• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
chinese cyber espionage targets telecom operators in asia since 2021

Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021

You are here: Home / General Cyber Security News / Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021
June 20, 2024

Cyber espionage groups affiliated with China have been connected to a lengthy-operating marketing campaign that has infiltrated a number of telecom operators located in a solitary Asian country at minimum because 2021.

“The attackers put backdoors on the networks of specific corporations and also tried to steal credentials,” the Symantec Risk Hunter Group, section of Broadcom, claimed in a report shared with The Hacker News.

The cybersecurity agency did not expose the place that was qualified, but claimed it observed proof to counsel that the destructive cyber exercise might have started as much back as 2020.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

The attacks also qualified an unnamed solutions company that catered to the telecoms sector and a university in another Asian country, it added.

The option of equipment utilised in this campaign overlaps with other missions done by Chinese espionage groups like Mustang Panda (aka Earth Preta and Fireant), RedFoxtrot (aka Neeedleminer and Nomad Panda), and Naikon (aka Firefly) in latest decades.

This features custom backdoors tracked as COOLCLIENT, QuickHeal, and RainyDay that occur outfitted with capabilities to capture sensitive data and build interaction with a command-and-handle (C2) server.

Whilst the correct initial obtain pathway applied to breach the targets is presently unidentified, the marketing campaign is also noteworthy for deploying port scanning tools and conducting credential theft by the dumping of Windows Registry hives.

The fact that the tooling has connections to 3 unique adversarial collectives has raised several choices: The attacks are currently being conducted independently of each other, a solitary risk actor is making use of instruments acquired from other groups, or assorted actors are collaborating on a solitary marketing campaign.

Also unclear at this phase is the most important motive driving the intrusions, whilst Chinese menace actors have a history of focusing on the telecoms sector throughout the entire world.

Cybersecurity

In November 2023, Kaspersky revealed a ShadowPad malware marketing campaign concentrating on one particular of the nationwide telecom businesses of Pakistan by exploiting recognized security flaws in Microsoft Trade Server (CVE-2021-26855 aka ProxyLogon).

“The attackers may well have been accumulating intelligence on the telecoms sector in that region,” Symantec postulated. “Eavesdropping is one more likelihood. Alternatively, the attackers may perhaps have been making an attempt to develop a disruptive capacity in opposition to critical infrastructure in that state.”

Identified this short article interesting? Stick to us on Twitter  and LinkedIn to examine more unique material we post.


Some components of this short article are sourced from:
thehackernews.com

Previous Post: «new rust based fickle malware uses powershell for uac bypass and New Rust-based Fickle Malware Uses PowerShell for UAC Bypass and Data Exfiltration
Next Post: Tool Overload: Why MSPs Are Still Drowning with Countless Cybersecurity Tools in 2024 tool overload: why msps are still drowning with countless cybersecurity»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
  • PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution
  • Securing Data in the AI Era
  • Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild
  • Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals
  • CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target Enterprises
  • Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads
  • Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord
  • Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods
  • What Security Leaders Need to Know About AI Governance for SaaS

Copyright © TheCyberSecurity.News, All Rights Reserved.