The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
TrickMo's Evolution: Leveraging TON for Enhanced Stealth in Banking Malware
In early 2026, a new variant of the TrickMo Android banking trojan emerged, leveraging The Open Network (TON) for command-and-control (C2) communications. This variant, observed by ThreatFabric between January and February 2026, actively targeted banking and cryptocurrency wallet users in France, Italy, and Austria. By utilizing TON's decentralized infrastructure, the malware effectively evaded traditional domain takedown efforts, complicating mitigation strategies. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/trickmo-c-ton-network-android/?utm_source=openai)) The adoption of TON for C2 communications signifies a broader trend among threat actors toward decentralized platforms to enhance stealth and resilience. This evolution underscores the need for security teams to adapt detection and response strategies to address threats that exploit decentralized networks. ([securityaffairs.com](https://securityaffairs.com/192003/malware/android-banking-trojan-trickmo-evolves-using-ton-network-for-c2.html?utm_source=openai))
4 months ago
Kill Chain
TrickMo Android Banker Leverages TON Blockchain for Covert Operations
In May 2026, a new variant of the TrickMo Android banking malware emerged, targeting users in France, Italy, and Austria. Disguised as popular apps like TikTok and streaming services, this malware employs The Open Network (TON) blockchain for covert command-and-control communications, enhancing its stealth and resilience. TrickMo's capabilities include intercepting one-time passwords (OTPs), recording screens, exfiltrating data, and executing overlay attacks to steal banking credentials. The malware's use of TON's decentralized infrastructure complicates detection and mitigation efforts. This incident underscores a growing trend of cybercriminals leveraging decentralized technologies to evade traditional security measures. The adoption of blockchain for malicious communications highlights the need for advanced detection strategies and reinforces the importance of user vigilance against social engineering tactics.
4 months ago
Kill Chain
cPanel CVE-2026-41940 Exploited to Deploy Filemanager Backdoor
In May 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was discovered in cPanel and WebHost Manager (WHM) software, allowing unauthenticated remote attackers to gain administrative access to affected systems. Exploiting this flaw, a threat actor known as Mr_Rot13 deployed a backdoor named Filemanager, enabling unauthorized control over compromised environments. The attack involved injecting malicious code to create unauthorized sessions, leading to potential data theft, malware deployment, and system compromise. ([support.cpanel.net](https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cyber actors targeting widely used web hosting platforms. The rapid exploitation of CVE-2026-41940 highlights the critical need for organizations to promptly apply security patches and implement robust monitoring to detect and mitigate unauthorized access attempts.
4 months ago
Kill Chain
Critical 'Dirty Frag' Zero-Day Exposes Major Linux Distributions to Root Exploits
In May 2026, security researcher Hyunwoo Kim disclosed a critical Linux zero-day vulnerability named 'Dirty Frag.' This exploit allows local attackers to gain root privileges on major Linux distributions, including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, AlmaLinux, openSUSE Tumbleweed, and Fedora. The vulnerability chains two kernel flaws—the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write—to modify protected system files in memory without authorization, leading to privilege escalation. Notably, 'Dirty Frag' is a deterministic logic bug that does not depend on race conditions, ensuring a high success rate for attackers. The disclosure of 'Dirty Frag' follows closely on the heels of the 'Copy Fail' vulnerability (CVE-2026-31431), highlighting a concerning trend of critical Linux kernel flaws being exploited in the wild. The rapid succession of these vulnerabilities underscores the urgent need for organizations to prioritize timely patching and robust security measures to protect their systems from potential exploits.
4 months ago
Kill Chain
NVIDIA GeForce NOW Data Breach in Armenia: What You Need to Know
In early May 2026, NVIDIA confirmed a data breach affecting its GeForce NOW service in Armenia, managed by regional partner GFN.am. The breach, occurring between March 20 and 26, exposed user data including full names, email addresses, phone numbers, dates of birth, and usernames. NVIDIA's own infrastructure remained unaffected, and GFN.am has initiated notifications to impacted users. The threat actor, identified as ShinyHunters, claimed responsibility and attempted to sell the stolen data online. This incident underscores the persistent threat posed by cybercriminal groups like ShinyHunters, known for targeting high-profile organizations. It highlights the critical need for robust security measures and vigilant monitoring of third-party partnerships to safeguard user data against sophisticated cyberattacks.
4 months ago
Kill Chain
TCLBANKER: A New Threat to Financial Platforms via WhatsApp and Outlook
In May 2026, Elastic Security Labs identified a new Brazilian banking trojan named TCLBANKER, which targets 59 banking, fintech, and cryptocurrency platforms. The malware is distributed through a trojanized Logitech installer and employs advanced anti-analysis techniques. Once installed, TCLBANKER monitors browser activity and overlays fraudulent interfaces to steal user credentials. Additionally, it propagates via WhatsApp and Outlook by sending malicious links to the victim's contacts, facilitating further infections. This incident underscores the evolving sophistication of banking trojans, particularly in their use of legitimate applications for distribution and self-propagation through popular communication platforms. Organizations must enhance their security measures to detect such advanced threats and educate users on recognizing and avoiding malicious links.
4 months ago
Kill Chain
CallPhantom Scam: Unveiling the Deception of Fake Call History Apps
In May 2026, cybersecurity researchers uncovered a fraudulent campaign involving 28 Android applications, collectively known as 'CallPhantom,' on the Google Play Store. These apps falsely claimed to provide access to call histories, SMS records, and WhatsApp call logs for any phone number. Users were prompted to pay subscription fees, ranging from €5 to $80, only to receive randomly generated data instead of the promised information. The apps amassed over 7.3 million downloads before being removed from the store. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-callphantom-scam-google-play/?utm_source=openai)) This incident highlights the persistent threat of deceptive applications infiltrating official app stores, exploiting user trust, and causing financial harm. It underscores the necessity for continuous vigilance, robust app vetting processes, and user education to mitigate the risks associated with such fraudulent schemes.
4 months ago
Kill Chain
Critical 'Dirty Frag' Vulnerability in Linux Kernel Grants Root Access
A critical local privilege escalation (LPE) vulnerability, dubbed 'Dirty Frag,' has been identified in the Linux kernel, affecting major distributions such as Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16. This flaw allows unprivileged local users to gain root access by exploiting a logic error in the kernel's cryptographic module. The vulnerability has been actively exploited in the wild, with a publicly available proof-of-concept demonstrating its reliability across affected systems. Immediate patching is essential to mitigate the risk of unauthorized system control. The disclosure of 'Dirty Frag' underscores the persistent challenges in securing widely used open-source software. Organizations must prioritize timely updates and consider implementing additional security measures, such as disabling vulnerable modules or restricting access, to protect against potential exploits targeting this and similar vulnerabilities.
4 months ago
Kill Chain
Dirty Frag: Unpatched Linux Vulnerability Grants Root Access
On May 7, 2026, a critical Linux kernel vulnerability known as 'Dirty Frag' was publicly disclosed. This flaw allows unprivileged local users to escalate their privileges to root across major Linux distributions, including Ubuntu, RHEL, Fedora, and others. Discovered by security researcher Hyunwoo Kim, Dirty Frag exploits two distinct vulnerabilities within the IPsec ESP and RxRPC modules, enabling attackers to modify read-only files in the page cache, leading to full system compromise. The premature disclosure occurred before patches were available, leaving systems vulnerable without immediate remediation options. The urgency of addressing Dirty Frag is heightened by its similarity to the recently disclosed 'Copy Fail' vulnerability (CVE-2026-31431), which also facilitates local privilege escalation. The public availability of exploit code for both vulnerabilities increases the risk of widespread exploitation. Organizations must prioritize mitigating these vulnerabilities to prevent potential system compromises and data breaches.
4 months ago
Kill Chain
CallPhantom Scam: Deceptive Android Apps Exploit User Curiosity
In November 2025, ESET researchers identified a series of fraudulent Android applications, collectively named 'CallPhantom,' on the Google Play Store. These 28 apps falsely claimed to provide access to call logs, SMS records, and WhatsApp call histories for any phone number. Users were prompted to pay for these services but received only randomly generated, fabricated data. The apps amassed over 7.3 million downloads before being reported to Google and subsequently removed from the store. This incident underscores the persistent threat of deceptive applications exploiting user curiosity and trust. The CallPhantom scam highlights the need for continuous vigilance against fraudulent apps, especially as cybercriminals increasingly target mobile platforms. Users should be cautious of apps requesting payments for services that seem too good to be true and verify the legitimacy of applications before installation.
4 months ago
Kill Chain
TCLBanker: The Self-Spreading Banking Trojan Threatening Financial Security
In May 2026, a sophisticated banking trojan named TCLBanker emerged, targeting 59 banking, fintech, and cryptocurrency platforms primarily in Brazil. The malware infiltrates systems through a trojanized MSI installer for Logitech AI Prompt Builder, employing DLL side-loading to evade detection. Once installed, TCLBanker monitors browser activity, activating when users access targeted financial websites. It establishes a WebSocket connection to its command-and-control server, enabling attackers to perform live screen streaming, keylogging, clipboard hijacking, and remote command execution. Additionally, TCLBanker features self-propagating worm modules that exploit WhatsApp and Outlook to spread the malware to the victim's contacts, significantly increasing its reach and impact. The emergence of TCLBanker underscores a concerning evolution in banking malware, combining advanced evasion techniques with self-propagation capabilities. This development highlights the urgent need for enhanced cybersecurity measures, particularly in the financial sector, to counteract increasingly sophisticated threats that can rapidly disseminate through trusted communication channels.
4 months ago
Kill Chain
Exploitation of PAN-OS Captive Portal Zero-Day (CVE-2026-0300) for Unauthenticated Remote Code Execution
On May 6, 2026, Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow vulnerability in the User-ID™ Authentication Portal (Captive Portal) service of PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Limited exploitation has been observed, with attackers deploying tools like EarthWorm and ReverseSocks5, conducting Active Directory enumeration, and systematically erasing logs to conceal their activities. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=openai)) This incident underscores the escalating trend of state-sponsored actors targeting edge-network devices to gain privileged access. The use of publicly available tools and meticulous operational tactics highlights the need for organizations to secure their network perimeters and implement robust monitoring to detect and mitigate such sophisticated threats. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=openai))
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports