Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

Chinese Threat Actors Target Global 5G Operators

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,908
Reaction score
943
Points
212
Awards
2
  • trusted user
  • Rich User
Security researchers have discovered a new cyber-espionage campaign targeting global telecoms operators for IP and information relating to 5G.

Named Operation Diànxùn by McAfee, the campaign is likely to be the work of Chinese threat actors RedDelta and Mustang Panda.

“While the initial vector for the infection is not entirely clear, the McAfee ATR team believes with a medium level of confidence that victims were lured to a domain under control of the threat actor, from which they were infected with malware which the threat actor leveraged to perform additional discovery and data collection,” explained McAfee regional solutions architect, Andrea Rossini.

“It is our belief that the attackers used a phishing website masquerading as the Huawei company career page.”

After visiting the fake Huawei phishing page, a victim would unwittingly download malware masquerading as Adobe Flash, which acts as a dropper for a .NET payload. This in turn acts as a tool “to manage and download backdoors to the machine and configure persistence,” Rossini explained.

The final stage of the attack involves creating a backdoor for full remote control of the victim’s system, using Cobalt Strike Beacon and a command-and-control (C&C) server.

The threat actors are thought to have been targeting mobile operators since last summer, in APAC, North America and Europe.

“To defeat targeted threat campaigns like Operation Dianxun, defenders must build an adaptive and integrated security architecture which will make it harder for threat actors to succeed and increase resilience in the business,” concluded Rossini.

In July last year, RedDelta attackers were detected inside the Vatican’s IT network in the run-up to a meeting between the Catholic Church and Beijing focusing on the religion’s status in China.
 
Ad End 1 February 2024
Top