The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
GreyVibe Hackers Leverage AI in 2025 Cyberattacks
In August 2025, the Russian-linked threat group GreyVibe initiated a cyberespionage campaign targeting Ukrainian military, government, civilian, and business sectors. Utilizing AI tools like ChatGPT and Google Gemini, they crafted sophisticated lures and developed custom malware, including LegionRelay and PhantomRelay, to infiltrate systems and exfiltrate sensitive data. Their tactics encompassed spear-phishing emails, fake CAPTCHA pages, and counterfeit websites, leading to significant data breaches and operational disruptions. This incident underscores the escalating use of AI in cyberattacks, enabling threat actors to enhance the scale and sophistication of their operations. Organizations must adapt by implementing advanced security measures and continuous monitoring to counteract these evolving threats.
3 months ago
Kill Chain
BTMOB RAT: A New Android Malware-as-a-Service Threat
In May 2026, cybersecurity researchers identified BTMOB, an Android Remote Access Trojan (RAT), actively targeting users in Brazil and Latin America. Distributed through phishing campaigns that mimic legitimate services, BTMOB is sold as a malware-as-a-service (MaaS), allowing attackers to create malicious apps without coding expertise. Once installed, it exploits Android's Accessibility Services to gain elevated permissions, enabling data exfiltration, screen capture, and full remote control of infected devices. This comprehensive access poses significant risks, including financial theft and privacy breaches. The emergence of BTMOB underscores a growing trend in the commoditization of sophisticated malware, lowering the barrier for cybercriminals and expanding the threat landscape. Its MaaS model facilitates rapid adaptation and distribution, making it a formidable challenge for cybersecurity defenses worldwide.
3 months ago
Kill Chain
Grandoreiro and BTMOB Malware Campaigns: A 2026 Cybersecurity Threat
In May 2026, cybersecurity firms WatchGuard and ESET identified two sophisticated banking trojan campaigns targeting Windows and Android users in Latin America and Europe. The Grandoreiro malware, active since 2016, employs DLL side-loading techniques to infiltrate Windows systems, primarily targeting financial institutions in Portugal. Concurrently, the BTMOB remote access trojan (RAT) compromises Android devices, enabling attackers to exfiltrate sensitive data and gain remote control. These campaigns utilize phishing emails and deceptive websites to distribute malicious payloads, posing significant threats to both individual users and organizations. The persistence and evolution of these malware families underscore the adaptability of financially motivated threat actors. By leveraging legitimate services and employing advanced evasion techniques, such as WebRTC communications and anti-analysis checks, these campaigns highlight the increasing complexity of modern cyber threats and the necessity for robust, multi-layered security defenses.
4 months ago
Kill Chain
Cybercriminals Exploit Government Data in Latin America: The 2026 Antel Breach
In May 2026, the cybercriminal group La Pampa Leaks claimed to have breached Uruguay's government-sponsored identity service, TuID, managed by the state-owned telecommunications company Antel. The attackers alleged prolonged access to the platform's infrastructure, potentially exposing sensitive personal data of Uruguayan citizens, including identification numbers, full names, birth dates, email addresses, phone numbers, residential addresses, biometric information, and digital signature data. Antel confirmed the cyberattack but stated that authentication credentials and highly sensitive data remained uncompromised. Immediate containment measures were implemented, and the incident was reported to the relevant authorities. This incident underscores a growing trend in Latin America, where cybercriminals increasingly target government agencies to monetize citizen data. The public-administration sector in the region has become the most-breached industry in the past year, highlighting the urgent need for enhanced cybersecurity measures and regulatory compliance to protect sensitive information.
4 months ago
Kill Chain
BTMOB Android RAT: Unveiling a Stealthy Mobile Threat
In early 2025, the BTMOB Android Remote Access Trojan (RAT) emerged as a significant cybersecurity threat, evolving from the SpySolr malware. Unlike traditional banking trojans, BTMOB offers adversaries extensive capabilities, including data exfiltration, screenshot capture, activity recording, and full remote control of infected devices. Distributed primarily through phishing campaigns that mimic legitimate services, victims are lured into downloading malicious APKs from fake app stores. Once installed, BTMOB exploits Android's Accessibility Services to gain elevated permissions, enabling it to operate stealthily and grant attackers comprehensive access to the device. The malware's commercialization through a no-code APK builder interface lowers the barrier for cybercriminals, allowing rapid generation of new payloads and tailored phishing lures without coding expertise. This ease of customization and distribution has led to its proliferation beyond initial detections in Brazil, posing a global threat to Android users. ([welivesecurity.com](https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/?utm_source=openai))
4 months ago
Kill Chain
Charter Communications Data Breach: A 2026 Case Study
In April 2026, Charter Communications, a leading U.S. telecommunications provider, experienced a data breach orchestrated by the cyber extortion group ShinyHunters. The attackers employed a voice phishing (vishing) technique to compromise an employee's Microsoft Entra account, subsequently accessing the company's Salesforce system. This breach led to the exfiltration of approximately 40 million customer records, encompassing names, email addresses, physical addresses, phone numbers, and plan details. Charter has stated that no sensitive personal information or customer proprietary network information was compromised. This incident underscores a growing trend of cybercriminals leveraging social engineering tactics, such as vishing, to infiltrate organizations. The increasing sophistication of these methods highlights the critical need for enhanced employee training and robust security protocols to mitigate the risk of similar breaches.
4 months ago
Kill Chain
Dutch Authorities Dismantle Cyberattack Infrastructure Linked to Russian Operations
In May 2026, Dutch authorities arrested two individuals, aged 57 and 39, for allegedly providing IT infrastructure used by Russian entities to conduct cyberattacks and disinformation campaigns within the European Union. The arrests followed investigations into Stark Industries Solutions, a hosting provider sanctioned by the EU in 2025 for facilitating Russian cyber operations. The suspects, associated with MIRhosting and WorkTitans BV, were charged with violating sanctions laws by making economic resources available to sanctioned entities. During the operation, over 800 servers were seized from data centers in Dronten and Schiphol-Rijk. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/?utm_source=openai)) This incident underscores the persistent challenges in enforcing sanctions against entities that support state-sponsored cyber activities. Despite previous sanctions, the rebranding and asset transfers by Stark Industries highlight the adaptability of such organizations in evading regulatory measures. The case emphasizes the need for continuous monitoring and robust enforcement mechanisms to prevent the circumvention of international sanctions.
4 months ago
Kill Chain
ShinyHunters Ransomware Attack on Charter Communications - May 2026
In May 2026, the cybercriminal group ShinyHunters executed a ransomware attack against Charter Communications, Inc., a major U.S. telecommunications and cable company known for its Spectrum services. The attack involved unauthorized access to Charter's systems, leading to the encryption of critical data and disruption of services. ShinyHunters demanded a ransom for the decryption keys, threatening to leak sensitive customer and corporate information if their demands were not met. The breach was publicly disclosed on May 23, 2026, highlighting significant vulnerabilities in Charter's cybersecurity defenses. This incident underscores the escalating threat posed by sophisticated ransomware groups like ShinyHunters, who have been increasingly targeting large corporations across various sectors. The attack on Charter Communications serves as a stark reminder of the importance of robust cybersecurity measures and the need for organizations to proactively defend against evolving cyber threats.
4 months ago
Kill Chain
Authorities Arrest KimWolf Botnet Operator in 2026
In May 2026, U.S. and Canadian authorities arrested Jacob Butler, a 23-year-old Canadian national known online as "Dort," for operating the KimWolf botnet. This botnet infected nearly two million devices worldwide, including digital photo frames, web cameras, and Android-based TV boxes. Butler allegedly sold access to this network through a DDoS-for-hire service, facilitating over 25,000 attacks that reached up to 30 terabits per second, causing financial losses exceeding $1 million for some victims. The KimWolf botnet was also linked to attacks targeting Department of Defense Information Network IP addresses. ([justice.gov](https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos?utm_source=openai)) The arrest underscores the escalating threat posed by large-scale botnets exploiting Internet of Things (IoT) devices. The KimWolf botnet's rapid expansion and its use in record-breaking DDoS attacks highlight the need for enhanced security measures and international cooperation to combat cybercrime. ([techradar.com](https://www.techradar.com/pro/security/a-massive-new-ddos-botnet-has-already-snared-1-8-million-devices-heres-what-we-know?utm_source=openai))
4 months ago
Kill Chain
Ubiquiti Patches Critical UniFi OS Vulnerabilities - May 2026
In May 2026, Ubiquiti released patches for three critical vulnerabilities in UniFi OS, identified as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. These flaws allowed remote attackers to make unauthorized system changes, access underlying system files, and execute command injection attacks without requiring authentication. The vulnerabilities were reported through Ubiquiti's bug bounty program and could be exploited in low-complexity attacks. At the time of disclosure, nearly 100,000 UniFi OS endpoints were exposed online, with approximately 50,000 located in the United States. This incident underscores the persistent targeting of network infrastructure by cybercriminals and state-sponsored actors. Organizations must prioritize timely patching and robust security measures to mitigate risks associated with such vulnerabilities.
4 months ago
Kill Chain
Former US Executives Admit to Aiding Tech Support Scammers
In May 2026, Adam Young and Harrison Gevirtz, former executives of C.A. Cloud Attribution, Ltd., pleaded guilty to concealing a tech support fraud scheme that operated from early 2017 to April 2022. Their company provided services to clients engaged in telemarketing and tech support scams, which involved deceptive pop-up ads and impersonation of companies like Microsoft and Apple to defraud victims worldwide. Despite knowing their clients' fraudulent activities, Young and Gevirtz failed to report them and instead facilitated their operations by advising on methods to evade detection. This case underscores the critical need for vigilance against tech support scams, which continue to exploit individuals globally. The involvement of corporate executives in such schemes highlights the importance of ethical business practices and the necessity for companies to implement robust compliance measures to prevent complicity in fraudulent activities.
4 months ago
Kill Chain
Arrest of Kimwolf Botnet Operator Highlights IoT Security Risks
In May 2026, Canadian authorities arrested Jacob Butler, known online as "Dort," for allegedly creating and operating the Kimwolf botnet. This botnet infected millions of Internet-of-Things (IoT) devices, such as digital photo frames and web cameras, to execute massive distributed denial-of-service (DDoS) attacks. Some of these attacks reached nearly 30 terabits per second, causing financial losses exceeding one million dollars for certain victims. The U.S. Department of Justice has charged Butler with aiding and abetting computer intrusion, and he faces potential extradition to the United States. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/?utm_source=openai)) The Kimwolf botnet's unprecedented scale and impact underscore the growing threat posed by IoT-based cyberattacks. This incident highlights the critical need for enhanced security measures in IoT devices and increased international cooperation to combat cybercrime effectively.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports