Latest / Tech Talks With Kinsoft / UNC3886 – China-Linked Espionage Hits Singapore's Telcos
Transcript
- 0:00Imagine opening your phone right now. You know,
- 0:02you look at it, you have full bars. Yeah, your
- 0:04texts are sending instantly. Exactly. The internet
- 0:07is lightning fast. Everything just looks and
- 0:09feels completely perfect. Right. But what if
- 0:12I told you that for the last year or so, elite
- 0:15hackers have been, well, quietly sitting inside
- 0:19your mobile carrier, just watching the data flow.
- 0:22Wow. And their ultimate goal. was to make sure
- 0:24you literally never noticed a single thing. That
- 0:27is entirely the point of what we're looking at
- 0:29today. Right. Welcome to Tech Talks with Kinsoft.
- 0:32Today we are exploring a massive, really highly
- 0:35complex cyber espionage campaign that targeted
- 0:39the absolute backbone of Singapore's telecommunications
- 0:42infrastructure. It's a huge story. It really
- 0:45is. We're looking at a threat actor that infiltrated
- 0:47four major telcos, all without breaking anything.
- 0:50We're going to talk about the incredibly advanced
- 0:51tools they use to pull off this silent invasion
- 0:55and what this quiet siege reveals about the future
- 0:59of global cyber operations. The details coming
- 1:02out of this incident, they really subvert everything
- 1:05we're usually taught to expect from a cyber attack.
- 1:08Yeah, absolutely. You know, we're sort of conditioned
- 1:10to look for flashing red screens or locked files
- 1:15or, I don't know, massive Internet outages. Ransomware
- 1:19notes, right? Exactly, ransomware notes. But
- 1:21the reality we're looking at today provides this
- 1:23masterclass in how modern state -level cyber
- 1:27operations actually function in the real world.
- 1:31Prioritizing stealth above all else. Right. So
- 1:34the news broke via a statement from the Cybersecurity
- 1:36Agency of Singapore, or the CSA. Yeah. And they
- 1:40laid out the facts regarding a threat actor known
- 1:42to the cybersecurity community as UNC3886. Catchy
- 1:46name. Right. Very catchy. So the CSA described
- 1:48this as a deliberate, targeted, and well -planned
- 1:51attack. And they didn't just hit one vulnerable
- 1:53company. No, they didn't. They hit all four of
- 1:56Singapore's top telecommunications providers.
- 1:58So that's Singtel, Starhub, M1 and Simba Telecom.
- 2:03And to really understand the staggering scope
- 2:05of hitting all four top providers, you have to
- 2:08understand the adversary here. OK, let's get
- 2:10into that. Who is UNC 38886? Well, they are not
- 2:14a loose collective of amateur hackers looking
- 2:16for a quick ransom payout, right? They're not
- 2:18kids in a basement. Exactly. Cybersecurity researchers
- 2:21at Google, specifically their cybersecurity unit
- 2:24Mandiant, they've tracked this group pretty extensively.
- 2:27And they categorize them as highly disciplined
- 2:29and... Well, incredibly stealthy. And they link
- 2:33UNC 3886 as an espionage group likely working
- 2:37on behalf of China. OK. And we should definitely
- 2:40state clearly for you listening that, you know,
- 2:43we are just reporting the findings from these
- 2:44specific cybersecurity firms and government incident
- 2:47responders. Right. Absolutely. Because Beijing
- 2:50routinely and repeatedly. denies conducting any
- 2:54cyber espionage operations abroad. Yeah, their
- 2:57official stance is a very consistent denial of
- 2:59these kinds of state -backed hacking allegations.
- 3:02And, you know, the Chinese embassy in Singapore,
- 3:04they didn't publicly respond to the specific
- 3:07disclosure. So our focus is strictly on the technical
- 3:09forensics. Just the mechanics of the event itself.
- 3:11Right. And those technical forensics, they point
- 3:14to a group. that operates with a very, very specific
- 3:18strategic mindset. They are not looking to make
- 3:20noise. Which brings up a really glowing question.
- 3:23Yeah. If a highly advanced group manages to compromise
- 3:27the core infrastructure of an entire country's
- 3:30top four phone companies. The literal bedrock
- 3:34of their communication. Exactly. Why didn't the
- 3:36Internet go down? I mean if you have the keys
- 3:39to the castle across four different networks,
- 3:41why not turn off the lights and cause some chaos?
- 3:44Well, because causing chaos alerts the administrators
- 3:47that you are inside the network. Oh. Yeah. We
- 3:50are so used to seeing, you know, ransomware gangs
- 3:53locking up hospital databases. Right. Or denial
- 3:56of service attacks taking down banking websites.
- 3:58Those attacks are allowed by design. Because
- 4:01they want you to know they're there. Right. Because
- 4:02they demand attention or extortion. They want
- 4:04to get paid. Got it. But if your goal is long
- 4:07term intelligence gathering, the absolute worst
- 4:09thing you can do is break a server or disrupt
- 4:13a routing protocol. Because a dropped connection
- 4:15triggers a support ticket. Exactly. A support
- 4:18ticket brings a network engineer to investigate.
- 4:20That engineer pokes around and then they find
- 4:22your malware. So silence is literally the only
- 4:25way to maintain persistence. So the methodology
- 4:28requires completely avoiding the standard alarms.
- 4:31Yes. And UNC386 achieved this. By bypassing standard
- 4:36malware entirely. OK, so what do they use? Well,
- 4:39you won't find them using a generic Trojan. You
- 4:41might, you know, accidentally download from a
- 4:43phishing email. They specifically deployed zero
- 4:46day vulnerabilities in foundational network systems.
- 4:49Right. Zero days. And just to underscore the
- 4:51gravity of that for anyone, you know, tracking
- 4:53the economics of cyber warfare. Yeah. A zero
- 4:55day is a vulnerability. completely unknown to
- 4:59the software vendor. Hence the name. You have
- 5:01zero days to patch it. Right. There is no patch
- 5:03because the creator literally doesn't know the
- 5:05flaw exists. Exactly. And developing or purchasing
- 5:08a reliable zero day, I mean, that can cost millions
- 5:11of dollars in the exploit market. Oh, absolutely.
- 5:14Millions. So you don't burn a multi -million
- 5:16dollar asset just to deface a website. No, you
- 5:20burn it to gain a master key. Wow. And UNC3886,
- 5:24they didn't just target one type of software.
- 5:27They deployed zero days across a variety of foundational
- 5:30systems. Like what kind of systems? Well, vulnerabilities
- 5:33in Fortinet firewalls, VMware virtualized environments,
- 5:38and even custom backdoors deployed on Juniper
- 5:41routers. Okay, so these are the heavy -duty enterprise
- 5:43-grade systems that literally route the Internet
- 5:47and build the perimeter defenses for massive
- 5:50corporations. Yep. They went straight for the
- 5:53load -bearing wall. It sounds like instead of
- 5:55kicking down the front door and tripping the
- 5:56alarm, the burglars sort of acquired a hidden
- 6:01blueprint to the building. Right. Slipped into
- 6:03the ventilation shafts and built an entirely
- 6:06hidden room where the security guards literally
- 6:08aren't capable of patrolling. That ventilation
- 6:11shaft analogy works perfectly, actually, when
- 6:13we talk about targeting VMware. Okay, break that
- 6:15down for me. Let's look at the mechanics of why
- 6:17VMware is such a critical target. In a modern
- 6:19telco, they aren't running thousands of individual
- 6:21physical computers, right? No, of course not.
- 6:24They run massive server racks and they use software
- 6:26called a hypervisor. like VMware, to create hundreds
- 6:30of virtual machines on a single physical box.
- 6:33Right. And the hypervisor sits underneath the
- 6:35operating systems. Meaning it controls the environment
- 6:38the operating systems live inside. Exactly. Therefore,
- 6:41if you deploy standard enterprise security software
- 6:43like an antivirus or endpoint detection system.
- 6:46Yeah. It gets installed inside the Windows or
- 6:49Linux operating system. It can only see what
- 6:51the operating system sees. Oh, I see where this
- 6:53is going. Yeah. If UNC -3886 compromises the
- 6:57hypervisor level beneath it, they are invisible.
- 7:00Wow. The security tools literally cannot reach
- 7:03down into that foundational layer to spot the
- 7:06anomaly. So they are operating in the absolute
- 7:08blind spots of the network architecture. Precisely.
- 7:11And the forensics show they went even further
- 7:13to ensure they stayed invisible, right? I mean,
- 7:16Singapore's Coordinating Minister for National
- 7:18Security, Kay Shanmugam, noted that the hackers
- 7:21used advanced tools like Linux rootkits. Yeah,
- 7:24rootkits. Rootkits are fascinating pieces of
- 7:26engineering. Because they hide things, right?
- 7:28Right. Their primary function is to intercept
- 7:30commands at the kernel level of an operating
- 7:32system. so how does that work in practice imagine
- 7:36a system administrator suspects something is
- 7:38wrong okay and they type a command to list all
- 7:41the active processes and hidden files currently
- 7:44running on a router okay standard troubleshooting
- 7:47right the rootkit sees that command being issued
- 7:50actively filters its own malicious files out
- 7:53of the results, and hands a pristine, perfectly
- 7:55clean list back to the administrator. Are you
- 7:58kidding me? No. The operating system is actively
- 8:01lying to the very people trying to defend it.
- 8:04Wow. So if the attackers are utilizing these
- 8:07ultra -expensive zero -day exploits to get into
- 8:09the hypervisors, and then deploying rootkits
- 8:12that actively lie to the system administrators,
- 8:15I mean, finding them sounds hard enough. But
- 8:18getting them out must be an entirely different
- 8:20nightmare. It is an incredibly delicate operation.
- 8:22Which explains the massive scale of the response
- 8:25here. I mean, the Singapore government launched
- 8:27what they called Operation Cyber Guardian. Yes,
- 8:29Cyber Guardian. Based on the numbers from the
- 8:31cybersecurity agency, this was Singapore's largest
- 8:35cyber incident response effort to date. It's
- 8:38a massive undertaking. This operation lasted
- 8:40more than 11 months. Nearly a year of continuous
- 8:43mitigation. And the duration alone that just
- 8:45highlights the extreme complexity of rooting
- 8:48out a hypervisor level threat. OK, wait, let
- 8:51me challenge that timeline for a second. Sure.
- 8:5311 months seems like an absolute eternity in
- 8:56the tech world. I mean, if my laptop gets a severe
- 8:58virus, I back up my photos, wipe the hard drive
- 9:02completely clean, and reinstall the operating
- 9:05system in like an afternoon. Right. Why does
- 9:08it take over 100 government cyber experts almost
- 9:11a year to clean up a network? Well, think about
- 9:14the environment they are operating in. You are
- 9:16trying to rebuild the foundation of a suspension
- 9:18bridge while rush hour traffic is actively driving
- 9:21over it. Oh, man. You cannot simply wipe the
- 9:24hard drives of Singapore's four major telecommunications
- 9:27providers. You can't turn off the Internet for
- 9:29a nation. Because everything relies on it. Everything,
- 9:32hospitals, financial clearinghouses, military
- 9:35logistics, emergency services, they all rely
- 9:39on continuous unbroken uptime. So they basically
- 9:42have to surgically remove the root kits while
- 9:45the data packets are... actively flowing. Exactly.
- 9:48They have to identify the compromised nodes,
- 9:51spin up entirely new, clean, patched virtual
- 9:54environments that are parallel to the infected
- 9:56ones. Then they have to seamlessly migrate the
- 9:58live network traffic over to the clean nodes
- 10:01without dropping a single connection. That sounds
- 10:03impossible. And then on top of that, they have
- 10:05to isolate and study the infected servers to
- 10:08ensure the threat actor hasn't left, you know,
- 10:10a secondary back door somewhere else. Right.
- 10:12Because if you miss one. They're back in. Yeah.
- 10:14So doing that across four massive telcos without
- 10:17causing a latency spike is a monumental engineering
- 10:20feat. And the fact that they pulled it off brings
- 10:23up the most counterintuitive, surprising aspect
- 10:25of this entire event, at least to me. What's
- 10:27that? Despite the hackers gaining access to critical
- 10:30systems and despite them maintaining this covert,
- 10:33persistent presence for roughly a year, there
- 10:36were absolutely zero service disruptions. None.
- 10:39None at all. And that points to the discipline
- 10:41of UNC 3886 for sure. But it also validates the
- 10:46defense in depth mechanisms that the telcos possess.
- 10:48OK, so the telcos had safeguards. Right. The
- 10:51attackers were inside. But they were prevented
- 10:53from gaining total unrestricted administrative
- 10:56control over the entire core. But the strangest
- 10:59part is the data itself. The missing data. Exactly.
- 11:03The CSA explicitly reported that there was no
- 11:06evidence to date that any sensitive customer
- 11:08data or personal records were accessed or exfiltrated.
- 11:12None. No credit cards were stolen. No personal
- 11:14text messages were downloaded. No billing records
- 11:17were dumped on the dark web for sale. Right.
- 11:19Really analyze that for a second. They spend
- 11:21millions of dollars. on zero days. They build
- 11:23these invisible rooms in the hypervisors. They
- 11:25sit quietly in the digital walls for a year.
- 11:28And they don't steal a single credit card or
- 11:30private text. What is the motive? I mean, why
- 11:34expend all those resources just to sit there?
- 11:36Well, this is where we really have to separate
- 11:38our understanding of cybercrime from cyberespionage.
- 11:41Okay, break that down. Cybercriminals, right,
- 11:43they are motivated by immediate financial liquidity.
- 11:46Cash. Exactly. They steal databases to sell on
- 11:50dark web forums or they deploy ransomware to
- 11:53extort cryptocurrency. Right. That's the loud
- 11:55stuff we talked about. Exactly. Nation state
- 11:57threat actors, though, they are playing a vastly
- 12:00different, much longer game. OK. Their currency
- 12:04is strategic intelligence and geopolitical advantage.
- 12:07So in that context, telecommunications infrastructure
- 12:10isn't just a company. No. It's the central nervous
- 12:14system of a target nation. You nailed it. Telecommunications
- 12:17infrastructure is the holy grail for a state
- 12:20-backed intelligence apparatus. Why specifically
- 12:23telecom? Because everything a modern society
- 12:25requires to function flows through those specific
- 12:28pipes. When a group like UNC386 infiltrates a
- 12:31telco and deploys these silent route kits, their
- 12:34primary goal is often mapping out the network
- 12:36architecture. They just want the blueprints.
- 12:39Right. They need to understand exactly how the
- 12:41data flows, where the most critical administrative
- 12:43nodes are located, and what the dependencies
- 12:45are between different government and civilian
- 12:48sectors. They're learning the layout of the building
- 12:50so they know exactly which load -bearing walls
- 12:54to hit in the future? Exactly. The term used
- 12:56in the intelligence community is prepositioning.
- 12:59Prepositioning. And according to the broader
- 13:01context provided by Reuters and Mandiant, these
- 13:04operations are frequently about preparing for
- 13:06future geopolitical conflicts. Like what kind
- 13:08of conflicts? Well, take the constantly analyzed
- 13:11scenario of a potential future conflict over
- 13:14Taiwan. Right. If a regional crisis erupts, having
- 13:18deep, undetected, persistent access to the telecommunications
- 13:22infrastructure of a major logistical and financial
- 13:25hub like Singapore. I mean, that provides an
- 13:28unbelievable strategic advantage. Huge. You don't
- 13:31have to launch a new attack on day one of a conflict.
- 13:34Because you've already been inside the network
- 13:35for two years. You are already in the control.
- 13:37room. You could monitor high -level government
- 13:40communications. You could subtly disrupt maritime
- 13:43logistics. Wow. Or even sever connectivity to
- 13:47financial sectors at the precise moment it causes
- 13:49the maximum amount of strategic paralysis. So
- 13:52you basically plant the digital explosives years
- 13:55in advance, simply waiting for a political directive
- 13:58to detonate them. That's the theory. Yeah. And
- 14:00again, we have to note that Beijing vehemently
- 14:03denies engaging in this kind of prepositioning
- 14:05or state sponsored espionage. Of course. But
- 14:08from a purely theoretical military strategy standpoint,
- 14:11that is exactly how a major global power would
- 14:14leverage advanced cyber capabilities. Yeah, it's
- 14:17about securing the high ground for tomorrow's
- 14:19potential conflicts, completely ignoring today's
- 14:23financial game. And the sheer discipline required
- 14:25to secure that high ground. and then do absolutely
- 14:28nothing with it. I mean, that is what makes UNC
- 14:303886 so formidable. They had access to critical
- 14:34infrastructure, but they chose to merely observe.
- 14:36To really emphasize how specific that discipline
- 14:39is, I think it helps to contrast UNC 3886 with
- 14:43other major cyber events dominating the headlines
- 14:46recently. That's a good point. A great example
- 14:48is the Salt Typhoon attack. Right, Salt Typhoon.
- 14:50These were incredibly widespread breaches that
- 14:53hit hundreds of telecom companies globally, including
- 14:56major... carriers in the United States yeah and
- 14:58multiple Western governments linked salt typhoon
- 15:01to China as well right but the operational style
- 15:03was entirely different extremely different the
- 15:06difference in methodology is very revealing about
- 15:08how these groups are organized actually oh so
- 15:10well the Singapore government explicitly stated
- 15:14in their public announcement that the attack
- 15:15carried out by UNC 3886 on their local telcos
- 15:19had not resulted in the same extent of damage
- 15:22as cyber attacks elsewhere right specifically
- 15:25referencing those global salt typhoon acts. Exactly.
- 15:27Because salt typhoon was louder, it was aggressive,
- 15:30and it resulted in far more tangible exposure.
- 15:34But UNC -380 -A6 operated like a ghost. It proves
- 15:38that advanced persistent threat groups, or APTs,
- 15:41are not a single monolith. even if they are suspected
- 15:45to originate from the exact same country. They're
- 15:47compartmentalized. Yeah, they operate like highly
- 15:50specialized military units with entirely different
- 15:53objectives, different toolkits, and different
- 15:55rules of engagement. One group might be tasked
- 15:58with aggressive, loud data collection, sweeping
- 16:01up as much raw intelligence as possible. Like
- 16:04Soul Typhoon. Right. Another group, like UNC3886,
- 16:08is tasked purely with maintaining a silent foothold
- 16:11in critical infrastructure. at all costs. And
- 16:14Singapore's infrastructure is clearly a high
- 16:16priority target for these various groups. I mean,
- 16:19our sources indicate Singapore has faced similar
- 16:22sophisticated threats very recently. Oh, definitely.
- 16:25Earlier in 2024, Bloomberg reported that another
- 16:28major group known as Volt Typhoon was believed
- 16:31to have breached Singtel. the country's largest
- 16:33mobile carrier. Yeah, the typhoons. Right. You
- 16:36have Volt Typhoon, Salt Typhoon, UNC3886. I mean,
- 16:39these networks are under constant evolving siege.
- 16:42They are. And as the telcos themselves stated
- 16:45in their joint response, they regularly face
- 16:47attacks and they are forced to constantly evolve
- 16:50their defense in -depth mechanisms just to survive
- 16:53the baseline threat environment. It's exhausting
- 16:55just thinking about it. It really forces us to
- 16:58view the modern Internet not as a secure public
- 17:00utility, but as a highly contested battle space.
- 17:04Where the most significant dangerous maneuvers
- 17:06happen entirely out of public sight. Right. So
- 17:10synthesizing everything we've looked at today,
- 17:12you know, the CSA's detailed announcement, the
- 17:15sheer technical wizardry of burning zero days
- 17:18to access hypervisors. The root kits. The root
- 17:21kits, the monumental 11 -month engineering feat
- 17:24of Operation Cyber Guardian, and this really
- 17:27chilling geopolitical strategy of propositioning.
- 17:30Yeah. What is the core lesson for the people
- 17:33and organizations relying on these networks every
- 17:35day? I think the core lesson is a fundamental
- 17:38shift in how we define a secure environment.
- 17:41Okay, tell me more about that. Historically,
- 17:43we sort of assumed that a quiet network was a
- 17:46secure network. If the alarms weren't sounding,
- 17:48we were safe. Right. No news is good news. Exactly.
- 17:51But UNC -3886 proved definitively that the absence
- 17:55of alarms does not mean the absence of an intruder.
- 17:57Wow. The most dangerous cyber threats operating
- 18:00today aren't the ones that break your servers
- 18:02or lock your files and demand a ransom in cryptocurrency.
- 18:05The truly existential threats are the ones that
- 18:08are perfectly content to sit quietly in the shadows
- 18:11of the infrastructure you rely on, methodically
- 18:14mapping your vulnerabilities, just watching and
- 18:17waiting. That is an incredibly unsettling reality
- 18:20to leave you with. If it takes over 100 dedicated
- 18:23government cyber defenders nearly an entire year
- 18:26of painstaking surgical work to clean up a silent
- 18:29threat that never even tripped a standard alarm
- 18:31or stole a single file. Yeah. What else might
- 18:34be lurking in the digital pipes we use to communicate
- 18:36right this second? Are we absolutely sure the
- 18:39hidden room in the ventilation shaft is actually
- 18:41empty? It's a question we all need to be asking.
- 18:44Thank you so much for exploring this complex
- 18:45landscape with us today. Understanding the stark
- 18:47realities of these silent sieges is the absolute
- 18:50first step in defending against them. To make
- 18:52sure your own digital infrastructure is secure
- 18:54and to discuss your security and IT needs, be
- 18:57sure to visit www .kinsoft .com .au. Keep asking
- 19:02questions, keep looking past the obvious, and
- 19:05we will catch you next time.