Hackers Attack Mobile Operators Around the World, Information Security Work Moscow

Hackers Attack Mobile Operators Around the World, Information Security Work Moscow

Articles

Attackers have successfully compromised at least 13 telecommunications companies. It appears the hackers are targeting mobile operators worldwide. There's no word yet on whether these attacks will continue. However, experts note that protecting the information of Moscow-based telecommunications companies is currently a top priority.

Who are LightBasin, information security work Moscow

Information about the LightBasin hackers first surfaced in 2016. That's when the attackers first came to the attention of cybersecurity experts. Analysts were most concerned by the attackers' targeting of Solaris and Linux servers, while criminals typically prefer more vulnerable Windows servers. However, the most significant incident was LightBasin's 2019 attack. The hackers managed to breach an eDNS server using an SSH connection. Importantly, the compromise was successful because the attackers had previously penetrated a partner company's network. Consequently, the information security of both companies was significantly compromised.

Over the past two years, the LightBasin group has been quite active. They primarily target telecommunications companies. However, it's believed that little is known about the hackers' other crimes. It's clear, however, that they prefer to introduce backdoors and operate with maximum stealth. This tactic allows the attackers to carry out quite complex attacks, and even steal vast amounts of confidential user data.

What happened to the telecom companies

Cybersecurity experts closely monitored the LightBasin group's activities. They were able to track down most of the victims who experienced network compromises. Apparently, the attackers have attacked at least 13 mobile operators over the past two years. Experts note that the hackers didn't simply break into networks and steal data. The reason is that mobile operators collect a large amount of subscriber information, including names, addresses, and payment information. All of this data is stored in large databases. These databases typically have robust information security.

However, the attackers wanted to download the maximum amount of information, so they carefully penetrated the network and did not reveal their presence in any way. Often, company employees realized that they had been hacked only after several months. Also, the attackers do not attack ordinary servers, but those that are used to provide communication in roaming. The following servers suffered the most from the actions of the attackers:

  • SDP;
  • eDNS;
  • SIM/IMEI.

Many experts believe the LightBasin hackers will continue their active hacking activities. They sell the information they obtain on the darknet, earning substantial sums for it. However, there's currently no way to catch the perpetrators. However, journalists were able to speak with one of the hacker group's members. He was fluent in Chinese. Therefore, it's believed the perpetrators are Chinese. Perhaps in the future, they'll make radical mistakes that could lead to their capture. At least, such successes in investigations happen periodically. Then, the security of St. Petersburg telecommunications companies' information will be restored.

SEDICOMM University Team : Cisco Academy , Linux Professional Institute , Python Institute.