Mobility APT Research Source Ledger
Mobility APT Research Source Ledger
Source policy
Campaign claims prefer government advisories or the original incident-response report. Technical requirements prefer standards bodies and official product documentation. NVD is used for the confirmed Open5GS CVE record; upstream GitHub issues are labeled unverified and are not promoted to vulnerabilities without reproduction.
| ID | Source | Supports | Limits |
|---|---|---|---|
| S01 | CISA/NSA/FBI et al. — Enhanced Visibility and Hardening Guidance for Communications Infrastructure | PRC compromise of major telecom providers; management isolation, AAA, ACL, VPN, TLS, logging, and configuration-baseline guidance. | Guidance says no novel activity was observed; it is not a mobile-core CVE list. |
| S02 | CISA AA25-239A — Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide | Global backbone/edge targeting, router configuration access, virtualized environments, and actor-label overlap. | Alias overlap is not exact actor equivalence. |
| S03 | FBI — Seeking Tips About PRC Targeting of U.S. Telecommunications | Theft of call-data logs, limited private communications, and copied information associated with select court-ordered requests. | Does not name a specific LI/CALEA product, file, or exploit. |
| S04 | FBI/CSE — PRC Cyber Threat Activity Targeting Telecommunications | 2025 compromise of Canadian telecom network devices attributed with high confidence to PRC activity associated with Salt Typhoon. | Short bulletin; use the detailed joint advisories for controls. |
| S05 | CrowdStrike — An Analysis of LightBasin Telecommunications Attacks | Telecom Linux targeting, eDNS/SSH entry, password spraying, GTP/SIGTRAN tooling, persistence paths, iptables changes, and exact file IOCs. | Vendor attribution is moderate confidence; later LIMINAL PANDA naming should not expand the observed facts. |
| S06 | Virus Bulletin — Operation Soft Cell | IIS/China Chopper access, maybemimi.exe, Poison Ivy sideloading, Windows tools, and targeted CDR/IMSI/IMEI/MSISDN/location collection. |
Public actor attribution has been debated; this playbook states behavior more strongly than attribution. |
| S07 | Cisco Talos — Sea Turtle | State-sponsored DNS hijacking through registries/registrars and secondary telecom/ISP victims. | Not evidence of Open5GS or packet-core exploitation. |
| S08 | Google Cloud/Mandiant — UNC1945 | Solaris CVE-2020-14871/EVILSUN, SLAPSTICK PAM backdoor, named paths, SSH tunneling. | Report is useful Unix/MSP precedent, not telecom-core attribution. |
| S09 | CISA AA24-038A — PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure | Volt Typhoon valid-account/AD behavior, NTDS.dit, event IDs, and likely FortiGate CVE-2022-42475 path in a documented case. |
Not evidence that Volt Typhoon exploited mobile NFs. |
| S10 | CISA MAR-10435108 — 3CXDesktopApp | Trojanized communications application, filenames/config path, sample behavior and hashes. | Supply-chain analogue; not a mobile-core campaign. |
| S11 | Viasat — KA-SAT Network Cyber Attack Overview | VPN appliance misconfiguration, trusted management-segment access, legitimate commands, destructive modem flash overwrite. | Viasat’s report does not supply the actor attribution used by other governments. |
| S12 | Google Project Zero — Multiple Internet-to-Baseband RCEs in Exynos Modems | CVE-2023-24033, -26496, -26497, -26498 and no-user-interaction baseband exposure. | Vulnerability research, not an APT campaign claim; affected-device scope is product-specific. |
| S13 | NVD — CVE-2025-41067 | Open5GS through 2.7.6 NRF unauthenticated reachable assertion leading to registry deletion and abort. | NVD record supports affected range and impact; use upstream release notes to plan upgrades. |
| S14 | Open5GS — Release v2.7.6 | Official release/version context for the exact image used by the lab. | A release note is not a vulnerability advisory. |
| S15 | Open5GS issue #4393 | User-reported AMF PathSwitchRequest security-capability validation concern against 2.7.6 and named source location. | Open issue/report, no CVE, not reproduced locally; track as unverified. |
| S16 | Open5GS issue #4497 | User-reported concurrent NAS Security Mode/handover state-validation concern against 2.7.6. | Open issue/report, no CVE, not reproduced locally. |
| S17 | 3GPP TS 33.501 specification record and ETSI TS 133 501 v18.6.0 PDF | 5G security architecture, SBI transport/service authorization, subscriber privacy, and NF security context. | The standard permits protection by other means in defined trusted environments; cleartext alone must be evaluated with the network boundary. |
| S18 | ENISA — Threat Landscape for 5G Networks | Authoritative 5G asset, threat-agent, and architectural risk framing. | Threat scenarios are not evidence that a named actor performed them. |
| S19 | GSMA — Securing the 5G Era | Industry security framing and links to 5G security guidance. | Secondary to 3GPP for protocol requirements. |
| S20 | MongoDB Software Lifecycle Schedules | MongoDB 4.4 EOL 2024-02-29 and 6.0 EOL 2025-07-31. | Lifecycle status is not proof of a specific exploitable CVE. |
| S21 | Kubernetes — Ports and Protocols and Kubernetes Auditing | Future container-orchestration exposure and audit evidence requirements. | Kubernetes is absent from the active lab. |
Agent-assisted research audit
The initial broad collection was executed through agentctl in three workstreams: campaign/actor reporting, telecom protocol/interconnect risks, and infrastructure/cloud/RAN/UE risks. Its verification gate rejected drafts that conflated actors, invented proprietary paths, attached CVEs to the wrong campaigns, or presented architecture scenarios as observed operations. Only claims that survived source-by-source review or were independently checked against the sources above appear as documented facts. The local audit artifact is /Users/tester/.agentctl/orchestrations/b4be7a9872a5.json (three recorded outcomes); it is not a published authority and exists only to make the research process reproducible.
Rejected examples retained as a quality-control record
- No invented SEPP API paths, lawful-intercept filenames, vendor database table names, or MITRE technique IDs.
- No reassignment of UNC1945’s Solaris CVE-2020-14871 to LIMINAL PANDA.
- No assertion that Salt Typhoon used a named CALEA platform.
- No assertion that Volt Typhoon exploited this mobile core.
- No mapping of Open5GS GitHub reports to confirmed CVEs.
- No claim that a lab trust configuration is a vulnerability in the Open5GS product.