The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Cisco Firewall DoS Attack: How CVE-2025-20333 & CVE-2025-20362 Disrupted Critical Networks
In November 2025, Cisco disclosed a vulnerability exploitation campaign targeting its Secure Firewall ASA and Threat Defense (FTD) devices. Threat actors actively weaponized two zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, to force vulnerable appliances to unexpectedly reload, resulting in denial-of-service (DoS) conditions that disrupted network operations. Affected organizations saw service disruptions, increased operational risk, and potential visibility gaps, especially where patch management or segmentation was lacking. Cisco responded by recommending immediate updates, enhanced monitoring, and deployment of compensating security controls until all devices are patched. This incident underscores a continuing trend of attackers rapidly exploiting unpatched firewall vulnerabilities, threatening the network perimeter’s reliability. The rise in sophisticated DoS tactics against infrastructure devices points to an urgent need for proactive patching, segmentation, and visibility into both perimeter and east-west traffic.
8 months ago
Kill Chain
Cloudflare Top Domain Rankings Compromised by Aisuru Botnet in 2025
In October 2025, Cloudflare faced an unprecedented attack by the Aisuru botnet, a rapidly scaling network of compromised IoT devices. The botnet leveraged its vast fleet to overwhelm Cloudflare's public DNS resolver (1.1.1.1) with massive volumes of automated queries, propelling its malicious command-and-control domains to the top ranks of Cloudflare's most-queried website list. This manipulation triggered widespread concern over data integrity and brand confusion, as Aisuru domains temporarily displaced legitimate top domains like Google and Apple. In response, Cloudflare resorted to redacting and eventually removing suspicious domains from its ranking list, highlighting significant security gaps in popular trust datasets. This incident underscores the mounting risk posed by large IoT botnets to critical internet infrastructure, including DNS reliability and reputation-based services. It reveals how attackers exploit both technical and social trust mechanisms, with potential downstream effects on security decisions that leverage third-party domain rankings.
8 months ago
Kill Chain
Bronze Butler Exploits Zero-Day to Breach Japanese Enterprise Networks
In early 2025, Chinese state-sponsored APT group 'Bronze Butler' exploited a zero-day vulnerability (CVE-2025-61932) in a widely used endpoint management platform to penetrate several Japanese organizations. The attackers gained privileged access by leveraging the flaw for initial compromise, then established persistence and moved laterally across victims’ networks. Exfiltrated data included sensitive business documents and internal communications. The coordinated campaign went undetected for weeks, resulting in significant operational disruption and exposure of confidential assets, raising alarms about cyber-espionage threats facing Japan’s critical industries. This breach highlights the intensifying use of zero-day vulnerabilities by advanced threat actors for targeting supply chain software and trusted management tools. Similar recent attacks signal a broader trend of sophisticated, nation-state-driven intrusions against key sectors in Asia, and reinforce the urgent need for proactive patch management and stronger east-west network segmentation.
8 months ago
Kill Chain
Kimsuky Unleashes HTTPTroy Backdoor in Targeted Attack on South Korea
In early 2024, the North Korean state-sponsored group Kimsuky launched a targeted cyberespionage campaign using a new backdoor called HTTPTroy, aimed at South Korean users. Leveraging sophisticated obfuscation and advanced anti-analysis features, Kimsuky distributed the malware primarily via phishing emails containing malicious attachments. Once installed, HTTPTroy enabled the attackers to execute commands remotely and exfiltrate sensitive data while evading detection. The campaign underscores the increasing technical capabilities of North Korean APT groups and their persistent focus on South Korean government, critical infrastructure, and research sectors. This incident highlights an accelerating trend of advanced persistent threats deploying stealthy, resilient malware to bypass traditional defenses. As attackers evolve their toolchains, organizations—especially in frequently targeted regions—face heightened risk from espionage operations that blend social engineering, evasion tactics, and custom malware.
8 months ago
Kill Chain
Inside the 2025 Cybercrime Merger: Scattered Spider, LAPSUS$, and ShinyHunters Unite
In August 2025, a powerful new cybercrime collective emerged from the merger of Scattered Spider, LAPSUS$, and ShinyHunters—three of the most notorious threat groups involved in high-profile data theft, ransomware, and extortion. This unified entity quickly established 16 Telegram channels to coordinate attacks, evade platform moderation, and amplify operations. Leveraging advanced social engineering and data exfiltration techniques, the collective launched a string of multinational breaches targeting enterprises, exposing sensitive information and causing significant financial and reputational harm to victims. Security teams observed an uptick in lateral movement, exploitation of hybrid/cloud environments, and sophisticated policy evasion tied to these actors. This incident exemplifies a growing trend where cybercriminal syndicates combine resources and expertise, accelerating the pace and scale of attacks. The merger highlights the urgent need for organizations to adapt to evolving threat actor alliances and reinforces the importance of advanced segmentation, zero trust, and robust monitoring frameworks.
8 months ago
Kill Chain
IDIS ICM Viewer 2025: Critical Application Vulnerability Risk Exposed
In November 2025, IDIS disclosed a critical vulnerability (CVE-2025-12556) in its ICM Viewer application, enabling remote attackers to execute arbitrary code via improper neutralization of argument delimiters—a classic argument injection flaw. The vulnerability, scored CVSS v4 8.7, affected version 1.6.0.10 and allowed exploitation through low-complexity attacks requiring only limited privileges. The flaw could provide adversaries with broad control over vulnerable systems, directly impacting critical communications infrastructure deployed worldwide and potentially undermining operational continuity and data integrity. This incident highlights the growing risk posed by supply chain and application-layer vulnerabilities in industrial and communications networks. The prevalence of remote, low-complexity exploits underscores the urgent need for robust patch management and defense-in-depth approaches, especially as regulators intensify scrutiny of critical infrastructure cybersecurity.
8 months ago
Kill Chain
Android BankBot-YNRK: 2024 Indonesian Mobile Wallets Targeted by Muting Malware
In 2024, a variant of the Android/BankBot malware known as YNRK targeted mobile users in Indonesia by disguising itself as legitimate applications, often distributed via third-party app stores or phishing campaigns. Once installed, the malware muted system alerts and abused accessibility services to perform unauthorized actions, including theft of credentials and the draining of cryptocurrency and mobile banking wallets. The attack leveraged overlays to capture user inputs and bypassed security mechanisms, resulting in significant financial losses for affected users, with widespread impacts across consumer mobile banking apps in the country. This incident highlights the ongoing evolution and sophistication of mobile banking malware, which increasingly targets emerging markets and exploits weak security controls on non-official app stores. The rapid adoption of mobile wallets and cryptocurrency platforms has made these attacks more lucrative and frequent, intensifying the need for proactive mobile security, user awareness, and regulatory oversight.
8 months ago
Kill Chain
North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies
In 2023, multiple Western technology firms fell victim to a sophisticated insider threat campaign involving North Korean operatives posing as freelance IT job seekers. These actors used false identities and forged CVs to secure remote employment and gain access to sensitive corporate environments. Once inside, they leveraged their positions to siphon proprietary information, commit financial fraud, and, in some cases, facilitate broader cyber-espionage activities by collecting credentials and mapping internal systems. The impact spanned financial loss, reputation damage, and increased exposure to supply chain attacks. This incident highlights the growing trend of well-resourced nation-state actors exploiting remote work arrangements and third-party talent networks. As companies aggressively scale digital transformation and outsourcing, vigilance against social engineering and identity fraud is critical to mitigate the risk of covert infiltration and regulatory non-compliance.
8 months ago
Kill Chain
Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security
In November 2025, security researchers from Google Project Zero disclosed a significant design flaw in the Linux kernel’s implementation of Kernel Address Space Layout Randomization (KASLR) on modern Android devices, specifically Google Pixel phones. The weakness stems from the lack of randomization in both the linear kernel mapping and the physical memory loading address of the kernel itself. As a result, attackers with an arbitrary read/write primitive could derive static kernel virtual addresses, bypassing KASLR protections without leaks—thereby making exploitation significantly easier and increasing the risk of privilege escalation and persistence. This incident underscores a broader industry challenge where operating system mitigations lag behind evolving attacker techniques. The exposure of predictable kernel virtual addresses on widely deployed Android devices highlights the urgency for stronger kernel randomization and renewed attention to memory safety for mobile platforms.
8 months ago
Kill Chain
Kimsuky Deploys HttpTroy Backdoor in Sophisticated VPN-Phishing Attack Against South Korea
In late 2025, the North Korean advanced persistent threat (APT) group Kimsuky launched a targeted cyberattack against an organization in South Korea using a previously undocumented backdoor dubbed 'HttpTroy.' Leveraging a spear-phishing email containing a malicious ZIP file disguised as a VPN invoice, the attackers tricked the recipient into extracting and running a disguised executable. Once executed, HttpTroy enabled encrypted communication with attacker-controlled infrastructure, allowing remote data exfiltration and persistent access. This covert operation underscored the group's ongoing focus on espionage, intelligence collection, and the use of custom malware to evade detection. This incident is significant due to the rise of spear-phishing attacks deploying novel backdoors and the persistence of state-sponsored threats targeting geopolitical rivals. It highlights the necessity for vigilant endpoint monitoring, advanced traffic analysis, and robust segmentation to limit attacker lateral movement and safeguard sensitive communications.
8 months ago
Kill Chain
Lazarus Group Orchestrates Major 2025 Web3 Multi-Vector Breach
In November 2025, the Lazarus Group executed a sophisticated multi-vector attack campaign targeting several high-profile Web3 and cryptocurrency organizations. Utilizing social engineering and supply-chain attacks, the threat actors exploited newly disclosed vulnerabilities in trusted hardware (including Intel and AMD TEEs) mere hours after public disclosures. Attackers employed encrypted C2 channels, lateral movement tools, and advanced ransomware, allowing them to bypass internal segmentation and traverse east-west across internal networks. The result was significant compromise of sensitive assets, encrypted backups, and leakage of confidential data, leading to operational disruption and reputational harm to victims. This incident is especially noteworthy due to the rapid attacker adaptation to zero-day vulnerabilities, the blending of traditional and cloud-native threat techniques, and Lazarus’s evolution in targeting decentralized platforms. The attack highlights the increasing complexity and urgency of defending distributed infrastructure against agile, persistent threat actors.
8 months ago
Kill Chain
BankBot-YNRK and DeliveryRAT: Sophisticated Android Trojans Targeting Financial Data
In November 2025, cybersecurity researchers discovered the active deployment of two advanced Android trojans, BankBot-YNRK and DeliveryRAT, targeting users across multiple financial and delivery service platforms. The trojans infiltrated devices primarily through deceptive apps and phishing schemes, with BankBot-YNRK leveraging anti-analysis techniques to evade detection by testing for emulated and virtualized environments before unleashing its data theft capabilities. DeliveryRAT, meanwhile, provided attackers with remote access for layered exploitation. Both malware families are capable of harvesting sensitive personal and financial data, making banking credentials and payment details accessible to threat actors, potentially leading to significant financial losses and privacy violations for affected users and organizations. This incident highlights the evolving sophistication of Android-targeted infostealers, which increasingly combine stealth, anti-analysis, and remote access tactics. The attack underscores the urgent need for organizations and end-users to enhance mobile threat defenses and rapidly adapt to emerging malware targeting the growing mobile financial ecosystem.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports