Documented APT and Telecom Intrusion Campaigns

Documented APT and Telecom Intrusion Campaigns

Research rule

The table below separates what a source observed from what the lab can model. “Filename” means a path or process explicitly named by the source, not a guessed vendor path. When reporting does not publish a filename, the cell says so.

Campaign matrix

Campaign / actor label Confidence and target Documented entry or pivot Named files, tools, or applications Documented objective Lab comparison
Salt Typhoon and overlapping PRC cluster labels Joint government reporting describes global compromise of telecom and network infrastructure. AA25-239A notes overlap among Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807, and GhostEmperor; that overlap is not treated as exact identity. Backbone provider edge/customer-edge routers, administrator access, configuration changes, and virtualized router/container capabilities. Router running/startup configuration, AAA and command logs, VPN and management-plane telemetry. Public advisories do not publish a universal malware filename. Espionage and persistent access. The FBI separately reports theft of call-data logs, limited private communications, and copied information associated with select court-ordered requests. The lab has no carrier PE/CE routers or lawful-intercept platform. The relevant analogue is management-plane compromise of the Docker host followed by access to NF configs, MongoDB, and containers.
LIMINAL PANDA / LightBasin CrowdStrike assesses a China nexus with moderate confidence and documents repeated targeting of telecom Linux and inter-provider trust. Password spraying against an externally reachable eDNS server; SSH pivot from another compromised telecom; GTP/SIGTRAN tooling; persistence and packet-filter manipulation. /usr/bin/pingg; /etc/rc.d/init.d/sshd; /usr/bin/libcord.so; /usr/lib/cord.lib; /usr/lib/libcord.so; /home/REDACTED/cordscan_raw_arm; /usr/lib/javacee; /usr/lib/sgsnemu; /usr/bin/sgsnemu; /usr/lib/sgsnemu_bak; /usr/lib/tshd; /usr/local/sbin/iptables; /usr/sbin/iptablesDir/; /sbin/iptablesDir/; frpc, frpc.ini, proxychains configuration; applications include CordScan, SIGTRANslator, sgsnemu, TinyShell, and Fast Reverse Proxy. Telecom intelligence collection and durable access across trusted carrier relationships; source identifies eDNS, service-delivery, SIM/IMEI provisioning, OSS, and operations/maintenance systems among targets. Strong conceptual match to Linux host, GTP, subscriber provisioning, and internal trust. Exact IOCs are not expected in the containers unless the same tooling is introduced. Monitor container/host binaries, SSH, iptables/nftables, and unexpected GTP endpoints.
Operation Soft Cell Cybereason/Virus Bulletin document a multi-year intrusion into telecom providers; nation-state motivation is supported, while public actor attribution has been disputed. IIS compromise/web shell, credential dumping, lateral movement through Windows estates, and staged collection of call-detail records. w3wp.exe; China Chopper web shell; maybemimi.exe (modified Mimikatz); signed Samsung RunHelp.exe loading ssMUIDLL.dll; Poison Ivy; WinRAR; renamed cmd.exe; portqry.exe; hTran; net use; wmic.exe. Collection of CDR data including IMSI, IMEI, MSISDN, and location-related records for selected subscribers. The lab has no IIS/Windows OSS/BSS or CDR warehouse. MongoDB holds subscriber/core data and is the nearest data-store analogue, but calling it a CDR target would be inaccurate.
Sea Turtle Cisco Talos assesses a state-sponsored campaign with high confidence; primary and secondary victims included registries, registrars, telecoms, and ISPs. Credential compromise and DNS-record manipulation at registrars or DNS infrastructure, allowing traffic redirection and credential interception. Registrar panels, DNS records, EPP credentials/keys, name servers, and certificate-related artifacts; no universal malicious filename published. Credential theft and durable access through control of DNS resolution. There is no authoritative DNS or roaming eDNS service in the active lab. The analogue is integrity of Docker DNS/service names and repository configuration, not a claim that Sea Turtle targeted Open5GS.
UNC1945 Mandiant documents a threat cluster targeting Solaris/Linux environments including managed-service providers; the cited report is not evidence of a mobile-core campaign. Exposed SSH and a Solaris PAM zero-day, followed by living-off-the-land activity and SSH port forwarding. Initial access was not established in every case. EVILSUN exploiting CVE-2020-14871; SLAPSTICK; modified/copied /lib64/security/pam_unix.so; /var/tmp/.cache/ocb_static; SSH utilities and tunneling. Long-term access and credential capture in Unix estates. Relevant as a Unix/management-plane precursor. The local macOS/Docker stack is not Solaris and is not affected by CVE-2020-14871.
Volt Typhoon Joint government advisory documents PRC activity against U.S. critical infrastructure. It is not public evidence of compromise of this Open5GS stack. Valid administrator credentials, edge-appliance compromise, Active Directory discovery, movement to domain controllers, and NTDS.dit extraction. Windows NTDS.dit; ESENT Application events 216/325/326/327; Security event 1102. CISA reports a likely exploitation path involving a FortiGate 300D and CVE-2022-42475 in one case. Pre-positioning and durable access to critical infrastructure. Relevant to identity, edge, and host hardening. The lab has no AD or FortiGate; do not map that CVE to Open5GS.
3CX supply-chain incident CISA analysis confirms trojanized 3CXDesktopApp distribution. This is a communications-software supply-chain incident, not proof of a mobile-core intrusion. Signed/vendor software update and malicious installer/application loading. 3CXDesktopApp; \3CXDesktopApp\config.json; browser database access; CISA publishes hashes and analyzed samples. Initial access and follow-on collection through a trusted communications application. The analogue is provenance of Docker images and build dependencies (gradiant/open5gs, mongo, UERANSIM), plus CI/repository integrity.
KA-SAT destructive incident Viasat’s incident report documents the access and effect; this row avoids adding an actor attribution beyond that source. Misconfigured VPN appliance enabled access to a trusted management segment; legitimate management commands were then used against many modems. VPN appliance configuration, trusted management network, and modem-management commands; no single malware filename is necessary to explain the destructive action. Service disruption by overwriting flash data on large numbers of modems. Strong management-plane lesson: a valid control channel can create destructive impact without exploiting the endpoint. The lab analogue is Docker/API administrative access to NFs and containers.
Exynos baseband vulnerabilities Google Project Zero documented four Internet-to-baseband RCE vulnerabilities reachable with only the victim phone number on affected devices/chipsets. This is vulnerability research, not an APT campaign claim. Remote baseband processing over cellular protocols without user interaction. CVE-2023-24033, CVE-2023-26496, CVE-2023-26497, and CVE-2023-26498; affected Samsung Exynos modem code. Potential code execution in the baseband trust domain. The lab’s simulated UERANSIM UE is not an Exynos modem. Physical UE/baseband testing belongs in the owned-device track, not the Docker core.

What the campaigns collectively say

  1. Initial access is usually outside the packet core. Edge routers, VPN, DNS, Windows/IIS, vendor software, SSH, and administrator identities dominate the public evidence.
  2. Telecom specialization appears after access. LIMINAL PANDA’s GTP/SIGTRAN tooling and Soft Cell’s CDR targeting are examples of operators understanding telecom assets rather than relying on a magical radio exploit.
  3. Trust links amplify access. Inter-provider Linux systems, DNS registrars, management networks, vendors, and privileged identities convert a local compromise into a multi-system event.
  4. Legitimate administration is itself an attack vector. Router configuration, modem management, Docker control, subscriber provisioning, and NF APIs can all cause impact without a memory-corruption exploit.

Claims deliberately excluded or narrowed

Proposed claim Disposition
“Salt Typhoon compromised CALEA systems.” Narrowed. The FBI says copied information associated with select court-ordered requests. This document does not infer a specific platform or statutory implementation.
“LIMINAL PANDA exploited CVE-2020-14871.” Rejected. The cited Solaris zero-day belongs to Mandiant’s UNC1945 reporting, not the CrowdStrike LIMINAL PANDA report.
“Volt Typhoon used mobile-core CVEs.” Rejected. The authoritative case evidence concerns edge/identity/AD activity; it is used only as a precursor model.
“Operation Soft Cell used EternalBlue, DCSync, or Kerberoasting.” Not included. Those details were not supported by the selected primary campaign paper.
“Every cleartext telecom protocol is an observed APT path.” Rejected. Cleartext is an architectural exposure only until campaign or local evidence demonstrates use.
“A newly filed Open5GS GitHub issue is a confirmed CVE.” Rejected. Upstream issue reports remain unverified unless reproduced and are labeled separately.