The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
2024 Mega Email Stealer Log Breach: Over 2 Billion Accounts Exposed
In early June 2024, a large-scale data breach involving the exposure of over 2 billion email addresses was discovered in a massive stealer log dataset. Attackers compiled these emails through widespread info-stealer malware campaigns, collecting credentials and sensitive data from compromised systems and aggregating them into searchable logs accessible on illicit forums. The breach, prepared for public release after extensive validation and costly processing, highlights the sheer scale and complexity of modern info-theft operations. Affected users may face targeted phishing, credential stuffing attacks, and long-term privacy risks due to the availability of this data. This breach exemplifies the accelerating trend of industrialized data theft and commoditization of stolen information, especially as info-stealer malware campaigns proliferate and cybercriminals refine monetization methods. Organizations should be on heightened alert for downstream risks, including targeted attacks leveraging exposed data and regulatory scrutiny of data protection practices.
8 months ago
Kill Chain
Nation-State Actors Infiltrate Ribbon Communications: 2024’s Latest APT Assault on US Telecom
In December 2023, Ribbon Communications, a major US telecommunications provider, suffered a cyber intrusion attributed to suspected nation-state actors. Attackers gained unauthorized access to parts of the company’s internal network, leveraging advanced persistent threat (APT) techniques to bypass existing security controls and maintain sustained access over several months. Although Ribbon discovered the breach and contained it by early 2024, the company has not confirmed whether sensitive customer or operational data was exfiltrated. The incident has raised concerns about the vulnerability of critical telecom infrastructure to espionage and cyber-enabled disruption. This breach exemplifies the escalating cyber risk telecoms face from organized, highly sophisticated attackers targeting supply chains and core communications platforms. With the telecommunications sector increasingly in the crosshairs of state-sponsored actors, the event spotlights the urgent need for zero trust, segmentation, and advanced detection controls.
8 months ago
Kill Chain
Australia Warns: BadCandy Infects Unpatched Cisco IOS XE Devices in 2024
In June 2024, Australian cybersecurity authorities issued urgent warnings regarding ongoing cyberattacks targeting unpatched Cisco IOS XE devices across the country. Threat actors exploited known vulnerabilities to install the BadCandy webshell, enabling persistent, covert access to network infrastructure. Once a device was compromised, attackers leveraged the foothold for lateral movement, unauthorized surveillance, and potentially for command-and-control activities, putting government entities, businesses, and ISPs at risk. The infections are widespread and ongoing due to delayed patching and lack of robust segmentation. This incident highlights an increasing trend of sophisticated exploitation of edge network devices, demonstrating attackers’ focus on device-level vulnerabilities and lateral movement methods. The urgency is heightened by the scale and automation of attacks and the continued use of vulnerable systems.
8 months ago
Kill Chain
Airstalk Malware: 2025 Nation-State Supply Chain Attack Hits Mobile Device Ecosystems
In October 2025, a suspected nation-state threat actor, tracked as CL-STA-1009, orchestrated a sophisticated supply chain attack involving the novel 'Airstalk' malware. Investigations by Palo Alto Networks Unit 42 revealed that Airstalk exploited the AirWatch mobile device management (MDM) API to gain unauthorized access to victim organizations' internal networks. This enabled adversaries to compromise large numbers of mobile devices, bypass network controls, and pivot laterally within affected systems, causing operational disruption and data loss. The primary targets were organizations with complex supply chains, where the attackers injected malicious code via trusted software providers, highlighting the vulnerabilities inherent in interconnected IT ecosystems. This incident is especially relevant as supply chain attacks become increasingly prevalent, with attackers leveraging trusted third-party relationships to bypass traditional network defenses. Nation-state actors' use of advanced evasion techniques and MDM abuse underscores the need for enhanced visibility, segmentation, and threat detection across distributed and hybrid IT environments.
8 months ago
Kill Chain
Multi-Vector Attacks Surge: DNS Poisoning, Supply-Chain Compromise, and Rust Malware in 2025
In October 2025, a major multi-vector cyberattack was uncovered leveraging DNS poisoning, a sophisticated software supply-chain compromise, and the deployment of a new strain of Rust-based malware capable of evading traditional detection mechanisms. The attackers exploited vulnerabilities in third-party supplier code to infiltrate enterprise networks, enabling lateral movement via compromised DNS servers. Shortly thereafter, remote access trojans (RATs) and other post-exploitation tools were deployed, resulting in significant data exfiltration and disruption across multiple sectors. Incident response teams collaborated internationally to isolate affected systems and assess the operational damage. This event highlights a tightening attacker focus on high-value targets and critical infrastructure, driven by advances in malware tooling, zero-day exploitation, and the mainstream use of modern programming languages like Rust for stealthy payloads. The breach exemplifies how defenders must adapt to increasingly layered threats that combine classic attack vectors with contemporary tactics.
8 months ago
Kill Chain
Critical 2025 Raisecomm Authentication Bypass: Root Access Risk to ICS Networks
In October 2025, a critical remote authentication bypass vulnerability (CVE-2025-11534) was publicly disclosed in Raisecomm RAX701-GC series network equipment, allowing unauthenticated attackers to establish SSH sessions and gain root shell access without providing valid credentials. Discovered and reported by security researchers from runZero, this exploit poses an elevated risk to infrastructure sectors relying on these devices globally, as affected firmware versions remain susceptible with exploits achievable at low complexity and no prior privileges. Business and operational impacts include full remote compromise, lateral movement potential, and the ability for attackers to implant persistent threats or disrupt essential communications and IT operations. The incident is especially pressing now, indicating a rising trend in targeting embedded and edge devices in critical environments via misconfigurations or software flaws. As attackers expand their focus to accessible infrastructure, organizations face increasing pressure to implement robust access controls, proactive segmentation, and defense-in-depth strategies to safeguard operational networks.
8 months ago
Kill Chain
Hitachi Energy TropOS ICS Flaws Threaten Critical Infrastructure Security (2025)
In October 2025, Hitachi Energy disclosed multiple critical vulnerabilities in its TropOS 4th Generation firmware (versions 8.9.6.0 and prior), widely used in critical manufacturing and energy sectors. Three CVEs—CVE-2025-1036, CVE-2025-1037, and CVE-2025-1038—were identified, including OS command injection and improper privilege management flaws in the web-based configuration utility. Exploiting these, authenticated attackers could escalate privileges and obtain root SSH access to affected devices, substantially compromising network security and potentially disrupting critical infrastructure operations. The flaws were reported by Idaho National Laboratory’s CyTRICS program and carry CVSS v4 scores between 7.5 and 8.7. This incident highlights ongoing risks posed by authentication and privilege flaws in industrial control systems (ICS), especially as critical infrastructure devices increasingly attract remote exploitation attempts. It underscores the urgent need for regular firmware updates, network segmentation, and robust access controls amid tightening regulations and persistent adversarial interest in ICS environments.
8 months ago
Kill Chain
Aisuru Botnet’s 2025 Shift: From DDoS Disruptor to Proxy Powerhouse
In mid-2025, the Aisuru botnet—already infamous for record-shattering distributed denial-of-service (DDoS) attacks—shifted tactics, repurposing hundreds of thousands of compromised Internet of Things (IoT) devices to fuel residential proxy networks. Initially detected in August 2024, Aisuru rapidly infected over 700,000 vulnerable routers and cameras, enabling DDoS attacks reaching up to 30 terabits per second. As global internet providers struggled to mitigate these waves, Aisuru’s operators began renting bot-infected devices as residential proxies, granting cybercriminals more effective means to anonymize web scraping, credential stuffing, and data harvesting operations. This incident marks a significant escalation in how botnets are monetized, as botnet-powered residential proxies become a key enabler for content scraping—especially by AI firms seeking vast datasets. The pivot highlights a rising convergence between traditional cybercrime and emerging AI-driven abuse, challenging defenders to address both volumetric attack trends and subtle, persistent data exfiltration.
8 months ago
Kill Chain
AI-Powered Social Engineering Attacks Surge Across Africa in 2024
In early 2024, a surge of AI-powered social engineering attacks swept across Africa, targeting both government agencies and private enterprises. Threat actors utilized AI-generated phishing campaigns, deepfake technology, and sophisticated impersonation tactics to gain unauthorized access to sensitive systems and data. The attackers rapidly evolved their techniques by testing them in diverse African markets, often bypassing conventional security controls using realistic AI-driven lures and voice/video spoofing. The outcome included data breaches, operational interruptions, increased fraud, and reputational harm to affected organizations, while also exposing gaps in detection and response capabilities. This incident highlights the accelerating adoption of AI by cybercriminals, who now leverage machine learning to refine attack vectors and increase success rates. As similar TTPs proliferate globally, organizations face heightened regulatory scrutiny and must rapidly adapt cybersecurity frameworks to counter increasingly intelligent and deceptive threats.
8 months ago
Kill Chain
F5's 2024 Nation-State Breach: Lessons in Supply Chain and Platform Security
In late 2023, F5 Networks experienced a prolonged attack attributed to a nation-state threat actor who gained persistent access to internal systems, stealing segments of BIG-IP source code, undisclosed vulnerabilities, and customer configuration data. The company became aware of the intrusion on August 9, with public disclosure on October 15 following a rare emergency directive from federal authorities. F5 coordinated with security firms and mobilized rapid emergency software and hardware updates across thousands of customer deployments while investigating the breach’s full scope. The identified impact included widespread emergency patching and a limited set of customers affected by stolen configuration data, though F5 reported that most exfiltrated information was not sensitive. This incident underscores ongoing targeting of technology and security vendors by advanced persistent threat actors. With the steady increase in supply chain attacks, the F5 breach highlights the need for stronger product code security, rapid response to vulnerability disclosure, and cross-industry collaboration against sophisticated intrusions.
8 months ago
Kill Chain
Herodotus Trojan Outsmarts Android Defenses with Human-Like Behavior
In October 2025, cybersecurity researchers uncovered a new Android banking trojan, dubbed Herodotus, actively targeting financial institutions and users in Italy and Brazil. The malware stands out by performing sophisticated device takeover (DTO) attacks while mimicking genuine human behavior—specifically attempting to bypass behavioral biometrics and anti-fraud detection. Herodotus infects devices via malicious apps or phishing, granting attackers near-complete control, which they use to exfiltrate sensitive financial and authentication data by simulating legitimate user interaction. The Herodotus incident underscores a troubling advancement in mobile malware—attackers are increasingly leveraging techniques that closely imitate human behavior to elude cutting-edge security controls. This signals a growing risk for banking apps and enterprises relying on behavioral biometrics, and highlights the urgent need for multilayered zero trust strategies and improved east-west visibility in mobile ecosystems.
8 months ago
Kill Chain
LockBit 5.0 Resurgence: How WSUS and F5 Vulnerabilities Fueled 2025's Biggest Ransomware Wave
In October 2025, a coordinated wave of cyberattacks struck major enterprise environments worldwide. Attackers exploited Windows Server Update Services (WSUS) flaws and vulnerabilities in F5 infrastructure, deploying the new LockBit 5.0 ransomware variant. Using phishing, unauthorized RDP access, and advanced persistence techniques, LockBit affiliates moved laterally across networks, encrypting critical data and disrupting cloud-hosted workloads. Compromised systems experienced operational downtime, data theft, and subsequent ransom demands, while threat actor activity on underground forums confirmed an aggressive resurgence and evolving TTPs. This incident underscores the heightened pace and sophistication of ransomware operations, with threat actors exploiting both zero-day vulnerabilities and supply chain channels. As enterprise defenses adapt to increasingly hybrid and distributed infrastructure, recent attacks have spotlighted urgent needs for segmentation, real-time visibility, and policy enforcement to counter proactive adversary tactics.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports