Search
Close this search box.

How hackers are targeting telcos to steal 5G secrets

Share:

Using Huawei Careers page-lookalike site to lure other telcos’ employees

Suspected China-backed hackers are targeting telcos around the globe in an attempt to steal sensitive data, including 5G network information.

The cyber espionage campaign, dubbed Operation Dianxun by security firm McAfee, is actively going after telcos mostly located in Southeast Asia, Europe, and the United States.

At least 23 telcos have been targeted by the campaign, which appears to have been perpetrated by the China-backed group known as Mustang Panda or RedDelta, McAfee said. It has not yet identified any targets in Australia.

Huawei EU Careers (@careers_huawei) | Twitter
The malicious site – designed to look like Huawei’s corporate careers page – delivers malware disguised as a legitimate Flash application to the victim’s machine.

It is unclear how the hackers initially lure victims to their phishing website, McAfee noted.

But once there, the malicious site – designed to look like Huawei’s corporate careers page – delivers malware disguised as a legitimate Flash application to the victim’s machine.

Huawei is not involved itself in the campaign.

The malware then drops a backdoor that gives the hackers remote access to the computer.

The hackers appear to be specifically targeting telco employees with specific knowledge of 5G technology, McAfee said.

The security firm suggested the group’s motivation could relate to decisions by a number of countries to ban the use of Chinese technology in the global 5G rollout.

Mustang Panda has long been linked to attacks that aim to further the Chinese government’s interests; it was recently claimed to be behind a campaign that targeted the Vatican and other Catholic organisations in Hong Kong and Italy. It has also previously targeted thinktanks and non-government organisations that have relationships with the Mongolian government.

Having strong endpoint security controls as well as an alert workforce can help protect networks from these kind of attacks, McAfee said. 

Ahmed Khanji

Ahmed Khanji

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. An emerging thought leader in cybersecurity, Ahmed is an Adjunct Professor at Western Sydney University and regularly contributes to cybersecurity conversations in Australia. As well as his extensive background as a security advisor to large Australian Enterprises, he is a regular keynote speaker and guest lecturer on offensive cybersecurity topics and blockchain.

Contact

Sydney Offices
Level 12, Suite 6
189 Kent Street
Sydney NSW 2000
1300 211 235

Melbourne Offices
Level 13, 114 William Street
Melbourne, VIC 3000
1300 211 235

Perth Offices
Level 32, 152 St Georges Terrace
Perth WA 6000
1300 211 235

Company

Learn more about the team at the forefront of the Australian Cyber Security scene.

About Us →

Meet the Team →

Partnerships →

Learn more about the team at the forefront of the Australian Cyber Security scene.

Career Opportunities →

Internships →

Media appearances and contributions by Gridware and our staff.

See More →

Services

Services

Whether you need us to take care of security for you, respond to incidents, or provide consulting advice, we help you stay protected.

View all services →

Web App Pen. Test Calculator →

Network Pen. Test Calculator →

Governance & Audit

Legal and regulatory protection

Penetration Testing

Uncover system vulnerabilities

Remote Working & Phishing

Fortify your defenses

Cyber Security Strategy

Adaptation to evolving threats

Cloud & Infrastructure

Secure cloud computing solutions

Gridware 360

End-to-end security suite

Gridware Managed Services

Comprehensive & proactive security

Gridware CloudControl
360

Harness the benefits of cloud technology

Gridware Incident Response 24/7

Swift, expert-led incident resolution

Solutions
Resources

Resources

A collection of our published insights, whitepapers, customer success stories and more.

Customer success stories from real Gridware customers. Find out how we have helped others stay on top of their Cyber Security.

Read More →