HomeSecurityHackers are trying to steal 5G information from telecommunications companies

Hackers are trying to steal 5G information from telecommunications companies

Hackers are targeting telecommunications companies around the world with attacks using malicious downloads in an attempt to steal sensitive and confidential data – including information about 5G technology – from victims. The espionage campaign, discovered by security researchers at McAfee , targets telecommunications providers primarily in Europe, the US and Southeast Asia.

According to researchers, a hacking group called “Operation Diànxùn”with ties to China is behind this malicious activity. The group, also known as Mustang Panda and RedDelta, has a history of hacking and espionage campaigns targeting organizations around the world, and now appears to be focusing on compromising telecommunications providers. As reported by ZDNet, it is estimated that at least 23 telecommunications companies have been targeted so far, with the campaign being active since at least August 2020.However, it remains unknown how many of the targets have been successfully compromised.

Hackers are trying to steal 5G information from telecommunications companies
Hackers are trying to steal 5G information from telecommunications companies

Read also: Hackers breached security cameras of Tesla, Cloudflare and others!

Additionally, while the initial means of infection have not been identified, it is known that victims are directed to a malicious phishing domain, which is under the control of the attackers and is used to deliver malware to victims.

See also: USA: More domains used in COVID-19 phishing attacks seized

According to the researchers, this malicious page appears to be a Huawei careers site, designed in such a way as to be indistinguishable from the company's legitimate site. However, the researchers stressed that Huawei is not involved in the espionage campaign.

When users visit the malicious site, they are presented with a malicious Flash application that is used to “attack” the user’s device with Cobalt Strike, ultimately providing attackers with visibility into the device and the ability to steal sensitive and confidential information.

The attacks appear to be specifically designed to target those with knowledge of 5G, while malicious actors steal sensitive or “secret” information related to this technology.

Huawei Loses Out in Singapore 5G Network Provider Bid | Technology News
Hackers are trying to steal 5G information from telecommunications companies

Suggestion: NimzaLoader malware is written in Nim to evade detection

Researchers have linked Operation Diànxùn to previous hacking operations by Chinese groups due to the attacks and malware developed using similar tactics, techniques, and procedures (TTPs). Analysis of the attacks suggests that the campaign is still actively trying to compromise telecommunications companies.

To protect against these types of attacks, companies should properly train their staff so they can recognize when they are being directed to a fake or malicious site – although given how good cyber attackers have become at creating convincing fake sites, this can be difficult. Having a strong strategy for timely application of security updates and patches can also help protect networks from cyberattacks, as a network with the latest updates in place is more resilient when it comes to preventing hackers from exploiting vulnerabilities.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS