✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Android Spyware Campaigns Target Signal and ToTok Users in Sophisticated 2025 Attack
In June 2025, cybersecurity firm ESET uncovered targeted Android spyware campaigns, dubbed ProSpy and ToSpy, which impersonated upgrades and plugins for the popular messaging apps Signal and ToTok. Threat actors distributed malicious APK files via websites masquerading as official app sites and third-party stores, luring users primarily in the United Arab Emirates. Once installed, these spyware variants harvested sensitive data including device information, contacts, SMS, files, and backups, using sophisticated persistence mechanisms and disguising themselves as legitimate apps. Data exfiltration was conducted using encrypted channels to evade detection. This incident underscores the increasing threat of mobile malware leveraging convincing social engineering tactics and fake branding. It highlights a macro trend of attackers exploiting trust in widely used apps to infiltrate user devices, reflecting rising complexity in mobile threat landscapes and growing regulatory pressure on app distributors.
6 months ago
Kill Chain
Urgent: DrayTek Vigor Router RCE Vulnerability (CVE-2025-10547) Exposes SMB Networks
In October 2025, DrayTek disclosed a critical remote code execution vulnerability (CVE-2025-10547) impacting multiple Vigor router models, commonly used by small to medium businesses. The flaw allows unauthenticated attackers to remotely execute arbitrary code by sending specially crafted HTTP or HTTPS requests to the router's Web User Interface (WebUI). Triggered by an uninitialized stack value that facilitates arbitrary memory operations, the vulnerability could lead to full system compromise, crash, or remote takeover if exploited. DrayTek confirmed the issue following responsible disclosure and provided urgent firmware updates for affected devices. This incident exemplifies the rising risks posed by infrastructure vulnerabilities in network devices widely deployed in business environments. As attackers increasingly target edge and remote-management interfaces, proactive patch management has become paramount for organizations seeking to mitigate evolving threats and comply with stricter cybersecurity standards.
6 months ago
Kill Chain
U.A.E. Android Spyware Alert 2025: ProSpy & ToSpy Impersonate Secure Messaging Apps
In October 2025, cybersecurity researchers at ESET identified two sophisticated Android spyware campaigns, ProSpy and ToSpy, actively targeting users in the United Arab Emirates by masquerading as legitimate apps such as Signal Encryption Plugin and ToTok Pro. The spyware was disseminated through fake websites leveraging social engineering techniques, deceiving users into downloading malicious apps. Once installed, the malware secretly exfiltrated device data, tracked user communications, and introduced significant privacy and data security risks for both individuals and organizations. The campaigns indicate a growing trend of targeted mobile espionage in the region, significantly undermining user trust and operational safety. This incident underscores the escalating threat from mobile spyware distributed via convincing social engineering and fake app storefronts. As more users move critical communications to mobile platforms, adversaries are rapidly advancing their techniques, prompting urgent calls for enhanced mobile threat detection, robust user education, and strict compliance with data protection frameworks.
6 months ago
Kill Chain
Android Spyware Attack Impersonates UAE Government App in 2024
In early June 2024, security analysts uncovered a sophisticated campaign in which attackers distributed Android spyware posing as a well-known UAE government surveillance app. By leveraging convincing social engineering and impersonation tactics, the threat actors tricked users into installing malicious software capable of exfiltrating sensitive data, monitoring communications, and maintaining persistent control over compromised devices. The spyware utilized encrypted and covert exfiltration methods, giving attackers broad access to user data while evading standard detection. The incident quickly raised concerns among organizations and citizens in the region about mobile device security and privacy. This attack is part of a growing trend using brand impersonation and sophisticated spyware packaging, targeting both individuals and potentially organizations. The resurgence of mobile surveillance threats underscores the evolving risks facing users in high-risk regions and highlights the need for robust mobile device security and compliance with privacy frameworks.
6 months ago
Kill Chain
Klopatra Trojan: VNC-Powered Android Banking Attacks Sweep Europe in 2025
In March 2025, a newly identified Android trojan named Klopatra emerged, targeting over 3,000 devices across Europe by masquerading as a legitimate IPTV and VPN app. Researchers from Cleafy discovered that this banking and remote access trojan—believed to be operated by a Turkish-speaking cybercrime group—leveraged VNC-based remote control, overlay attacks, anti-analysis techniques, and Accessibility Service abuse to steal banking credentials, manipulate transactions, exfiltrate clipboard and keystroke data, and harvest cryptocurrency wallet information. The malware sidestepped Google Play protections by distributing its dropper app on unofficial websites and continuously evolving, with at least 40 builds detected since its appearance. This incident underscores the growing sophistication and adaptability of Android malware, including the deployment of advanced evasion techniques and real-time remote access capabilities. As mobile banking adoption rises globally, such attacks signal an urgent need for stronger app vetting, user awareness, and holistic endpoint security strategies in enterprise and consumer environments.
6 months ago
Kill Chain
Klopatra Android Banking Trojan Orchestrates VNC-Based Fraud in Spain and Italy
In August 2025, the Klopatra Android banking trojan was discovered by Cleafy, an Italian fraud prevention firm, after it compromised more than 3,000 smartphones—primarily in Spain and Italy. This sophisticated malware leveraged a hidden Virtual Network Computing (VNC) module that enabled threat actors to stealthily control infected devices remotely, bypassing traditional security measures and enabling real-time fraudulent activities. The attackers employed social engineering and malicious app delivery techniques to distribute the trojan, ultimately enabling the theft of sensitive banking credentials and direct manipulation of banking apps on compromised phones. The Klopatra campaign reflects the evolution of mobile threats in Europe, combining advanced remote access with banking-focused exfiltration. Its success underlines an urgent need for rigorous mobile device security as banking trojans rapidly adopt more covert control and anti-detection techniques.
6 months ago
Kill Chain
Attackers Exploit Milesight Routers to Launch European SMS Phishing Wave
In early 2025, unidentified threat actors exploited vulnerabilities in Milesight industrial cellular routers to launch a large-scale smishing campaign across Europe. By abusing the routers’ publicly exposed APIs, attackers sent malicious SMS messages containing phishing URLs directly to mobile users in countries including Sweden and Italy. This campaign has been ongoing since at least February 2022, with attackers leveraging compromised infrastructure to bypass traditional security filters, resulting in widespread delivery of credential-theft links and potential downstream attacks. This incident highlights the increasing trend of attackers targeting edge infrastructure and IoT devices to amplify their phishing and malware operations. As threat actors shift tactics toward abusing legitimate network equipment, organizations face new regulatory and operational risks, with urgent need to secure device APIs, implement segmentation, and strengthen monitoring to counter evolving smishing threats.
6 months ago
Kill Chain
Klopatra: The Stealth Android Banking Trojan Draining European Accounts Overnight
In mid-2024, the Klopatra Android banking Trojan emerged as a major threat to mobile users in Italy and Spain. Disguised as the popular but illicit Mobdro streaming app, the malware leveraged social engineering tactics to trick users into granting dangerous Accessibility permissions. Once installed, Klopatra used advanced obfuscation, anti-analysis techniques, and commercial packers to avoid detection. Attackers remotely took control of compromised devices while users slept, using stolen credentials and simulated taps to access and empty bank accounts through a series of stealthy transfers—all while remaining undetected until victims discovered their losses in the morning. The Klopatra incident underscores a rising trend in real-time, remote-controlled mobile banking fraud, combining overlays, credential theft, and session manipulation. As attackers continue targeting mobile banking, organizations and end-users must adapt defenses to evolving TTPs and maintain vigilance toward app sideloading.
6 months ago
Kill Chain
China APT Launches Fileless, Precision Attack in 2024: Lateral Movement and Cloud Risk
In early 2024, an advanced persistent threat (APT) group dubbed 'Phantom Taurus,' believed to be affiliated with China, executed a sophisticated cyberattack targeting large enterprises in the finance and technology sectors. The attackers leveraged an in-memory, fileless backdoor ('IIServerCore') on Microsoft Windows servers to evade traditional detection, exploiting east-west traffic within cloud and hybrid environments. Initial access was likely gained through phishing and exploitation of public-facing applications, enabling lateral movement and persistent foothold. Impact included disruption of business operations, potential data exfiltration, and internal system compromise, with detection hampered by the backdoor's stealth techniques and encrypted command and control channels. This incident underscores an increasing trend of nation-state actors employing fileless malware and leveraging deep Windows system knowledge to bypass endpoint and network defenses. The use of advanced lateral movement tactics and persistent, in-memory attack tools highlights ongoing gaps in east-west cloud visibility and the urgency for zero trust segmentation across enterprise environments.
6 months ago
Kill Chain
TOTOLINK X6000R Routers: 2025 Vulnerabilities Uncovered in Edge Devices
In June 2025, three new critical vulnerabilities (CVE-2025-52905, CVE-2025-52906, CVE-2025-52907) were discovered in TOTOLINK X6000R routers by Palo Alto Networks' Unit 42 researchers. These flaws exposed the devices to remote code execution and unauthorized access, potentially allowing attackers to gain persistent control over affected networks. The vulnerabilities stem from insecure input validation, weak authentication mechanics, and flaws in firmware that could be exploited over the internet. Immediate patching and network segmentation were recommended to prevent exploitation while vendor mitigation efforts commenced. This incident highlights ongoing risks to consumer and small business gateway devices, demonstrating how router vulnerabilities remain a rich attack surface for cyber actors. The event underscores the urgency for continuous vulnerability research, robust patch management, and defense-in-depth to counter the accelerating trend of targeting edge and IoT devices.
6 months ago
Kill Chain
Phantom Taurus: China-Linked Espionage Group Infiltrates Diplomatic Targets with Undetected Malware
In early 2024, Palo Alto Networks' Unit 42 uncovered a newly confirmed China-linked espionage group, dubbed Phantom Taurus, employing advanced stealth techniques and novel malware to infiltrate nearly a dozen high-value targets in the Middle East, Africa, and Asia. The group relied on exploiting unpatched, internet-facing devices to gain initial access before deploying a custom malware suite designed for in-memory execution and deep evasion, allowing them to establish persistent access and exfiltrate sensitive diplomatic and governmental data over periods stretching up to two years. While Phantom Taurus shares some infrastructure traits with other Chinese threat actors, its custom tooling, extended operational security, and unique tactics distinguish it from other known groups, and it remains active with recent campaigns expanding to new regions. This incident highlights an escalation in the sophistication and reach of nation-state cyber espionage. The emergence of Phantom Taurus signals a growing trend of attackers prioritizing stealth and long-term intelligence gathering, making it more difficult for organizations to detect and respond to breaches within high-value sectors.
6 months ago
Kill Chain
Phantom Taurus: Stealth China-Linked APT Breaches Global Governments in 2025
Between early 2023 and mid-2025, government and telecommunications agencies spanning Africa, the Middle East, and Asia became the targets of a previously undocumented China-linked nation-state threat group, dubbed Phantom Taurus. The group leveraged stealthy, custom malware and encrypted command-and-control channels to infiltrate ministries of foreign affairs, embassies, and military operations, maintaining persistent access to sensitive networks for extended periods. Attackers employed advanced lateral movement and living-off-the-land techniques, hindering detection and enabling covert intelligence collection. Exfiltrated data included diplomatic communications and potentially classified material, posing severe geopolitical and operational risks to the affected organizations. This incident underscores a rising trend of sophisticated China-aligned APT campaigns exploiting stealth malware, encrypted traffic, and advanced cloud evasion to breach strategic targets. As state-sponsored espionage continues to escalate, organizations must strengthen zero trust controls, real-time traffic inspection, and segmented multicloud defenses to counter evolving nation-state tactics.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports