logo

Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021

ID: fe84c74c-5773-5dbc-9a3b-c073c6b8af2e

STIX ID: report--fe84c74c-5773-5dbc-9a3b-c073c6b8af2e

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-20

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Symantec/Broadcom reported a multi-year Chinese-linked cyber-espionage campaign (active since ~2020–2021) that compromised multiple telecom operators, a telecom services provider, and a university in Asia. Attackers used custom backdoors (COOLCLIENT, QUICKHEAL, RainyDay), port scanners, and credential theft via Windows Registry hive dumping; tooling overlaps with Mustang Panda, RedFoxtrot, and Naikon suggest nation-state intelligence-gathering or potential disruptive targeting of telecom infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.