Hackers pretended to be Huawei to try and steal 5G secrets

Fraud
(Image credit: Shutterstock / Sapann Design)

Researchers have identified an extensive cyberespionage campaign designed to exfiltrate sensitive data from telecoms companies worldwide.

According to the Advanced Threat Research (ATR) team at security company McAfee, attacks have been directed at telecoms firms in Europe, Southeast Asia and the US, likely with the goal of “stealing sensitive or secret information in relation to 5G technology”.

The campaign, named Operation Diànxùn, sees victims infected with malware that has been dressed up as Flash applications. This malware is then used to locate, gather and extract sensitive information stored on the infected network.

“While the initial vector for the infection is not entirely clear, we believe with a medium level of confidence that victims were lured to a domain under control of the threat actor,” explained McAfee in a blog post.

The domain in question, “hxxp://update.careerhuawei.net”, is designed to mimic the legitimate Huawei careers website, which is likely to be visited by members of the telecoms industry. McAfee was at pains to make clear that Huawei itself was not involved in the campaign.

Telecoms industry under attack

Although the identity of the operators is yet to be confirmed, McAfee claims the tactics, techniques and procedures (TTPs) on display are similar to those used by Chinese cybercriminal syndicates RedDelta and Mustang Panda.

Attacks linked with RedDelta were first spotted in the wild in May last year, targeting the Catholic Church and other religious organizations. The shared characteristics of attacks launched by RedDelta and Mustang Panda suggest the two groups may be one and the same, says McAfee.

The security firm believes “with a moderate level of confidence” that the recent attacks on telecoms companies have something to do with restrictions on the use of Chinese 5G equipment put in place by some countries, but offered no further explanation.

It is unclear how many of the 23 affected telecoms providers were successfully compromised as a result of the campaign.

To shield against cyberthreats of this kind, McAfee has advised businesses to employ a multi-layered approach, spanning web vector protection, signature and behavioral analysis, endpoint protection and more.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
China
Chinese hackers targeting Juniper Networks routers, so patch now
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
A computer being guarded by cybersecurity.
Huge cyberattack found hitting vulnerable Microsoft-signed legacy drivers to get past security
China
Chinese hackers develop effective new hacking technique to go after business networks
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring