| Salt Typhoon and overlapping PRC cluster labels |
Joint government reporting describes global compromise of telecom and network infrastructure. AA25-239A notes overlap among Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor; that overlap is not treated as exact identity. |
Backbone provider edge/customer-edge routers, administrator access, configuration changes, and virtualized router/container capabilities. |
Router running/startup configuration, AAA and command logs, VPN and management-plane telemetry. Public advisories do not publish a universal malware filename. |
Espionage and persistent access. The FBI separately reports theft of call-data logs, limited private communications, and copied information associated with select court-ordered requests. |
The lab has no carrier PE/CE routers or lawful-intercept platform. The relevant analogue is management-plane compromise of the Docker host followed by access to NF configs, MongoDB, and containers. |
| LIMINAL PANDA / LightBasin |
CrowdStrike assesses a China nexus with moderate confidence and documents repeated targeting of telecom Linux and inter-provider trust. |
Password spraying against an externally reachable eDNS server; SSH pivot from another compromised telecom; GTP/SIGTRAN tooling; persistence and packet-filter manipulation. |
/usr/bin/pingg; /etc/rc.d/init.d/sshd; /usr/bin/libcord.so; /usr/lib/cord.lib; /usr/lib/libcord.so; /home/REDACTED/cordscan_raw_arm; /usr/lib/javacee; /usr/lib/sgsnemu; /usr/bin/sgsnemu; /usr/lib/sgsnemu_bak; /usr/lib/tshd; /usr/local/sbin/iptables; /usr/sbin/iptablesDir/; /sbin/iptablesDir/; frpc, frpc.ini, proxychains configuration; applications include CordScan, SIGTRANslator, sgsnemu, TinyShell, and Fast Reverse Proxy. |
Telecom intelligence collection and durable access across trusted carrier relationships; source identifies eDNS, service-delivery, SIM/IMEI provisioning, OSS, and operations/maintenance systems among targets. |
Strong conceptual match to Linux host, GTP, subscriber provisioning, and internal trust. Exact IOCs are not expected in the containers unless the same tooling is introduced. Monitor container/host binaries, SSH, iptables/nftables, and unexpected GTP endpoints. |
| Operation Soft Cell |
Cybereason/Virus Bulletin document a multi-year intrusion into telecom providers; nation-state motivation is supported, while public actor attribution has been disputed. |
IIS compromise/web shell, credential dumping, lateral movement through Windows estates, and staged collection of call-detail records. |
w3wp.exe; China Chopper web shell; maybemimi.exe (modified Mimikatz); signed Samsung RunHelp.exe loading ssMUIDLL.dll; Poison Ivy; WinRAR; renamed cmd.exe; portqry.exe; hTran; net use; wmic.exe. |
Collection of CDR data including IMSI, IMEI, MSISDN, and location-related records for selected subscribers. |
The lab has no IIS/Windows OSS/BSS or CDR warehouse. MongoDB holds subscriber/core data and is the nearest data-store analogue, but calling it a CDR target would be inaccurate. |
| Sea Turtle |
Cisco Talos assesses a state-sponsored campaign with high confidence; primary and secondary victims included registries, registrars, telecoms, and ISPs. |
Credential compromise and DNS-record manipulation at registrars or DNS infrastructure, allowing traffic redirection and credential interception. |
Registrar panels, DNS records, EPP credentials/keys, name servers, and certificate-related artifacts; no universal malicious filename published. |
Credential theft and durable access through control of DNS resolution. |
There is no authoritative DNS or roaming eDNS service in the active lab. The analogue is integrity of Docker DNS/service names and repository configuration, not a claim that Sea Turtle targeted Open5GS. |
| UNC1945 |
Mandiant documents a threat cluster targeting Solaris/Linux environments including managed-service providers; the cited report is not evidence of a mobile-core campaign. |
Exposed SSH and a Solaris PAM zero-day, followed by living-off-the-land activity and SSH port forwarding. Initial access was not established in every case. |
EVILSUN exploiting CVE-2020-14871; SLAPSTICK; modified/copied /lib64/security/pam_unix.so; /var/tmp/.cache/ocb_static; SSH utilities and tunneling. |
Long-term access and credential capture in Unix estates. |
Relevant as a Unix/management-plane precursor. The local macOS/Docker stack is not Solaris and is not affected by CVE-2020-14871. |
| Volt Typhoon |
Joint government advisory documents PRC activity against U.S. critical infrastructure. It is not public evidence of compromise of this Open5GS stack. |
Valid administrator credentials, edge-appliance compromise, Active Directory discovery, movement to domain controllers, and NTDS.dit extraction. |
Windows NTDS.dit; ESENT Application events 216/325/326/327; Security event 1102. CISA reports a likely exploitation path involving a FortiGate 300D and CVE-2022-42475 in one case. |
Pre-positioning and durable access to critical infrastructure. |
Relevant to identity, edge, and host hardening. The lab has no AD or FortiGate; do not map that CVE to Open5GS. |
| 3CX supply-chain incident |
CISA analysis confirms trojanized 3CXDesktopApp distribution. This is a communications-software supply-chain incident, not proof of a mobile-core intrusion. |
Signed/vendor software update and malicious installer/application loading. |
3CXDesktopApp; \3CXDesktopApp\config.json; browser database access; CISA publishes hashes and analyzed samples. |
Initial access and follow-on collection through a trusted communications application. |
The analogue is provenance of Docker images and build dependencies (gradiant/open5gs, mongo, UERANSIM), plus CI/repository integrity. |
| KA-SAT destructive incident |
Viasat’s incident report documents the access and effect; this row avoids adding an actor attribution beyond that source. |
Misconfigured VPN appliance enabled access to a trusted management segment; legitimate management commands were then used against many modems. |
VPN appliance configuration, trusted management network, and modem-management commands; no single malware filename is necessary to explain the destructive action. |
Service disruption by overwriting flash data on large numbers of modems. |
Strong management-plane lesson: a valid control channel can create destructive impact without exploiting the endpoint. The lab analogue is Docker/API administrative access to NFs and containers. |
| Exynos baseband vulnerabilities |
Google Project Zero documented four Internet-to-baseband RCE vulnerabilities reachable with only the victim phone number on affected devices/chipsets. This is vulnerability research, not an APT campaign claim. |
Remote baseband processing over cellular protocols without user interaction. |
CVE-2023-24033, CVE-2023-26496, CVE-2023-26497, and CVE-2023-26498; affected Samsung Exynos modem code. |
Potential code execution in the baseband trust domain. |
The lab’s simulated UERANSIM UE is not an Exynos modem. Physical UE/baseband testing belongs in the owned-device track, not the Docker core. |