Attackers using tools associated with Chinese espionage groups have breached multiple telecom operators in a single Asian country in a long-running espionage campaign.
The attackers placed backdoors on the networks of targeted companies and also attempted to steal credentials. The attacks have been underway since at least 2021, with evidence to suggest that some of this activity may even date as far back as 2020. Virtually all of the organizations targeted were telecoms operators, with the addition of a services company that serves the telecoms sector and a university in another Asian country.
Read more…
Source: Symantec
Related:
- Police warn Israelis not to answer unknown calls
October 27, 2023
The Israel Police warned citizens on Friday not to answer phone or video calls from numbers they don’t recognize—particularly from abroad—following a surge of suspicious calls reported to authorities. “The purpose of the calls may be to cause panic and harassment and may be part of attempts to take over the WhatsApp accounts,” per a ...
- Stayin’ Alive – targeted attacks against telecoms and government ministries in Asia
October 11, 2023
In the last few months, Check Point Research has been tracking “Stayin’ Alive”, an ongoing campaign that has been active since at least 2021. The campaign operates in Asia, primarily targeting the Telecom industry, as well as government organizations. The “Stayin’ Alive” campaign consists of mostly downloaders and loaders, some of which are used as ...
- MICITT Seeks To Protect Costa Ricans From Cyber Attacks With The 5G Network
October 8, 2023
Protecting the information of citizens, businesses, public institutions and the country in general from constant cyber attacks is the purpose sought by the Ministry of Science, Innovation, Technology and Telecommunications (MICITT) with the “Regulation on Cybersecurity Measures Applicable to Telecommunications Services Based on Fifth Generation Mobile Technology (5G) and Higher. ”This was announced by Paula ...
- Lyca Mobile blames cyberattack for network disruption
October 4, 2023
U.K.-based mobile virtual network provider giant Lyca Mobile has confirmed a cyberattack that caused service disruption for millions of its customers. Lyca Mobile claims to be the world’s largest international mobile virtual network operator, or MVNO, which piggybacks off network operator EE’s infrastructure. Lyca confirmed in a statement this week that the security incident prevented customers ...
- Budworm: APT Group Uses Updated Custom Tool in Attacks on Government and Telecoms Org
September 28, 2023
The Budworm advanced persistent threat (APT) group continues to actively develop its toolset. Most recently, the Threat Hunter Team in Symantec, part of Broadcom, discovered Budworm using an updated version of one of its key tools to target a Middle Eastern telecommunications organization and an Asian government. Both attacks occurred in August 2023. Budworm (aka LuckyMouse, ...
- One of the largest T-Mobile authorized retailers had 90GB of info leaked, including customer data
September 23, 2023
T-Mobile is often in the news for the wrong reasons. Yesterday, a glitch in the company’s system showed personal customer information to the wrong account holders. And now, there is fear that freshly leaked data that is available online could help bad actors gain access to sensitive information. In T-Mobile’s defense, the carrier cannot be blamed ...