Related Threat Clusters
-
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks
A China-linked threat actor known as Red Menshen has been conducting a long-term espionage campaign targeting global telecommunications networks using a stealthy Linux kernel backdoor called BPFdoor. This malware…
16 articles · Updated March 26, 2026 -
Rapid7 Reports State-Sponsored Espionage in Global Telecoms
Rapid7 Labs has identified a sustained espionage campaign by a China-nexus threat actor, Red Menshen, targeting global telecommunications infrastructure. The research, titled 'Sleeper Cells in the Telecom Backbone,'…
4 articles · Updated March 26, 2026 -
Showboat Malware Targets Telecoms in China-Aligned Cyber Espionage Campaign
A new Linux malware family named Showboat has been discovered, targeting telecommunications firms primarily in the Middle East and Central Asia since mid-2022. Researchers from Lumen's Black Lotus Labs and PwC…
9 articles · Updated May 21, 2026 -
Cybersecurity Spending Surges Amid Rising AI Threats and Regulatory Pressures
In 2026, global cybersecurity spending is projected to reach $244 billion, driven by tighter regulations and the emergence of AI-driven vulnerabilities. The U.S. Intelligence Community's 2026 Annual Threat Assessment…
2 articles · Updated March 31, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
KT Corp Fined ₩53.97 Billion for Femtocell Breach and Evidence Tampering
KT Corp was fined ₩53.97 billion (approximately $37.6 million) by South Korea's privacy regulator for failing to secure its femtocell system, allowing unauthorized access to its mobile network. The breach began in…
8 articles · Updated July 30, 2026 -
New BPFDoor Malware Variants Target Telecom Networks
Seven new variants of the BPFDoor malware have been identified, enhancing stealth in compromising major telecommunication networks. These variants utilize stateless command-and-control (C2) routing and employ techniques…
2 articles · Updated April 8, 2026 -
Royal Navy Drones Found Sending Data to China Amid Security Concerns
Cameras on Royal Navy K3 Scout drones were discovered sending 'heartbeat communications' to a device in China during a routine cyber vulnerability assessment. The Ministry of Defence (MoD) confirmed that the…
23 articles · Updated August 10, 2026 -
BPFDoor and Symbiote Rootkits Target Linux Systems via eBPF Exploits
BPFDoor and Symbiote rootkits are exploiting vulnerabilities in eBPF filters to compromise Linux systems. These advanced threats are designed to evade detection and have raised alarms in the cybersecurity community.…
3 articles · Updated December 3, 2025 -
KT Corp Concealed Malware Infections on 43 Servers, Leading to Data Breach
KT Corp., South Korea's second-largest mobile carrier, concealed malware infections on 43 servers from March to July 2024. A government-led investigation revealed that the company failed to report these security…
3 articles · Updated November 7, 2025
Recent Intelligence Reports
- Spy cameras on Navy drones used by UK's elite special forces sending signals to China as ... — Lbc · August 10, 2026
- T1027 — attack.mitre.org · August 7, 2026
- Linux Berkeley Packet Filter — sandflysecurity.com · July 30, 2026
- KT had deployed thousands of femtocells across its network using shared certificates stored in plaintext on each device, without root password protection and with SSH enabled for remote access — www.theregister.com · July 30, 2026
- fined KT Corp. ₩53.97 billion (approximately $37.6 million) — www.koreaherald.com · July 30, 2026
- Korea Fines KT for Rogue Femtocell Breach, Refers Both Carriers to Police — Techtimes · July 30, 2026
- KT hit with W54b penalty over data breach — M.Koreaherald · July 30, 2026
- Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks — Darkreading · May 21, 2026