HomeSecurityHackers exploit T-Mobile to extract sensitive information

Hackers exploit T-Mobile to extract sensitive information

American telecommunications company T-Mobile confirmed that it was the target of Chinese hackers, who sought access to sensitive information.

hackers T-Mobile breach

The hackers, known as Salt Typhoon, breached the company as part of a “month-long campaign” to collect mobile phone communications from “high-value intelligence targets.” The nature of the information likely obtained remains unclear.

See related: Salt Typhoon group hacked US telecom companies

“T-Mobile is closely monitoring this hacking attack and, to date, our systems and data have not been significantly impacted. We have no evidence of any impact to customer information,” a company spokesperson told The Wall Street Journal. “We will continue to monitor this matter, working with our peers and the appropriate authorities.”.

With this latest development, T-Mobile joins a list of major organizations including AT&T, Verizon and Lumen Technologies that have been targeted in a widespread cyberespionage campaign. Reports have not documented the success of these attacks or whether any malware. Salt Typhoon’s access to Americans’ cellphone data was previously revealed by Politico. The US government said its ongoing investigation has uncovered a “broad and significant” breach by the People’s Republic of China (PRC).

Read also: USA: Chinese hackers Salt Typhoon breached Internet service providers

Chinese actors have allegedly hacked into the networks of multiple telecommunications companies to steal customer call-recording data, intercept private communications of individuals with government or political activity, and copy specific information subject to U.S. law enforcement requests. It warns that the scope of these breaches could increase as the investigation continues.

The most sophisticated infection sequence involves exploiting vulnerable Microsoft Exchange servers to install the China Chopper web shell, which is used to deliver Cobalt Strike, Zingdoor, and Snappybee. These backdoors are delivered either via a command-and-control server or by using cURL to download from controlled servers.

The collection of documents is done via RAR and extracted using cURL, sending data to anonymous file sharing services. Programs such as NinjaCopy and PortScan are used for credential extraction and network. Persistence is achieved through scheduled tasks. In one case, Salt Typhoon is believed to have reused a victim proxy to forward traffic to the real C2 server, hiding the malicious traffic.

T-Mobile hackers

See more: Salt Typhoon hack: Government employees urged to limit phone use

Trend Micro noted that one of the infected machines hosted the Cryptmerlin and FuxosDoor, designed to execute commands. “Our analysis reveals a sophisticated and adaptive malicious actor that uses various tools and backdoors, offering technical capabilities and a strategic approach to maintaining access to compromised environments,” the researchers said. “Earth Estries has demonstrated an understanding of their targets’ environments, creating a complex attack that is difficult to detect and mitigate.”

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS