Sunday, October 4, 2026

Chinese Hackers Target Singapore Telecoms in Edge Device Compromise Campaign

A massive, eleven-month campaign to root out sophisticated attackers from the nation’s critical infrastructure.

The Cyber Security Agency of Singapore (CSA) and the Infocomm Media Development Authority (IMDA) revealed details of “Operation CYBER GUARDIAN,” a multi-agency effort to defend the country’s four major telecommunications providers Singtel, StarHub, M1, and SIMBA from a persistent cyber espionage campaign.

The attacks have been attributed to UNC3886, an Advanced Persistent Threat (APT) group known for its deep technical capabilities and connections to Chinese espionage activities.

The group launched a targeted and deliberate campaign to infiltrate the networks that power Singapore’s digital economy.

Technical Breakdown: Zero-Days and Rootkits

According to investigations, UNC3886 utilized a zero-day exploit to breach the telcos’ perimeter firewalls. A zero-day exploit attacks a software vulnerability that is unknown to the vendor, meaning there was no patch available to stop the initial entry.

Once inside the network, the hackers used advanced stealth techniques to remain undetected.

They deployed rootkits malicious software designed to give attackers privileged access to a computer while hiding their presence from standard security tools.

This allowed them to maintain a foothold in the system for months, making it extremely difficult for defenders to spot them without comprehensive, deep-dive forensic checks.

The attackers did not rely on simple phishing emails. Instead, they targeted the “edge devices” the hardware that sits on the perimeter of a network, such as firewalls and routers.

Operation CYBER GUARDIAN

The breach was first detected by the telcos, triggering a massive Whole-of-Government response.

Operation CYBER GUARDIAN involved over 100 cyber defenders from agencies including the CSA, the Digital and Intelligence Service (DIS), and the Internal Security Department (ISD).

The operation focused on containing the breach and analyzing the attackers’ movements. While UNC3886 managed to exfiltrate a small amount of technical network data likely to help them map the system for further attacks the damage was successfully limited.

Authorities confirmed three key points regarding the impact:

  1. No Service Disruption: Internet and phone services were not interrupted.
  2. No Data Leak: There is no evidence that customer personal data or sensitive records were stolen.
  3. Access Revoked: Defenders have closed the security loopholes and expelled the attackers from the networks.

While Operation CYBER GUARDIAN was a success, officials warn that the threat is not over. Telecommunications networks remain a primary target for state-sponsored actors seeking to undermine national security.

Minister for Digital Development and Information, Josephine Teo, praised the defenders but urged against complacency.

The CSA is continuing to work with telcos to conduct joint threat hunting and penetration testing, ensuring that as attackers evolve their methods, Singapore’s defenses evolve faster.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

A newly identified IoT botnet, Cling, disguises its command-and-control...

Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands

Microsoft Threat Intelligence has identified a ClickFix campaign in...

Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands

GitLab has issued emergency security updates for a critical...

AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials

AWS has released security fixes for four vulnerabilities affecting...

Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update

Citrix NetScaler administrators report repeated appliance crashes and forced...

Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF

A newly released PlayStation 5 jailbreak chain, called Relapse,...

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root

Two critical vulnerabilities in the open-source Zammad helpdesk and...

Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History database contains a lesser-known tagging artifact that...

Related Articles

Recent News