 ,
,A cyber group breached telecoms across Southeast Asia, deploying advanced tracking tools instead of stealing data. Palo Alto Networks' Unit 42 assesses the activity as 'associated with a nation-state nexus'.
A hacking group gained covert access to telecom networks across Southeast Asia, most likely to track users' locations, according to cybersecurity analysts at Palo Alto Networks' Unit 42.
The campaign lasted from February to November 2024.
Instead of stealing data or directly communicating with mobile devices, the hackers deployed custom tools such as CordScan, designed to intercept mobile network protocols like SGSN. These methods suggest the attackers focused on tracking rather than data theft.
Unite42 assessed the activity 'with high confidence' as 'associated with a nation state nexus'. The Unit notes that 'this cluster heavily overlaps with activity attributed to Liminal Panda, a nation state adversary tracked by CrowdStrike'; according to CrowdStrike, Liminal Panda is considered to be a 'likely China-nexus adversary'. It further states that 'while this cluster significantly overlaps with Liminal Panda, we have also observed overlaps in attacker tooling with other reported groups and activity clusters, including Light Basin, UNC3886, UNC2891 and UNC1945.'
The attackers initially gained access by brute-forcing SSH credentials using login details specific to telecom equipment.
Once inside, they installed new malware, including a backdoor named NoDepDNS, which tunnels malicious data through port 53 - typically used for DNS traffic - in order to avoid detection.
To maintain stealth, the group disguised malware, altered file timestamps, disabled system security features and wiped authentication logs.
 
       
              
         
     
    




















