Mobility APT Research Source Ledger

Mobility APT Research Source Ledger

Source policy

Campaign claims prefer government advisories or the original incident-response report. Technical requirements prefer standards bodies and official product documentation. NVD is used for the confirmed Open5GS CVE record; upstream GitHub issues are labeled unverified and are not promoted to vulnerabilities without reproduction.

ID Source Supports Limits
S01 CISA/NSA/FBI et al. — Enhanced Visibility and Hardening Guidance for Communications Infrastructure PRC compromise of major telecom providers; management isolation, AAA, ACL, VPN, TLS, logging, and configuration-baseline guidance. Guidance says no novel activity was observed; it is not a mobile-core CVE list.
S02 CISA AA25-239A — Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide Global backbone/edge targeting, router configuration access, virtualized environments, and actor-label overlap. Alias overlap is not exact actor equivalence.
S03 FBI — Seeking Tips About PRC Targeting of U.S. Telecommunications Theft of call-data logs, limited private communications, and copied information associated with select court-ordered requests. Does not name a specific LI/CALEA product, file, or exploit.
S04 FBI/CSE — PRC Cyber Threat Activity Targeting Telecommunications 2025 compromise of Canadian telecom network devices attributed with high confidence to PRC activity associated with Salt Typhoon. Short bulletin; use the detailed joint advisories for controls.
S05 CrowdStrike — An Analysis of LightBasin Telecommunications Attacks Telecom Linux targeting, eDNS/SSH entry, password spraying, GTP/SIGTRAN tooling, persistence paths, iptables changes, and exact file IOCs. Vendor attribution is moderate confidence; later LIMINAL PANDA naming should not expand the observed facts.
S06 Virus Bulletin — Operation Soft Cell IIS/China Chopper access, maybemimi.exe, Poison Ivy sideloading, Windows tools, and targeted CDR/IMSI/IMEI/MSISDN/location collection. Public actor attribution has been debated; this playbook states behavior more strongly than attribution.
S07 Cisco Talos — Sea Turtle State-sponsored DNS hijacking through registries/registrars and secondary telecom/ISP victims. Not evidence of Open5GS or packet-core exploitation.
S08 Google Cloud/Mandiant — UNC1945 Solaris CVE-2020-14871/EVILSUN, SLAPSTICK PAM backdoor, named paths, SSH tunneling. Report is useful Unix/MSP precedent, not telecom-core attribution.
S09 CISA AA24-038A — PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure Volt Typhoon valid-account/AD behavior, NTDS.dit, event IDs, and likely FortiGate CVE-2022-42475 path in a documented case. Not evidence that Volt Typhoon exploited mobile NFs.
S10 CISA MAR-10435108 — 3CXDesktopApp Trojanized communications application, filenames/config path, sample behavior and hashes. Supply-chain analogue; not a mobile-core campaign.
S11 Viasat — KA-SAT Network Cyber Attack Overview VPN appliance misconfiguration, trusted management-segment access, legitimate commands, destructive modem flash overwrite. Viasat’s report does not supply the actor attribution used by other governments.
S12 Google Project Zero — Multiple Internet-to-Baseband RCEs in Exynos Modems CVE-2023-24033, -26496, -26497, -26498 and no-user-interaction baseband exposure. Vulnerability research, not an APT campaign claim; affected-device scope is product-specific.
S13 NVD — CVE-2025-41067 Open5GS through 2.7.6 NRF unauthenticated reachable assertion leading to registry deletion and abort. NVD record supports affected range and impact; use upstream release notes to plan upgrades.
S14 Open5GS — Release v2.7.6 Official release/version context for the exact image used by the lab. A release note is not a vulnerability advisory.
S15 Open5GS issue #4393 User-reported AMF PathSwitchRequest security-capability validation concern against 2.7.6 and named source location. Open issue/report, no CVE, not reproduced locally; track as unverified.
S16 Open5GS issue #4497 User-reported concurrent NAS Security Mode/handover state-validation concern against 2.7.6. Open issue/report, no CVE, not reproduced locally.
S17 3GPP TS 33.501 specification record and ETSI TS 133 501 v18.6.0 PDF 5G security architecture, SBI transport/service authorization, subscriber privacy, and NF security context. The standard permits protection by other means in defined trusted environments; cleartext alone must be evaluated with the network boundary.
S18 ENISA — Threat Landscape for 5G Networks Authoritative 5G asset, threat-agent, and architectural risk framing. Threat scenarios are not evidence that a named actor performed them.
S19 GSMA — Securing the 5G Era Industry security framing and links to 5G security guidance. Secondary to 3GPP for protocol requirements.
S20 MongoDB Software Lifecycle Schedules MongoDB 4.4 EOL 2024-02-29 and 6.0 EOL 2025-07-31. Lifecycle status is not proof of a specific exploitable CVE.
S21 Kubernetes — Ports and Protocols and Kubernetes Auditing Future container-orchestration exposure and audit evidence requirements. Kubernetes is absent from the active lab.

Agent-assisted research audit

The initial broad collection was executed through agentctl in three workstreams: campaign/actor reporting, telecom protocol/interconnect risks, and infrastructure/cloud/RAN/UE risks. Its verification gate rejected drafts that conflated actors, invented proprietary paths, attached CVEs to the wrong campaigns, or presented architecture scenarios as observed operations. Only claims that survived source-by-source review or were independently checked against the sources above appear as documented facts. The local audit artifact is /Users/tester/.agentctl/orchestrations/b4be7a9872a5.json (three recorded outcomes); it is not a published authority and exists only to make the research process reproducible.

Rejected examples retained as a quality-control record