{"id":6337,"date":"2024-11-20T14:35:09","date_gmt":"2024-11-20T20:35:09","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/china-liminal-panda-telcos-phone-data"},"modified":"2024-11-20T14:35:09","modified_gmt":"2024-11-20T20:35:09","slug":"chinas-liminal-panda-apt-attacks-telcos-steals-phone-data","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/11\/20\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data\/","title":{"rendered":"China&#8217;s &#8216;Liminal Panda&#8217; APT Attacks Telcos, Steals Phone Data"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltf266ccbaabb2bf11\/673e2e31612f15f9d789b0be\/China_phone-Jakub_Krechowicz-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A newly unveiled threat actor has been spying on mobile phones in Asia and Africa for more than four years.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On Nov. 19, Adam Meyers, senior vice president for counter-adversary operations at CrowdStrike, testified before the US Senate Judiciary Subcommittee on Privacy, Technology, and the Law, on the subject of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.judiciary.senate.gov\/committee-activity\/hearings\/big-hacks-and-big-tech-chinas-cybersecurity-threat\">Chinese cyber threats to critical infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. In the process, he unveiled <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/liminal-panda-telecom-sector-threats\/\">Liminal Panda<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, an advanced persistent threat (APT) hyper-focused on gathering intelligence from telecommunications networks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/sophisticated-threat-group-targeting-telecoms-worldwide-in-spying-campaign\">Since 2020<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Liminal Panda has been using network-based attacks to penetrate and pivot between telcos across geographic regions, gathering SMS messages, unique identifiers, and other metadata associated with mobile phones that could be of political or economic use to the Chinese state.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Liminal Panda's MO\">Liminal Panda&#8217;s MO<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though the aim is to obtain data transmitted over telecommunications channels, a typical Liminal Panda attack might look a lot like any regular network breach.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Your cellphone has a radio that talks to a tower, called a base station controller. And those things are connected, typically, by Internet-type protocols \u2014 network technology,&#8221; Meyers explained. Where some attackers might focus on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/mobile-security\/your-phone-s-5g-connection-is-exposed-to-bypass-dos-attacks\">the towers and their transmissions<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Liminal Panda targets the IT network infrastructure underpinning the system. &#8220;They&#8217;re going to go in through the gateway of the telco, and inside there&#8217;s going to be a lot of traditional IT systems.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once inside a telco&#8217;s network \u2014 so often staffed by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/rockwell-ics-directive-critical-infrastructure-risk-peaks\">outdated legacy systems<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 Liminal Panda has tools for collecting call and text records and other sensitive identifying data on large groups or individual targets. &#8220;When you send a text message from your mobile device, it goes to the tower via SMS that gets passed back into the core of the telco. Routing decisions are made, and then it goes to the next destination,&#8221; he says. Liminal Panda malware acts on that interim step.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To facilitate the exfiltration of that information, the group&#8217;s command-and-control (C2) setup emulates the Global System for Mobile Communications (GSM). GSM is a mobile communications standard that enables calling, texting, and the use of mobile data, and is the most widespread such standard in the world, used in more than 193 countries.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Hopping Between Telcos\">Hopping Between Telcos<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Besides attacking specific telcos, Liminal Panda has also been observed hopping between them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;When you go from one part of the country to another, or when you go from one country to another, you need to have interoperability. And there&#8217;s a lot of infrastructure that goes into making that happen,&#8221; Meyers said. Thing is: The open lines of communication between telecommunications providers, and their infrastructure over long distances, can also be weaponized. &#8220;There are <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/salt-typhoon-tmobile-telecom-attack-spree\">multiple threat actors from China<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> who really understand how telecommunications infrastructure works. They understand how it&#8217;s all connected together, and they&#8217;re able to abuse that in order to go between providers.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though its understanding of industry-specific protocols helps, Liminal Panda also jumps between providers simply by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/savvy-seahorse-hackers-debut-novel-dns-cname-trick\">abusing the Domain Name System (DNS)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. By the end of a campaign, the group has often established multiple, redundant routes for traveling between providers.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"China's End Goals\">China&#8217;s End Goals<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Oppressive governments have long used telecommunications breaches to spy on foreign officials, internal political dissidents, journalists, and academics. &#8220;All of these groups are targeting telcos to perform bulk collection, because it gives them the opportunity to then [hone in on] an individual \u2014 see who they&#8217;re texting, who they&#8217;re calling, who they&#8217;re with,&#8221; Meyers explained.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If Liminal Panda is indeed working on behalf of China, as CrowdStrike assesses with admittedly low confidence, then this sort of spying might have a dual economic benefit as well. In his Senate testimony, Meyers highlighted how major national projects like the Belt and Road Initiative, Made in China 2025, the 2035 Vision, the Global China 2049, and the country&#8217;s regular Five-Year Plans provide impetus for economic espionage.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If you&#8217;re doing a deal in that region, I want to know who you&#8217;re meeting with. I can collect that information, if you&#8217;re sending text messages about the deal,&#8221; he says. &#8220;Or I can intercept them if you&#8217;re meeting with somebody that is politically problematic for me.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/china-liminal-panda-telcos-phone-data\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly unveiled threat actor has been spying on mobile<\/p>\n","protected":false},"author":12,"featured_media":6338,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6337","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/11\/chinas-liminal-panda-apt-attacks-telcos-steals-phone-data-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6337","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6337"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6337\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6338"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6337"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6337"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6337"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}