Hackers using telecoms like 'global spy system': report

Published June 25, 2019
A cellular site equipment in London. ─ AP
A cellular site equipment in London. ─ AP

An ambitious group of state-backed hackers has been burrowing into telecommunications companies in order to spy on high-profile targets across the world, a US cybersecurity firm said in a report published Tuesday.

Boston-based Cybereason said the tactic gave hackers sweeping access to VIPs' call records, location data and device information effectively turning the targets' cellular providers against them.

Cybereason Chief Executive Lior Div said that because customers weren't directly targeted, they might never discover their every movement was being monitored by a hostile power.

The hackers had turned the affected telecoms into "a global surveillance system", Div said in a telephone interview ahead of the report's launch. "Those individuals don't know they were hacked because they weren't."

Div, who is presenting his findings at the Cyber Week conference in Tel Aviv, provided scant details about who was targeted in the hack, saying that Cybereason had been called in to help an unidentified cellular provider last year and discovered that the hackers had broken into the firm's billing server, where call records are logged.

The hackers were using their access to extract the call data of "around 20" customers, Div said.

Who those people were he declined to say, describing them as mainly coming from the world of politics and the military. He said the information was so sensitive he would not provide even the vaguest idea of where they or the telecom were located. "I'm not even going to share the continent," he said.

Cybereason said the compromise of its customer eventually led it to about 10 other firms that had been hit in a similar way, with hackers stealing data in 100 gigabyte chunks. Div said that, in some cases, the hackers appeared to be tracking non-phone devices, such as cars or smartwatches.

The GSMA, which represents mobile operators worldwide, did not immediately return a message seeking comment.

Who might be behind such hacking campaigns is often a fraught question in a world full of digital false flags. Cybereason said that all the signs pointed to APT10 the nickname often applied to a notorious China-linked cyberespionage group.

But Div said the clues they found were so obvious he and his team sometimes wondered whether they might have been left on purpose. "I thought: 'Hey, just a second, maybe it's somebody who wants to blame APT10,'" he said.

Chinese authorities have routinely denied responsibility for hacking operations. The Chinese Embassy in London did not immediately return a message seeking comment.

Div said that it was unclear whether the ultimate targets of the espionage operation were warned, saying Cybereason had left it to the telecom firms to notify their customers. Div added that he had been in touch with "a handful" of law enforcement agency about the matter, although he did not say which ones.

The FBI in Washington did not immediately return a message seeking comment.

Follow Dawn Business on Twitter, LinkedIn, Instagram and Facebook for insights on business, finance and tech from Pakistan and across the world.

Opinion

The Dar story continues

The Dar story continues

One wonders what the rationale was for the foreign minister — a highly demanding, full-time job — being assigned various other political responsibilities.

Editorial

Wheat protests
Updated 01 May, 2024

Wheat protests

The government should withdraw from the wheat trade gradually, replacing the existing market support mechanism with an effective new one over the next several years.
Polio drive
01 May, 2024

Polio drive

THE year’s fourth polio drive has kicked off across Pakistan, with the aim to immunise more than 24m children ...
Workers’ struggle
Updated 01 May, 2024

Workers’ struggle

Yet the struggle to secure a living wage — and decent working conditions — for the toiling masses must continue.
All this talk
Updated 30 Apr, 2024

All this talk

The other parties are equally legitimate stakeholders in the country’s political future, and it must give them due consideration.
Monetary policy
30 Apr, 2024

Monetary policy

ALIGNING its decision with the trend in developed economies, the State Bank has acted wisely by holding its key...
Meaningless appointment
30 Apr, 2024

Meaningless appointment

THE PML-N’s policy of ‘family first’ has once again triggered criticism. The party’s latest move in this...