A Chinese group has been linked to targeted cyberattacks on telecommunications companies in South Asia and Africa since at least 2020, with the aim of gathering intelligence. Cybersecurity firm CrowdStrike tracks Chinese hackers as Liminal Panda and has observed them exploiting telecommunications networks, protocols that support telecommunications (e.g. SIGTRAN, GSM), and various interconnections between providers.

Attackers use special tools that facilitate illegal access and data extraction.
“Liminal Panda used compromised telecommunications servers to launch attacks on further providers in other geographic regions,” CrowdStrike’s Counter Adversary Operations team reported.
See also: Hackers exploit T-Mobile to extract sensitive information
Chinese hackers Liminal Panda use protocols that support mobile telephony, such as GSM protocols to enable C2, while also developing tools to retrieve mobile subscriber information, call metadata, and text messages (SMS).
Some of the tools used by hackers are SIGTRANslator, CordScan, and PingPong, which have the following capabilities:
- SIGTRANslator: Designed to send and receive data using SIGTRAN protocols
- CordScan: A network scanning utility that retrieves data related to common telecommunications protocols, from infrastructures such as the Serving GPRS Support Node (SGSN).
- PingPong: A backdoor that listens for incoming magic ICMP echo requests and sets up a TCP reverse shell connection to an IP address and port specified in the packet.
Chinese hackers Liminal Panda infiltrate external DNS (eDNS) servers using extremely weak and stolen passwords. They also use TinyShell in conjunction with a publicly available SGSN emulator called sgsnemu (for C2 communications).
“TinyShell is an open-source Unix backdoor used by many hacking groups,” CrowdStrike said. “SGSNs are essentially GPRS network access points, and the emulation software allows the attacker to tunnel traffic through this telecommunications network.”
See also: Hive0145 hackers: Phishing attacks distribute Strela Stealer in Europe
The ultimate goal of the attacks is to collect network telemetry information and subscriber data or to breach other telecommunications companies.
“Liminal Panda hackers typically abuse trust relationships between telecommunications providers and gaps in security policies, and gain access to key infrastructure from external hosts,” the company said.

Telecommunications companies: Protecting networks from cyberattacks
Telecommunications companies can protect their networks from cyberattacks by taking some protective measures.
The first and perhaps most critical step is education. Attacks are increasing in frequency and complexity, so it's important for everyone in the company to be informed and understand the risk. Regular training and seminars can help provide this information. Employees should learn the signs of a phishing attack and other tactics used by attackers.
Regularly updating and upgrading software and devices is another important measure to prevent cyberattacks. Out-of-date systems are more vulnerable to attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Next, companies need to use advanced systems security. These systems include intrusion detection and intrusion prevention, and the use of reliable antivirus software is also important.
Additionally, companies can use encryption to protect data transmitted over their networks. Encryption converts data into a form that can only be decoded with a special key.
Telecom companies can also implement access policies to limit who can access networks . This can include requiring access credentials, two-factor authentication, and monitoring user behavior.
See also: USA: Charges against “Snowflake hackers”
Using a firewall and VPN can also be very useful, as well as creating backups to restore stolen or locked files.
Finally, network segmentation is necessary so that an attack cannot spread to all of a company's systems.
Source: thehackernews.com
