Malware tied to Chinese hackers has been found infecting telecommunication networks to steal SMS messages from thousands of phone numbers.
The Aboutspying effort comes from a Chinese state-sponsored hacking group called APT 41, according to the cybersecurity firm FireEye. On Thursday, the company published a report on a malware strain from the group that's designed to infect Linux-based servers used by telecommunication carriers to route SMS messages.
Some time this year, FireEye uncovered the malicious computer code on a cluster of servers belonging to an unnamed telecommunication network provider. "During this intrusion, thousands of phone numbers were targeted, to include several high-ranking foreign individuals likely of interest to China," the company told PCMag.
Interestingly, the malware is selective of which SMS messages it will try to collect. The APT 41 hackers pre-programmed it using two lists. The first one searches outs the target, based on the person's phone number and International Mobile Subscriber Identity (IMSI) number. The second list contains certain keywords that the malware will seek to find within the SMS messages. If one of the keywords is found in an SMS message, the malware will then save it in a .CSV file, which the hacker can later extract.
"The keyword list contained items of geopolitical interest for Chinese intelligence collection. Sanitized examples include the names of political leaders, military and intelligence organizations and political movements at odds with the Chinese government," FireEye researchers said in the report.
The suspected Chinese hackers behind the malware also clearly knew who they were targeting, since they had access to both the victims' phone numbers and the IMSI numbers, which is harder to come by. On some Android phones, you can access the IMSI number in the settings function. But the information is primarily used by telecommunication carriers to uniquely identity each subscriber on a cellular network, which suggests the hackers had some serious intel-collecting abilities.
In the same intrusion, the hackers were also found interacting with databases that contained voice call record details, including the time of the call, the duration and the phone numbers involved.
"In 2019, FireEye observed four telecommunication organizations targeted by APT41 actors," the company added in today's report, which refrained from naming the organizations hit. "Further, four additional telecommunications entities were targeted in 2019 by separate threat groups with suspected Chinese state-sponsored associations."
SEE ALSO: Facebook sues WhatsApp developer that allegedly put spyware on phones of journalists and political dissidentsOther security researchers have also noticed suspected Chinese cyberspies infiltrating cellular networks. In June, security firm Cybereason uncovered evidence that Chinese hackers had broken into telecommunication carriers to steal call log and location data from "high-value" individuals across the globe.
The attacks underscore the risk of sending unencrypted information over cellular networks; the content is readable to whoever controls the SMS routing server. For especially sensitive messages, it's a good idea to use a mobile messaging app, such as WhatsApp or Signal, which offer end-to-end encryption.
Topics Cybersecurity Politics
5 super cool name ideas for future cities on Mars'Arrow' Season 5: Marc Guggenheim talks Olicity breakup, fan reaction'Black is not a weapon': Celebrities star in stunning PSA against police brutalityOne of the most popular 360Red alert: new 'Rogue One' trailer drops Thursday'Arrow' Season 5: Marc Guggenheim talks Olicity breakup, fan reactionIf you don't see Moments in your Twitter app anymore, here's whyIt looks like Facebook motivated a lot of people to register to voteGoogle's Pixel smartphones are going on preEsports as seen through the eyes of grandma and grandpaTennis pro Nick Kyrgios apologises after deliberate Shanghai fail9 TV crossovers we'd love to seeJimmy Olsen is Guardian: Supergirl Season 2 makes James a vigilante'Batman' is now chasing creepy clowns in the UKThis is officially Britain's favourite 'Friends' characterToyota recalls over 300,000 Prius cars due to brake problemHow Charlie Brown became a Thanksgiving Day Parade balloon againGoogle's experimental Sprayscape app makes VR more like SnapchatBaby monitor catches baby doing spooky headstand in her sleepThis is how much Instagram fashion bloggers get paid per post Our Shrinking Vocabulary of Landscape Wordle today: Here's the answer and hints for September 16 Staff Picks: DeLillo, Jean Merrill, Cabinet, and More TikTok and Billboard now have their own music chart In Which St. Patrick Drives the Gummy Snakes Into the Sea Wordle today: Here's the answer and hints for September 15 In Alec Soth's New Photographs, a Fresh Take on Public Space 'Quordle' today: See each 'Quordle' answer and hints for September 16, 2023 Avoid This Book: The History and Romance of Elastic Webbing The iPhone 15 Pro is faster, but not by much Make Twitter less toxic by fixing your notifications Dictionary.com selects allyship as word of the year Teens don't need 'finstas' anymore Ron Arad’s Haunting, Flattened Cars Remind of J. G. Ballard Northwestern vs Duke livestream: How to watch live, kickoff time 'The thing that killed' Twitter meme argues everyday tasks are actually famously deadly Photos of 19th Century Alaska Rediscovered Under a Porch Best Garmin deal: Garmin epix smartwatch on sale for $200 off Peter Gizzi on Poetry and Nothingness Ben Tolman’s Grim Paean to the Suburbs