The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
APT28's 2025 SOHO Router DNS Hijacking: A Wake-Up Call for Network Security
In August 2025, the Russian state-sponsored group APT28 (also known as Forest Blizzard) initiated a large-scale cyber-espionage campaign targeting small office/home office (SOHO) routers, primarily from TP-Link and MikroTik. By exploiting known vulnerabilities, such as CVE-2023-50224, the attackers gained unauthorized access to these routers and modified their DNS settings to redirect traffic through malicious servers under their control. This allowed them to intercept and steal credentials for web and email services, including Microsoft Outlook, from over 200 organizations and 5,000 consumer devices across more than 120 countries. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/?utm_source=openai)) The campaign, which peaked in December 2025, underscores the critical need for securing network infrastructure, especially SOHO devices that may lack robust security measures. The U.S. Department of Justice, in collaboration with the FBI and international partners, conducted Operation Masquerade to disrupt this malicious network, highlighting the ongoing threat posed by state-sponsored cyber activities and the importance of proactive defense strategies. ([justice.gov](https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled?utm_source=openai))
5 months ago
Kill Chain
DISGOMOJI Malware: A New Era of Emoji-Based Cyber Attacks
In 2024, the Pakistan-based Advanced Persistent Threat (APT) group UTA0137 launched a cyber-espionage campaign targeting Indian government entities. The group deployed a sophisticated malware named DISGOMOJI, written in Golang and designed for Linux systems. DISGOMOJI uniquely utilized Discord for command-and-control (C2) communications, employing emojis to execute commands such as taking screenshots, exfiltrating files, and terminating processes. The malware was delivered via spear-phishing emails containing a ZIP archive with a Golang ELF binary. Upon execution, the binary downloaded a lure file and the DISGOMOJI payload, establishing a dedicated Discord channel for each infected system, allowing individualized interaction with each victim. This campaign underscores the evolving tactics of state-sponsored threat actors in leveraging unconventional methods to evade detection and maintain persistent access to targeted systems. The use of emojis in C2 communications highlights a broader trend of adversaries adopting more visual and adaptive forms of interaction to obfuscate their activities and complicate monitoring efforts.
5 months ago
Kill Chain
EngageLab SDK Vulnerability: A Wake-Up Call for Android Developers
In April 2025, a critical intent redirection vulnerability was discovered in the EngageLab SDK, a widely used third-party Android library for managing messaging and push notifications. This flaw allowed malicious applications to exploit the SDK's exported activity, MTCommonActivity, to gain unauthorized access to private data by bypassing Android's security mechanisms. The vulnerability affected numerous applications, including cryptocurrency wallets, with over 30 million installations, exposing sensitive user information to potential risk. EngageLab addressed the issue by releasing version 5.2.1 on November 3, 2025, which set the vulnerable activity to non-exported, mitigating the risk. This incident underscores the significant security implications of vulnerabilities in third-party SDKs, especially in high-value sectors like digital asset management. It highlights the necessity for developers to rigorously review and monitor third-party components integrated into their applications to prevent similar security breaches.
5 months ago
Kill Chain
Unveiling the 2023-2024 Hack-for-Hire Campaign Targeting Journalists in MENA
Between 2023 and 2024, a sophisticated hack-for-hire campaign targeted journalists and activists in the Middle East and North Africa, notably in Egypt and Lebanon. The attackers employed spear-phishing techniques, sending messages that appeared to be from legitimate sources to deceive victims into revealing personal data, including credentials and financial information. This campaign has been linked to the Bitter APT group, known for targeting government and critical infrastructure sectors across South Asia. The operation underscores the persistent threat posed by state-sponsored cyber espionage groups utilizing advanced social engineering tactics to infiltrate and compromise sensitive information. ([accessnow.org](https://www.accessnow.org/press-release/hack-for-hire-new-report-egyptian-journalists/?utm_source=openai))
5 months ago
Kill Chain
APT28's PRISMEX Malware Campaign: A 2026 Cyber-Espionage Threat
In early 2026, the Russian state-sponsored group APT28 (also known as Fancy Bear and Pawn Storm) initiated a sophisticated cyber-espionage campaign targeting Ukraine and its NATO allies. The operation employed a newly developed malware suite named PRISMEX, which utilizes advanced steganography, Component Object Model (COM) hijacking, and the exploitation of legitimate cloud services for command-and-control (C2) communications. The campaign began in September 2025 and intensified in January 2026, focusing on sectors such as defense, emergency services, and logistics across multiple countries, including Poland, Romania, Slovenia, Turkey, Slovakia, and the Czech Republic. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai)) This campaign underscores the rapid weaponization of newly disclosed vulnerabilities by APT28, notably CVE-2026-21509 and CVE-2026-21513, to infiltrate target systems. The use of PRISMEX highlights a strategic shift towards more covert and resilient attack methodologies, posing significant challenges for detection and mitigation. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai))
5 months ago
Kill Chain
Masjesu Botnet: A New Era of DDoS-for-Hire Targeting IoT Devices
In April 2026, cybersecurity researchers identified 'Masjesu,' a sophisticated botnet operating as a DDoS-for-hire service. Masjesu has been active since 2023, primarily targeting a wide array of IoT devices, including routers and gateways, across multiple architectures. The botnet employs advanced evasion techniques, such as randomizing packet headers and payloads, to mimic legitimate traffic and avoid detection. It propagates by exploiting known vulnerabilities in devices from manufacturers like D-Link, GPON, and Netgear, and by brute-forcing weak or default passwords. Masjesu's operators advertise their services via Telegram, offering clients the ability to launch large-scale DDoS attacks on demand. ([trellix.com](https://www.trellix.com/blogs/research/masjesu-rising-stealth-iot-botnet-ddos-evasion/?utm_source=openai)) The emergence of Masjesu underscores the escalating threat posed by IoT-based botnets. With the proliferation of unsecured IoT devices, attackers can easily amass vast networks capable of launching devastating DDoS attacks. This trend highlights the urgent need for enhanced security measures, including regular firmware updates, strong password policies, and network monitoring, to protect against such evolving threats.
5 months ago
Kill Chain
GrafanaGhost: Unveiling the AI Vulnerability Exposing Enterprise Data
In April 2026, a critical vulnerability named 'GrafanaGhost' was discovered in Grafana's AI components, allowing attackers to exfiltrate sensitive enterprise data through indirect prompt injection. By embedding malicious instructions within external web content, attackers could manipulate Grafana's AI to process these prompts as legitimate, leading to unauthorized data exposure without user interaction. This flaw was promptly patched by Grafana following responsible disclosure. The GrafanaGhost incident underscores the growing risks associated with integrating AI into enterprise systems. It highlights the necessity for robust security measures to prevent AI-specific vulnerabilities, as attackers increasingly exploit such weaknesses to access sensitive information.
5 months ago
Kill Chain
Latin American Banks Confront 155% Surge in Social Engineering Scams in 2025
In 2025, Latin American financial institutions experienced a 155% increase in social engineering scams, with fraud attempts utilizing remote-access tools surging fivefold and malware attacks rising by 225%. This escalation underscores a shift in fraudsters' tactics, moving from basic phishing to sophisticated methods that exploit human behavior and technological vulnerabilities. The surge in fraud cases highlights the urgent need for enhanced security measures and collaborative efforts among financial institutions to combat evolving threats.
5 months ago
Kill Chain
Anthropic's Project Glasswing: Revolutionizing Cybersecurity with AI
In April 2026, Anthropic launched Project Glasswing, a collaborative initiative with major technology companies including Amazon, Apple, Microsoft, and Cisco, to enhance cybersecurity defenses using advanced AI. Central to this project is Claude Mythos Preview, an unreleased AI model that has identified thousands of previously undetected vulnerabilities across critical software systems, including a 27-year-old bug in OpenBSD and a 16-year-old flaw in FFmpeg. To mitigate potential misuse, Anthropic has restricted access to this powerful model to select partners and has committed significant resources to support open-source security organizations. ([anthropic.com](https://www.anthropic.com/project/glasswing?utm_source=openai)) This initiative underscores the growing importance of AI in cybersecurity, highlighting both its potential to fortify defenses and the risks associated with its misuse. As AI capabilities advance, the industry faces the dual challenge of leveraging these tools for protection while preventing their exploitation by malicious actors. ([cyberscoop.com](https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnerabilities/?utm_source=openai))
5 months ago
Kill Chain
Forest Blizzard 2026: Unveiling and Neutralizing a Global Espionage Threat
In early 2026, the Russian state-sponsored group Forest Blizzard (APT28) compromised over 18,000 routers across 120 countries, exploiting known vulnerabilities in TP-Link and MikroTik devices. By hijacking DNS settings, they conducted adversary-in-the-middle attacks, intercepting credentials and tokens for services like Microsoft Outlook Web Access. This extensive espionage campaign targeted more than 200 organizations, including government agencies and critical infrastructure sectors. A collaborative effort led by the FBI, known as Operation Masquerade, successfully neutralized the threat by resetting DNS settings and preventing further exploitation. This incident underscores the persistent threat posed by state-sponsored cyber actors and highlights the critical need for robust network security measures. Organizations must remain vigilant, regularly update and patch network devices, and implement comprehensive monitoring to detect and mitigate such sophisticated attacks.
5 months ago
Kill Chain
FrostArmada: Unveiling APT28's DNS Hijacking Tactics Targeting Microsoft 365
In April 2026, an international law enforcement operation, in collaboration with private companies, successfully disrupted 'FrostArmada,' a cyber espionage campaign orchestrated by the Russian state-sponsored group APT28 (also known as Fancy Bear or Forest Blizzard). The campaign involved compromising small office/home office (SOHO) routers, primarily from MikroTik and TP-Link, to alter DNS settings and redirect traffic through attacker-controlled servers. This allowed APT28 to intercept authentication traffic and steal Microsoft 365 credentials and OAuth tokens. At its peak in December 2025, FrostArmada infected 18,000 devices across 120 countries, targeting government agencies, law enforcement, IT and hosting providers, and organizations operating their own servers. The operation to neutralize the malicious infrastructure was supported by Microsoft, Lumen's Black Lotus Labs, the FBI, the U.S. Department of Justice, and the Polish government. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/authorities-disrupt-dns-hijacks-used-to-steal-microsoft-365-logins/?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored threat actors in exploiting network infrastructure vulnerabilities to conduct large-scale credential theft. The use of DNS hijacking via compromised routers highlights the need for organizations to secure network devices, implement robust monitoring, and adopt zero-trust principles to mitigate such sophisticated attacks.
5 months ago
Kill Chain
Storm-1175's Rapid Exploitation of Zero-Days Leads to Medusa Ransomware Attacks
In early April 2026, the China-based cybercriminal group Storm-1175 executed a series of high-velocity attacks targeting vulnerable internet-facing systems across sectors such as healthcare, education, professional services, and finance in Australia, the United Kingdom, and the United States. By exploiting a combination of zero-day and N-day vulnerabilities, including CVE-2025-10035 in Fortra's GoAnywhere MFT and CVE-2026-23760 in SmarterMail, the group rapidly gained initial access. Post-compromise activities involved deploying web shells, creating new user accounts, and utilizing remote monitoring and management tools like SimpleHelp and MeshAgent for persistence and lateral movement. Within as little as 24 hours, Storm-1175 exfiltrated data and deployed Medusa ransomware, leading to significant operational disruptions for the affected organizations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the increasing sophistication and speed of financially motivated threat actors in exploiting newly disclosed vulnerabilities. The rapid transition from initial access to ransomware deployment highlights the critical need for organizations to promptly apply security patches, monitor for unauthorized activities, and implement robust incident response strategies to mitigate such high-tempo cyber threats.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports