaly detection.
6 months ago
Kill Chain
ThreatsDay 2025: Multi-Vector Attacks Redefine the Global Breach Landscape
In November 2025, a coordinated wave of multi-vector cyberattacks swept across organizations worldwide, leveraging zero-day exploits, LinkedIn spear-phishing, cryptocurrency theft, and vulnerabilities in IoT devices. Attackers exploited both east-west and egress traffic to evade detection, compromise sensitive data in transit, and establish persistent remote access. Prominent threat groups utilized unencrypted and encrypted traffic, weaponized browser extensions, and abused legitimate remote monitoring tools like AnyDesk. The result was disruption to business operations, regulatory investigations, and an uptick in ransomware and crypto-related financial crimes traced to state-sponsored and criminal actors. This incident underscores the escalating risk posed by attackers who blend diverse TTPs across cloud, hybrid, and enterprise networks. The convergence of espionage motives, cybercrime, and advanced ransomware strains highlights the need for real-time visibility, layered segmentation, and updated anomaly detection strategies.
6 months ago
Kill Chain
China-Backed PlushDaemon APT Leverages Network Devices for Advanced MitM Attacks (2024)
In 2024, ESET researchers uncovered a sustained campaign by the China-linked PlushDaemon APT that targeted edge and network devices in government, telecommunications, and technology sectors, enabling advanced adversary-in-the-middle (AitM) attacks. PlushDaemon deployed a sophisticated network implant capable of intercepting, modifying, and redirecting encrypted and unencrypted traffic, allowing the threat actor to facilitate credential theft and covert surveillance. The operation exploited weak segmentation and insufficient east-west controls, compromising business operations and exposing sensitive communications to persistent espionage. This incident is particularly relevant as APTs increasingly leverage traffic interception at the network device layer, bypassing traditional endpoint security and highlighting urgent gaps in zero trust, segmentation, and encrypted traffic monitoring solutions.
6 months ago
Kill Chain
WhatsApp 'Eternidade' Trojan Self-Propagates Across Brazil
In early 2024, a sophisticated infostealer campaign dubbed 'Eternidade' began targeting Brazilian Portuguese–speaking WhatsApp users. The attackers distributed a trojan combining phishing, credential theft, and worm-like self-propagation via compromised WhatsApp messages. Victims were lured with messages containing malicious links; once infected, devices exposed sensitive banking credentials and personal data to attackers. The malware leveraged localized tactics and social engineering to increase infection rates and circumvent traditional perimeter defenses, leading to widespread compromise across individual users and organizations reliant on WhatsApp for communication. The rapid spread, data loss, and potential for further extortion amplified business and consumer risks. This breach signals the growing sophistication of infostealer operations, especially their ability to exploit trusted communication apps in regionally tailored attacks. The incident raises alarm over encrypted-messaging-based malware and highlights gaps in endpoint and messaging security as threat actors increasingly weaponize social communication platforms.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports