Malware & Threats

Singapore: Rootkits, Zero-Day Used in Chinese Attack on Major Telecom Firms

China-linked UNC3886 targeted all four major telecom providers, but did not disrupt services or access customer information.

China hacks telecoms firms

All four major telecommunications providers in Singapore were targeted last year by a Chinese APT, according to Singapore’s cybersecurity agency CSA and its development agency IMDA.

The attack, initially disclosed in July, was attributed to UNC3886, a cyberespionage group active since at least 2021, which is known for targeting vulnerabilities in Ivanti, Juniper, and VMware products.

“UNC3886 launched a deliberate, targeted, and well-planned campaign against Singapore’s telecommunications sector. All four of Singapore’s major telecommunications operators – M1, SIMBA Telecom, Singtel and StarHub – have been the target of attacks,” CSA says.

As part of the campaign, the agency notes, the APT deployed advanced tools, including a zero-day exploit in a firewall, to access a telco’s network and obtain a small amount of technical data.

UNC3886 was also seen deploying rootkits to evade detection and maintain persistent access to the compromised environments.

CSA says UNC3886 gained limited access to some parts of the victim companies’ networks and systems, but could not disrupt services.

Advertisement. Scroll to continue reading.

“There is no evidence to-date that sensitive or personal data such as customer records were accessed or exfiltrated. There is also no evidence that the threat actor managed to disrupt telecommunications services such as internet availability,” CSA says.

The cybersecurity agency says it has been working with the targeted organizations to investigate the intrusions, close the threat actor’s access, implement remediation measures, and expand monitoring capabilities across the impacted networks.

“While our collective efforts have contributed to containing the attacks so far, we must be prepared that there may be future attempts to gain access into our telco infrastructure. Telcos are strategic targets for threat actors, including state-sponsored ones,” CSA notes.

The agency says it will introduce initiatives to improve Singapore’s cyber capabilities and ensure better and faster response to similar attacks.

Related: Chinese Spies Target Networking and Virtualization Flaws to Breach Isolated Environments

Related: Notepad++ Supply Chain Hack Conducted by China via Hosting Provider

Related: EU Plans Phase Out of High Risk Telecom Suppliers, in Proposals Seen as Targeting China

Related: China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear

Related Content

Government

Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.

Nation-State

Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025.

Malware & Threats

Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT.

Nation-State

The cybersecurity firm has not explicitly accused China of being behind the attack, but the evidence suggests it was. 

Malware & Threats

Dubbed GopherWhisper, the group relies on multiple Go-based backdoors alongside custom loaders and injectors.

Nation-State

The state-sponsored threat actor deployed kernel implants and passive backdoors enabling long-term, high-level espionage.

Nation-State

The state-sponsored hackers deployed custom tools and stayed dormant in the compromised environments for months.

Malware & Threats

The UNC2814 threat actor has been active since at least 2017, targeting organizations across 42 countries. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version