The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Officials Dismantle Major Southeast Asia Cybercrime Network in $15B Bitcoin Seizure
In early 2024, federal authorities from the U.S. and U.K. conducted a large-scale operation against Southeast Asia cybercrime networks, seizing 127,271 Bitcoins worth approximately $15 billion from Chen Zhi, the alleged head of the Prince Group based in Cambodia. The Prince Group, operating since 2015, is accused of running transnational scam compounds utilizing human trafficking and forced labor to enact wide-reaching financial fraud across over 30 countries, including the U.S. where a Brooklyn network victimized more than 250 individuals. The operation resulted in sanctions on 146 people and organizations, the severing of Huione Group from the U.S. financial system, and the dismantling of 117 illicit Prince Group-affiliated businesses. This record-breaking crackdown underscores the severity and international scale of cyber-enabled financial fraud, money laundering, and the role of organized crime groups leveraging technology across borders. The incident highlights growing regulatory and enforcement focus, as well as the evolving threat posed by sophisticated scam and laundering operations exploiting multi-region financial networks.
8 months ago
Kill Chain
Startling Satellite Breach: How $600 Unlocked a Global Data Leak in 2025
In early 2025, researchers from the University of Maryland and UC San Diego revealed widespread leakage of sensitive and private data—including military and telecom communications—through unencrypted transmissions sent over geostationary (GEO) satellites. By using only $600 in commercially available equipment, the team passively intercepted vast amounts of plaintext data from major organizations, government entities, and telecom users around the globe. The incident highlighted fundamental lapses in network-layer encryption practices, allowing phone calls, SMS messages, internal application data, and even military vessel information to leak with no authentication or protection. The research further demonstrated that even technically unsophisticated actors could compromise critical satellite backhaul links using minimal resources. This event underscores the urgent need for end-to-end encryption and robust monitoring of satellite communications as reliance on these channels increases and barriers to interception continue to fall. Government and industry must now address the rapidly evolving risk landscape, especially as critical infrastructure becomes more dependent on satellite connectivity.
8 months ago
Kill Chain
US Seizes $15B in Crypto from Global 'Pig Butchering' Syndicate
In October 2025, the U.S. Department of Justice seized $15 billion in bitcoin from the leader of the Prince Group, a transnational criminal organization responsible for orchestrating large-scale cryptocurrency investment scams, widely known as 'pig butchering.' Operating from Cambodia since 2015, Prince Group exploited social media, dating apps, and messaging platforms to lure victims into fraudulent investment schemes, funneling billions via complex laundering tactics and a vast network of shell companies in over 30 countries. The syndicate trafficked and forced thousands into labor-intensive scam compounds, evading law enforcement and leveraging bribery, automated call centers, and violence. The stolen funds were laundered and spent on luxury assets and high-value goods. The Prince Group incident underscores the escalating threat of organized cyber-enabled financial fraud, particularly those leveraging cryptocurrency to obfuscate illicit gains. Despite large-scale law enforcement crackdowns, similar tactics—ranging from romance baiting to advanced obfuscation—have proliferated globally, highlighting persistent regulatory and security challenges for fintech and law enforcement agencies.
8 months ago
Kill Chain
How Hacktivists Used Hashtags and DDoS to Disrupt in 2025
In early 2025, a surge in global hacktivist operations was observed, coordinated primarily via Telegram and X (formerly Twitter), with attackers leveraging hashtags to claim credit, issue threats, and organize campaigns. Over 120 hacktivist groups, originating in the MENA region but targeting organizations worldwide—including government, finance, and critical infrastructure—conducted highly visible DDoS attacks. These operations favored impact and propaganda over technical sophistication, resulting in significant service disruptions and reputational challenges for numerous victims, with attack announcements and proof frequently disseminated in near real-time. The campaign reflects a broader shift toward open, social-media-driven hacktivist tactics that often transcend regional geopolitics. As DDoS tools become more accessible and social platforms amplify coordination, all organizations—regardless of direct involvement in conflicts—face increased risk from ideologically motivated cyberattacks.
8 months ago
Kill Chain
Fake Inflation Refund Phishing Texts Target New Yorkers in 2025 Smishing Attack
In October 2025, a coordinated smishing campaign targeted New York State residents with fraudulent text messages purporting to be from the Department of Taxation and Finance. The attackers claimed recipients were eligible for an 'Inflation Refund' and directed them to a phishing site impersonating an official state portal, where victims were prompted to submit sensitive personal data—name, address, email, phone number, and Social Security Number—under the guise of processing their refund. This malicious operation seeks to steal identities and facilitate extensive financial fraud. Government officials swiftly issued warnings, clarifying that legitimate refunds required no action from residents and urging vigilance. This incident is a stark reminder of the increasing sophistication of SMS phishing (smishing) attacks, which blend timely government programs with social engineering techniques. The campaign highlights the persistent risk posed by identity-centric attacks, especially as digital fraudsters exploit widespread economic uncertainty and official-sounding initiatives.
8 months ago
Kill Chain
Russian ClayRat Android Spyware Masquerades as Popular Apps, Spreads Rapidly in 2024
In mid-2024, security researchers at Zimperium discovered ClayRat, a rapidly evolving Android spyware campaign targeting users in Russia. Disguised as trusted apps like TikTok and YouTube, ClayRat was spread via phishing websites and Telegram channels, infecting over 600 devices in just three months. Once installed, the spyware leverages Android’s SMS handler permissions to bypass typical security prompts, allowing attackers to covertly access messages, call logs, device information, and even remotely control infected phones. The highly orchestrated campaign abused social engineering, web deception, and obfuscation techniques to remain undetected, and can turn each compromised device into a new attack vector. The threat’s evolution signals rising global risks, as the campaign’s tactics can easily adapt to new payloads and regions. With increasing use of mobile malware, organizations globally should reassess mobile security controls and user awareness programs to defend against sophisticated, evasive spyware attacks exploiting trust in well-known apps.
8 months ago
Kill Chain
Aisuru Botnet’s Record DDoS Assaults Expose IoT Weaknesses in US ISPs
In October 2025, the Aisuru botnet orchestrated the largest recorded distributed denial-of-service (DDoS) attacks to date, leveraging over 300,000 compromised IoT devices primarily hosted on major U.S. ISPs such as AT&T, Comcast, and Verizon. The botnet, evolved from Mirai code, exploited insecure or outdated IoT firmware, driving attack volumes to nearly 30 terabits per second. Recurrent DDoS waves severely disrupted online gaming infrastructure and collateral users, overwhelming both DDoS mitigation providers and ISPs, and causing service dropouts and customer impact across multiple networks. This incident exemplifies the rising scale and sophistication of IoT-based botnets and exposes urgent deficiencies in outbound DDoS filtering at the ISP level. The Aisuru event also highlights a growing threat trend: attackers using compromised consumer IoT to reinforce both DDoS infrastructure and residential proxy networks, broadening attacker capabilities and the attack surface for businesses and critical providers.
8 months ago
Kill Chain
RondoDox Botnet Orchestrates Mass n-day IoT Attacks in 2025
In mid-2025, the RondoDox botnet emerged as a powerful threat targeting IoT and network devices by exploiting 56 known (n-day) vulnerabilities across over 30 device types, including routers, NVRs, DVRs, and CCTV systems. The operators, closely monitoring vulnerability disclosures—such as those revealed at Pwn2Own events—rapidly weaponized publicly disclosed exploits, including CVE-2023-1389 and CVE-2024-12856, using a high-volume "exploit shotgun" methodology to maximize infections. With operations observed since June 2025, the campaign affected both end-of-life and actively supported products, resulting in a widespread compromise of infrastructure, particularly among organizations and consumers with unpatched devices. This attack underscores a growing trend of mass exploitation of n-day vulnerabilities in IoT ecosystems, reflecting increasing automation and sophistication among botnet operators. The pace at which attackers operationalize new exploits demands faster patching, improved segmentation, and heightened baseline security practices across networked environments.
8 months ago
Kill Chain
ClayRat Android Spyware: Fake App Campaign Hits Mobile Users in 2025
In October 2025, cybersecurity researchers at Zimperium disclosed a widespread Android spyware campaign dubbed ClayRat, which targeted Russian users through phishing portals, Telegram channels, and malicious websites mimicking popular apps such as WhatsApp, TikTok, YouTube, and Google Photos. Using fraudulent Play Store-like websites and social engineering tactics, attackers tricked users into sideloading APKs that installed malicious payloads via a session-based installation method, bypassing Android security. Once installed, ClayRat acts as the device's default SMS handler, enabling interception of messages, call logs, notifications, and exfiltration of sensitive data to an AES-GCM-encrypted command and control (C2) server. It also uses infected devices to propagate itself by sending mass SMS messages to victims' contacts. This incident underscores an accelerating trend in mobile spyware leveraging legitimate app impersonation and sophisticated delivery mechanisms. The high volume of ClayRat samples and droppers, the abuse of sideloading, and the global reach of Telegram-based distribution channels highlight persistent gaps in mobile endpoint and social engineering defenses.
8 months ago
Kill Chain
FreePBX VoIP Vulnerability Exploited: CVE-2025-57819 Enables Code Execution
In August 2025, a critical SQL injection vulnerability (CVE-2025-57819) was disclosed in FreePBX, a popular open-source VoIP telephony platform. The flaw, found in the system's web-based admin interface, allowed unauthenticated attackers to inject malicious SQL queries via a vulnerable 'brand' parameter, enabling arbitrary modification of the backend database. Attackers have already been observed using this vulnerability to gain remote code execution by inserting persistent cron jobs that continuously recreate a web shell on the target server, providing full access for data exfiltration or fraudulent activities. Organizations using unpatched versions may be exposed to call fraud, impersonation, lateral movement, or further compromise of VoIP infrastructure. This breach highlights a persistent trend of attackers exploiting critical web application vulnerabilities shortly after public disclosure, underscoring the importance of proactive patching and real-time threat detection. It also illustrates attackers’ growing focus on embedded and telecom systems as entry points for broader enterprise compromise.
8 months ago
Kill Chain
EU Chat Control Law Threatens Privacy and Encryption in 2024
In 2024, the European Union considered sweeping legislation called Chat Control, aimed at mandating providers of end-to-end encrypted messaging apps to implement client-side scanning of user content for illegal material, notably child sexual abuse material (CSAM). Major privacy advocates and technology leaders, including Signal's CEO, highlighted that such a regulation would undermine privacy by requiring access to sensitive content before encryption. Technical experts warned that creating lawful access inherently weakens the entire encrypted ecosystem, exposing all users—including journalists, activists, and vulnerable groups—to potential surveillance or exploitation, and might force some encrypted messaging services to exit the EU market entirely. This proposed law has sparked an urgent debate on digital privacy, as its adoption could set a global precedent for government-mandated encryption backdoors. The current climate of rising concerns over lawful and extrajudicial surveillance, combined with persistent cyber threats, amplifies the pertinence and risks associated with such regulatory initiatives.
8 months ago
Kill Chain
Self-Propagating Malware Targets WhatsApp Users in Brazil with Financial Fraud Infostealer
In early June 2024, an infostealer campaign dubbed Water Saci aggressively targeted WhatsApp users in Brazil using self-propagating malware named Sorvepotel. Attackers leveraged compromised accounts to automatically distribute malicious links via WhatsApp messages, luring recipients to execute malware payloads. Once installed, Sorvepotel exfiltrates credentials and tracks browser activities, enabling threat actors to target and defraud regional financial institutions. The infection chain’s ability to rapidly spread through trusted social contacts increased both the velocity and scale of impact, compromising both individual and enterprise devices in a short time frame. The Water Saci operation highlights the evolution of credential-stealing malware adopting worm-like features to maximize reach. With messaging platforms remaining core to business and personal communications, this incident underscores the urgency of intercepting lateral movement, especially as attackers blend social engineering with advanced propagation and data theft techniques.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports