Denmark's cybersecurity agency has issued a warning about increased state-sponsored campaigns targeting European telecom companies.
The threat assessment in Denmark has raised the cyber espionage threat level for its telecom sector from medium to high due to growing threats across Europe.
The Danish Social Security Agency highlighted risks including cyber espionage, destructive attacks, cyber activism, and criminal hackers targeting the telecom sector.
State actors aim to access user data, monitor communications, and potentially launch cyber or physical attacks by targeting telecom providers for espionage.
Hackers have demonstrated advanced technical capabilities in targeting telecommunications infrastructure and protocols abroad.
China-linked APT group Salt Typhoon has been targeting global telecom providers, breaching networks using vulnerabilities in Cisco devices.
Salt Typhoon group compromised U.S. telecom firms by exploiting flaws like CVE-2023-20198 and CVE-2023-20273, maintaining persistence with GRE tunnels.
Telecoms such as Lumen, AT&T, and Verizon reported securing networks after cyberespionage attempts by Salt Typhoon, emphasizing the ongoing threat.
Other China-linked groups like Light Basin have targeted mobile carrier networks globally, compromising calling records and text messages from telecom companies.
CrowdStrike researchers highlighted the deep knowledge of telecommunication network architectures exhibited by threat actors, using protocols like GTP for malicious activities.