✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Fake Inflation Refund Phishing Texts Target New Yorkers in 2025 Smishing Attack
In October 2025, a coordinated smishing campaign targeted New York State residents with fraudulent text messages purporting to be from the Department of Taxation and Finance. The attackers claimed recipients were eligible for an 'Inflation Refund' and directed them to a phishing site impersonating an official state portal, where victims were prompted to submit sensitive personal data—name, address, email, phone number, and Social Security Number—under the guise of processing their refund. This malicious operation seeks to steal identities and facilitate extensive financial fraud. Government officials swiftly issued warnings, clarifying that legitimate refunds required no action from residents and urging vigilance. This incident is a stark reminder of the increasing sophistication of SMS phishing (smishing) attacks, which blend timely government programs with social engineering techniques. The campaign highlights the persistent risk posed by identity-centric attacks, especially as digital fraudsters exploit widespread economic uncertainty and official-sounding initiatives.
6 months ago
Kill Chain
Russian ClayRat Android Spyware Masquerades as Popular Apps, Spreads Rapidly in 2024
In mid-2024, security researchers at Zimperium discovered ClayRat, a rapidly evolving Android spyware campaign targeting users in Russia. Disguised as trusted apps like TikTok and YouTube, ClayRat was spread via phishing websites and Telegram channels, infecting over 600 devices in just three months. Once installed, the spyware leverages Android’s SMS handler permissions to bypass typical security prompts, allowing attackers to covertly access messages, call logs, device information, and even remotely control infected phones. The highly orchestrated campaign abused social engineering, web deception, and obfuscation techniques to remain undetected, and can turn each compromised device into a new attack vector. The threat’s evolution signals rising global risks, as the campaign’s tactics can easily adapt to new payloads and regions. With increasing use of mobile malware, organizations globally should reassess mobile security controls and user awareness programs to defend against sophisticated, evasive spyware attacks exploiting trust in well-known apps.
6 months ago
Kill Chain
Aisuru Botnet’s Record DDoS Assaults Expose IoT Weaknesses in US ISPs
In October 2025, the Aisuru botnet orchestrated the largest recorded distributed denial-of-service (DDoS) attacks to date, leveraging over 300,000 compromised IoT devices primarily hosted on major U.S. ISPs such as AT&T, Comcast, and Verizon. The botnet, evolved from Mirai code, exploited insecure or outdated IoT firmware, driving attack volumes to nearly 30 terabits per second. Recurrent DDoS waves severely disrupted online gaming infrastructure and collateral users, overwhelming both DDoS mitigation providers and ISPs, and causing service dropouts and customer impact across multiple networks. This incident exemplifies the rising scale and sophistication of IoT-based botnets and exposes urgent deficiencies in outbound DDoS filtering at the ISP level. The Aisuru event also highlights a growing threat trend: attackers using compromised consumer IoT to reinforce both DDoS infrastructure and residential proxy networks, broadening attacker capabilities and the attack surface for businesses and critical providers.
6 months ago
Kill Chain
RondoDox Botnet Orchestrates Mass n-day IoT Attacks in 2025
In mid-2025, the RondoDox botnet emerged as a powerful threat targeting IoT and network devices by exploiting 56 known (n-day) vulnerabilities across over 30 device types, including routers, NVRs, DVRs, and CCTV systems. The operators, closely monitoring vulnerability disclosures—such as those revealed at Pwn2Own events—rapidly weaponized publicly disclosed exploits, including CVE-2023-1389 and CVE-2024-12856, using a high-volume "exploit shotgun" methodology to maximize infections. With operations observed since June 2025, the campaign affected both end-of-life and actively supported products, resulting in a widespread compromise of infrastructure, particularly among organizations and consumers with unpatched devices. This attack underscores a growing trend of mass exploitation of n-day vulnerabilities in IoT ecosystems, reflecting increasing automation and sophistication among botnet operators. The pace at which attackers operationalize new exploits demands faster patching, improved segmentation, and heightened baseline security practices across networked environments.
6 months ago
Kill Chain
ClayRat Android Spyware: Fake App Campaign Hits Mobile Users in 2025
In October 2025, cybersecurity researchers at Zimperium disclosed a widespread Android spyware campaign dubbed ClayRat, which targeted Russian users through phishing portals, Telegram channels, and malicious websites mimicking popular apps such as WhatsApp, TikTok, YouTube, and Google Photos. Using fraudulent Play Store-like websites and social engineering tactics, attackers tricked users into sideloading APKs that installed malicious payloads via a session-based installation method, bypassing Android security. Once installed, ClayRat acts as the device's default SMS handler, enabling interception of messages, call logs, notifications, and exfiltration of sensitive data to an AES-GCM-encrypted command and control (C2) server. It also uses infected devices to propagate itself by sending mass SMS messages to victims' contacts. This incident underscores an accelerating trend in mobile spyware leveraging legitimate app impersonation and sophisticated delivery mechanisms. The high volume of ClayRat samples and droppers, the abuse of sideloading, and the global reach of Telegram-based distribution channels highlight persistent gaps in mobile endpoint and social engineering defenses.
6 months ago
Kill Chain
FreePBX VoIP Vulnerability Exploited: CVE-2025-57819 Enables Code Execution
In August 2025, a critical SQL injection vulnerability (CVE-2025-57819) was disclosed in FreePBX, a popular open-source VoIP telephony platform. The flaw, found in the system's web-based admin interface, allowed unauthenticated attackers to inject malicious SQL queries via a vulnerable 'brand' parameter, enabling arbitrary modification of the backend database. Attackers have already been observed using this vulnerability to gain remote code execution by inserting persistent cron jobs that continuously recreate a web shell on the target server, providing full access for data exfiltration or fraudulent activities. Organizations using unpatched versions may be exposed to call fraud, impersonation, lateral movement, or further compromise of VoIP infrastructure. This breach highlights a persistent trend of attackers exploiting critical web application vulnerabilities shortly after public disclosure, underscoring the importance of proactive patching and real-time threat detection. It also illustrates attackers’ growing focus on embedded and telecom systems as entry points for broader enterprise compromise.
6 months ago
Kill Chain
EU Chat Control Law Threatens Privacy and Encryption in 2024
In 2024, the European Union considered sweeping legislation called Chat Control, aimed at mandating providers of end-to-end encrypted messaging apps to implement client-side scanning of user content for illegal material, notably child sexual abuse material (CSAM). Major privacy advocates and technology leaders, including Signal's CEO, highlighted that such a regulation would undermine privacy by requiring access to sensitive content before encryption. Technical experts warned that creating lawful access inherently weakens the entire encrypted ecosystem, exposing all users—including journalists, activists, and vulnerable groups—to potential surveillance or exploitation, and might force some encrypted messaging services to exit the EU market entirely. This proposed law has sparked an urgent debate on digital privacy, as its adoption could set a global precedent for government-mandated encryption backdoors. The current climate of rising concerns over lawful and extrajudicial surveillance, combined with persistent cyber threats, amplifies the pertinence and risks associated with such regulatory initiatives.
6 months ago
Kill Chain
Self-Propagating Malware Targets WhatsApp Users in Brazil with Financial Fraud Infostealer
In early June 2024, an infostealer campaign dubbed Water Saci aggressively targeted WhatsApp users in Brazil using self-propagating malware named Sorvepotel. Attackers leveraged compromised accounts to automatically distribute malicious links via WhatsApp messages, luring recipients to execute malware payloads. Once installed, Sorvepotel exfiltrates credentials and tracks browser activities, enabling threat actors to target and defraud regional financial institutions. The infection chain’s ability to rapidly spread through trusted social contacts increased both the velocity and scale of impact, compromising both individual and enterprise devices in a short time frame. The Water Saci operation highlights the evolution of credential-stealing malware adopting worm-like features to maximize reach. With messaging platforms remaining core to business and personal communications, this incident underscores the urgency of intercepting lateral movement, especially as attackers blend social engineering with advanced propagation and data theft techniques.
6 months ago
Kill Chain
Signal Launches SPQR: A Quantum-Safe Encryption Upgrade for 2025
In October 2025, Signal introduced a major upgrade to its encryption suite by deploying the Sparse Post-Quantum Ratchet (SPQR), designed to secure user communications against present and future quantum computing threats. Developed in collaboration with leading academic and industry partners, SPQR brings a 'triple ratchet' protocol leveraging hybrid cryptography based on both traditional and quantum-resistant key exchange mechanisms. This system provides continual key rotation, forward secrecy, and robust post-compromise security, ensuring that even if current keys are compromised, future messages remain protected. The rollout will be gradual and backward-compatible, affecting Signal’s 100 million global users without requiring manual intervention. The launch of SPQR is a landmark response to the rise of quantum computing, which threatens conventional encryption schemes. Its introduction reflects mounting industry urgency to adopt advanced cryptographic standards and maintain trust in privacy-critical communications platforms amid rapid shifts in the threat landscape.
6 months ago
Kill Chain
SORVEPOTEL: New WhatsApp-Driven Malware Campaign Hits Brazil
In late 2025, cybersecurity researchers identified a rapid outbreak of a self-spreading malware targeting Brazilian Windows users through WhatsApp, labeled SORVEPOTEL and tracked as the Water Saci campaign. The malware leverages the inherent trust and widespread popularity of WhatsApp by delivering malicious payloads via chat messages, which entice users to download infected files. Once inside a system, SORVEPOTEL propagates by messaging victims’ contacts, enabling swift lateral movement and widespread distribution. Notably, the campaign appears engineered for rapid proliferation rather than for data theft or ransomware deployment, showcasing evolving malware propagation tactics. This incident highlights the increasing sophistication and speed of messaging app-based malware and reflects a broader trend of social engineering campaigns capitalizing on trusted digital platforms. Organizations should re-examine endpoint protections and user awareness in light of emerging threats exploiting popular communications channels.
6 months ago
Kill Chain
UAT-8099 Hijacks IIS Servers: SEO Fraud and Data Theft Exposed
In early 2024, the Chinese-language cybercrime group UAT-8099 orchestrated a sophisticated series of attacks targeting Internet Information Services (IIS) web servers belonging to reputable organizations worldwide, including technology firms, telecoms, and universities. Exploiting insecure internet-facing servers with weak file upload controls, the attackers established footholds using open source web shells. They escalated privileges, enabled remote access with OSS reverse proxy tools, and deployed 'BadIIS' implants to perform SEO poisoning, redirecting search engine traffic to fraudulent gambling and scam sites. Simultaneously, the threat actors exfiltrated credentials, configuration files, and certificates, setting the stage for future attacks or data sales on darknet markets. This campaign demonstrates the threat actor's multi-pronged approach, blending fraud and espionage in ways that evade immediate detection. The incident highlights a growing global trend where SEO manipulation and credential theft converge, exposing organizations to operational, reputational, and regulatory risks amidst rising regulatory scrutiny around digital trust and supply chain integrity.
6 months ago
Kill Chain
Android Spyware Masquerades as Messaging Apps in UAE: ESET Uncovers 2024 Mobile Threats
In June 2024, ESET researchers uncovered two Android spyware campaigns—ProSpy and ToSpy—masquerading as popular messaging apps Signal and ToTok, specifically targeting residents in the United Arab Emirates. The malware was distributed via third-party websites impersonating legitimate app stores, such as the Samsung Galaxy Store, and required users to manually install them. Upon installation, the spyware requested extensive permissions, gaining access to contacts, messages, stored files, audio, images, and more, enabling extensive data exfiltration. The campaigns utilized regional delivery tactics to focus on UAE users, exploiting trusted local app brands. These findings highlight a persistent threat trend: attackers disguising malware as legitimate communication apps to bypass official channels and exploit regional trust. With increased scrutiny on privacy and secure messaging, such campaigns pose heightened operational and compliance risks for organizations and individuals alike, underscoring the urgent need for enhanced mobile security measures and user awareness.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports