🧔♂️ A friendly human may check it before it goes live. More news here
Singapore telcos hit by cyberattack, no data leaked
Singapore’s four major telcos—Singtel, M1, Starhub, and Simba—were targeted in a cyberattack by the UNC3886 group, a suspected China-linked espionage actor, according to authorities.
The attack, disclosed last year, involved access to some critical systems but did not result in the theft of sensitive customer data or service disruptions.
The cyberattack used advanced techniques, including zero-day exploits and rootkits, to gain persistent access while evading detection.
The Singapore government launched Operation Cyber Guardian, involving over 100 personnel from six agencies, to contain the breach and strengthen cybersecurity measures.
Authorities said the attack was limited and did not cause widespread damage.
🔗 Source: CNA
🧠 Food for thought
Implications, context, and why it matters.
Attacker tools focused on stealth and messy forensics
- The intrusion used rootkits (malware that hides an intruder and supports long-term access) plus other advanced techniques, which helped evade detection 1.
- One UNC3886 backdoor,
lmpad, runs a script that turns off logging before hands-on work on a router, then turns it back on afterward 2. It can also block Simple Network Management Protocol (SNMP) traps, which are automated alerts used in network monitoring, and likely prevents audit logging for some management-daemon events 2. - Mandiant wrote that UNC3886 kept “layered persistence” on network devices, hypervisors (software that runs virtual machines), and virtual machines so access stayed available if one path failed 3.
Singapore telco breach raises wider network infrastructure risks
- CSA and IMDA said the attackers used a zero-day exploit to get past a perimeter firewall at a telco, then deployed rootkits for persistence and stealth 1. The sources here do not name the firewall vendor or mention end-of-life systems 1.
- In other operations, Mandiant wrote that UNC3886 went after end-of-life Juniper MX routers (carrier-grade routers commonly used in telecom networks) running end-of-life hardware and software, which left openings for espionage actors 2.
- Singapore’s response includes Operation Cyber Guardian, a whole-of-government effort with more than 100 people from six government agencies, and authorities said it limited attacker activity 1.
Recent Singtel developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




