The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
BGP Hijacking Enables Virtualizor Supply Chain Compromise
In late August 2026, attackers executed a sophisticated supply chain attack against Virtualizor, a popular virtualization management platform, by hijacking Border Gateway Protocol (BGP) routes to redirect software update traffic. The attack occurred between August 28-30, 2026, when threat actors diverted Softaculous traffic to attacker-controlled servers and delivered malicious Virtualizor updates that established persistent root access on affected systems. At least 5 of 34 hypervisors at one hosting provider were compromised, with attackers installing backdoors, creating unauthorized accounts, and maintaining persistence through systemd services. This incident highlights the growing sophistication of supply chain attacks targeting critical infrastructure management software. As organizations increasingly rely on automated software updates and third-party platforms for cloud operations, attackers are exploiting trust relationships and network-level vulnerabilities to achieve widespread compromise with minimal detection.
3 weeks ago
Kill Chain
Leaked Russian Documents Expose Systematic Cyber Warfare Training Pipeline
In September 2026, leaked training materials from Russia's Bauman Moscow State Technical University exposed the institutional framework behind Russian state-sponsored cyber operations. The documents revealed Department No. 4's role as a pipeline for recruiting students into GRU units including Sandworm (Military Unit 74455) and APT28, showing formalized pathways from university recruitment to military cyber roles. The leak provided unprecedented insight into how Russia systematically develops cyber capabilities through supervised technical and ideological preparation of students before their assignment to intelligence and cyber warfare units. This exposure comes as Russian cyber operations have intensified against critical infrastructure globally, with increased focus on destructive attacks and espionage campaigns targeting government and private sector networks across multiple domains.
3 weeks ago
Kill Chain
Iranian State Hackers Exploit Tech Job Market to Deploy Advanced Cross-Platform Malware
Iranian threat group Nimbus Manticore (also known as Mirage Kitten) has expanded their attack methodology by deploying cross-platform remote access trojans (RATs) through sophisticated social engineering campaigns targeting software engineers. The group poses as recruiters from major technology companies on LinkedIn and other job platforms, delivering trojanized coding challenges containing NodeRabbit and PollCat malware. These Node.js and JavaScript-based RATs can infect Windows, Linux, and macOS systems, representing a significant evolution from their traditional C/C++ toolset. The campaign has been observed targeting victims across Afghanistan, Egypt, and Ethiopia, demonstrating the group's expanded geographic reach and technical capabilities. This incident highlights the growing trend of state-sponsored actors adopting cross-platform development frameworks to maximize their attack surface while leveraging legitimate recruitment processes as attack vectors. The sophisticated nature of these fake coding challenges and the pressure tactics employed demonstrate how threat actors are increasingly exploiting the competitive job market in the technology sector.
3 weeks ago
Kill Chain
Fire Ant Hackers Transform Cisco Routers Into Covert Espionage Platforms
Chinese Fire Ant hackers, linked to the UNC3886 espionage group, evolved their tactics in August 2026 by compromising Cisco IOS XR routers to establish covert surveillance platforms. The threat actors deployed custom malware creating hidden GRE tunnels, suppressed system logs, and transformed network infrastructure into collection points for traffic monitoring and reconnaissance. They captured network traffic via PCAP files uploaded to external FTP servers, exposing internal topology, authentication flows, and communications across trusted network paths to enable lateral movement into high-value connected environments. This incident highlights the growing trend of nation-state actors targeting critical network infrastructure as initial access points, moving beyond traditional endpoint compromises to leverage trusted network devices for persistent espionage operations and supply chain infiltration.
3 weeks ago
Kill Chain
Chinese QTFY Threat Actor Targeted Federal Agencies Through Sophisticated IoT Botnet Operations
In August 2026, the U.S. Department of Justice corrected previous statements about Chinese state-sponsored threat actor QTFY (QT AND QTCYBER), clarifying that federal agencies including NASA, DOE, DOJ, HHS, NIH, and the U.S. Senate were targeted rather than successfully compromised. QTFY, operating since 2018 through Nanjing Xinjiuwei Network Technology Co with backing from China's Ministry of State Security, provided reconnaissance and proxy services using tools like QScan vulnerability scanner and QTRouter obfuscation network. The FBI disrupted the group's infrastructure, which facilitated cyber espionage through an industrialized botnet of compromised IoT devices and leased VPS servers. This incident highlights the persistent and sophisticated nature of Chinese state-sponsored espionage campaigns targeting critical U.S. infrastructure, demonstrating how adversaries leverage compromised IoT devices to blend malicious traffic with legitimate network activity and evade detection through decentralized operational relay networks.
3 weeks ago
Kill Chain
Fire Ant APT Turns Cisco Routers Into Credential Harvesting Platforms
In 2026, the China-linked Fire Ant threat group expanded their espionage operations beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts across high-value networks. The attackers transformed compromised routers into collection platforms, capturing network traffic, harvesting administrator credentials, and suppressing security logs to blind defenders. Fire Ant deployed custom malware including TacTap for credential theft, BridgeAgent backdoor, and router-specific implants that modified system libraries to hide their presence from network administrators. This incident demonstrates the evolving sophistication of nation-state actors targeting critical network infrastructure, particularly as organizations increasingly rely on hybrid cloud architectures. The attackers' ability to compromise trusted network devices highlights the growing threat to supply chain security and the need for enhanced monitoring of network edge devices that traditional security controls often overlook.
3 weeks ago
Kill Chain
ZBT Router Backdoors: How Chinese Manufacturer Compromised Global Networks
In August 2026, security researchers discovered that Shenzhen Zhibotong Electronics Co. Ltd. (ZBT), a major Chinese router manufacturer, had embedded multiple backdoors in firmware across millions of white-label routers sold globally. The backdoors, dubbed 'EndlessDoors,' 'SpeakingStone,' and 'DarkLantern,' provided root-level access and command-and-control capabilities to attackers. With ZBT producing 3.57 million units annually and exporting to over 50 countries including the US, Canada, Germany, and Australia, the supply chain compromise potentially affected hundreds of thousands of edge devices in critical infrastructure, corporate networks, and remote installations like oil pipelines. This incident exemplifies the growing threat of nation-state supply chain attacks targeting network infrastructure, particularly as organizations increasingly deploy edge devices with cellular connectivity in remote locations that are difficult to monitor and update.
3 weeks ago
Kill Chain
Factory Implants in ZBT Routers Expose Global Supply Chain Security Crisis
In August 2026, VulnCheck disclosed two previously undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, found in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Both implants, tracked as CVE-2026-74232 and CVE-2026-74233 with CVSS scores of 9.3-9.8, provide unauthenticated remote attackers with root access to affected devices. SPEAKINGSTONE operates as a surveillance implant that beacons to hardcoded command-and-control servers, while DARKLANTERN listens on UDP port 9992 with ineffective authentication. VulnCheck identified over 200 internet-facing DARKLANTERN instances across 22 countries and received beacons from 392 unique devices when they registered the backup C2 domain. This incident highlights the growing threat of supply chain attacks targeting network infrastructure, particularly as organizations increasingly rely on low-cost networking equipment from overseas manufacturers. The discovery comes amid heightened awareness of nation-state activities targeting critical infrastructure and follows similar findings in Chinese-manufactured networking equipment.
3 weeks ago
Kill Chain
Critical Xiiaozet LK100W Vulnerabilities Expose Industrial Control Systems to Remote Takeover
CISA disclosed three critical vulnerabilities in the Xiiaozet LK100W industrial control device, with CVSS scores up to 9.8. The flaws include OS command injection (CVE-2026-78037), missing authentication for critical functions (CVE-2026-78239), and authentication bypass (CVE-2026-76943). These vulnerabilities allow remote attackers to execute arbitrary commands with elevated privileges, enable unauthorized administrative services, and completely compromise affected devices running firmware versions below 2.1.240. The vulnerabilities were reported by Byron Guernsey of Okachobi, LLC and affect devices deployed worldwide across critical infrastructure sectors. This incident highlights the persistent security challenges in industrial IoT devices and the expanding attack surface of critical infrastructure. With nation-state actors increasingly targeting industrial control systems and the growing convergence of IT and OT networks, these authentication and command injection flaws represent the type of fundamental security weaknesses that enable sophisticated supply chain and infrastructure attacks.
3 weeks ago
Kill Chain
Dark Caracal Unveils Blockchain-Powered GoCaracal Malware in Advanced Espionage Campaign
The Lebanon-linked Dark Caracal threat group has deployed a previously unknown malware framework called GoCaracal to enhance its cyber espionage capabilities across Latin America. Discovered by Arctic Wolf researchers in August 2026 during investigation of a targeted intrusion in Venezuela, GoCaracal represents a significant evolution in Dark Caracal's toolkit, featuring modular architecture, encrypted communications, and innovative use of Ethereum blockchain for backup command-and-control infrastructure. The malware comes in two variants: a lightweight implant for initial access and a comprehensive version for intelligence harvesting and persistent control. This incident highlights the growing sophistication of state-sponsored espionage operations and their adaptation to modern defensive measures. The integration of blockchain technology for C2 resilience and modular malware design demonstrates how advanced persistent threat groups are evolving their tactics to maintain long-term access in increasingly monitored environments.
4 weeks ago
Kill Chain
Dark Caracal's GoCaracal Malware Pioneers Ethereum Smart Contract C2 Infrastructure
In June 2026, threat actors linked to Dark Caracal deployed GoCaracal, a previously undocumented Go-based malware framework, against a Venezuelan communications organization. Arctic Wolf discovered this sophisticated malware uses Ethereum smart contracts as a fallback mechanism to retrieve replacement command-and-control (C2) server addresses when primary servers fail. GoCaracal provides remote shell access, payload execution, browser data theft, keylogging, and remote desktop control capabilities, delivered through phishing campaigns using malicious SVG files. This incident demonstrates the evolution of C2 resilience mechanisms as threat actors adapt to increased infrastructure takedowns and incorporate blockchain technology for operational persistence, highlighting the need for comprehensive egress filtering and behavioral anomaly detection.
4 weeks ago
Kill Chain
How QTFY's 8-Year Espionage Campaign Exposed Critical Gaps in Federal Network Security
Federal authorities disrupted a sophisticated Chinese state-sponsored espionage operation conducted by the QTFY threat group, which had been targeting U.S. critical infrastructure since 2018. The group, operating through Nanjing Xinjiuwei Network Technology Company, successfully compromised multiple federal agencies including the Departments of Energy, Justice, Health and Human Services, Federal Reserve, NASA, and NIH. Using comprehensive toolsets including QScan vulnerability scanner with over 200 exploits and QTRouter traffic concealment platform, QTFY exploited zero-day vulnerabilities in major vendors like Ivanti, Pulse Secure, and Fortinet to maintain persistent access across government and private sector networks. This incident highlights the escalating sophistication of Chinese APT groups and their focus on long-term strategic intelligence collection from U.S. government agencies and critical infrastructure providers, demonstrating the urgent need for enhanced zero trust security architectures.
4 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports