HomeSecurityLiminal Panda hackers use GSM, SIGTRAN protocols to attack telecommunications

Liminal Panda hackers use GSM, SIGTRAN protocols to attack telecommunications

A Chinese group has been linked to targeted cyberattacks on telecommunications companies in South Asia and Africa since at least 2020, with the aim of gathering intelligence. Cybersecurity firm CrowdStrike tracks Chinese hackers as Liminal Panda and has observed them exploiting telecommunications networks, protocols that support telecommunications (e.g. SIGTRAN, GSM), and various interconnections between providers.

Chinese hackers Liminal Panda GSM, SIGTRAN to attack telecommunications

Attackers use special tools that facilitate illegal access and data extraction.

“Liminal Panda used compromised telecommunications servers to launch attacks on further providers in other geographic regions,” CrowdStrike’s Counter Adversary Operations team reported.

See also: Hackers exploit T-Mobile to extract sensitive information

Chinese hackers Liminal Panda use protocols that support mobile telephony, such as GSM protocols to enable C2, while also developing tools to retrieve mobile subscriber information, call metadata, and text messages (SMS).

Some of the tools used by hackers are SIGTRANslator, CordScan, and PingPong, which have the following capabilities:

  • SIGTRANslator: Designed to send and receive data using SIGTRAN protocols
  • CordScan: A network scanning utility that retrieves data related to common telecommunications protocols, from infrastructures such as the Serving GPRS Support Node (SGSN).
  • PingPong: A backdoor that listens for incoming magic ICMP echo requests and sets up a TCP reverse shell connection to an IP address and port specified in the packet.

Chinese hackers Liminal Panda infiltrate external DNS (eDNS) servers using extremely weak and stolen passwords. They also use TinyShell in conjunction with a publicly available SGSN emulator called sgsnemu (for C2 communications).

“TinyShell is an open-source Unix backdoor used by many hacking groups,” CrowdStrike said. “SGSNs are essentially GPRS network access points, and the emulation software allows the attacker to tunnel traffic through this telecommunications network.”

See also: Hive0145 hackers: Phishing attacks distribute Strela Stealer in Europe

The ultimate goal of the attacks is to collect network telemetry information and subscriber data or to breach other telecommunications companies.

“Liminal Panda hackers typically abuse trust relationships between telecommunications providers and gaps in security policies, and gain access to key infrastructure from external hosts,” the company said.

Liminal Panda hackers use GSM, SIGTRAN protocols to attack telecommunications
Liminal Panda hackers use GSM, SIGTRAN protocols to attack telecommunications

Telecommunications companies: Protecting networks from cyberattacks

Telecommunications companies can protect their networks from cyberattacks by taking some protective measures.

The first and perhaps most critical step is education. Attacks are increasing in frequency and complexity, so it's important for everyone in the company to be informed and understand the risk. Regular training and seminars can help provide this information. Employees should learn the signs of a phishing attack and other tactics used by attackers.

Regularly updating and upgrading software and devices is another important measure to prevent cyberattacks. Out-of-date systems are more vulnerable to attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Next, companies need to use advanced systems security. These systems include intrusion detection and intrusion prevention, and the use of reliable antivirus software is also important.

Additionally, companies can use encryption to protect data transmitted over their networks. Encryption converts data into a form that can only be decoded with a special key.

Telecom companies can also implement access policies to limit who can access networks . This can include requiring access credentials, two-factor authentication, and monitoring user behavior.

See also: USA: Charges against “Snowflake hackers”

Using a firewall and VPN can also be very useful, as well as creating backups to restore stolen or locked files.

Finally, network segmentation is necessary so that an attack cannot spread to all of a company's systems.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS