The LightBasin (aka UNC1945) hacker group has been targeting the telecommunications sector at a global scale since at least 2016, according to CrowdStrike research.Among the key takeaways to note:
- The LightBasin group has "extensive knowledge of telecommunications protocols, including the emulation of these protocols to facilitate command and control (C2) and utilizing scanning/packet-capture tools to retrieve highly specific information from mobile communication infrastructure, such as subscriber information and call metadata."
- LightBasin has successfully attacked at least 13 telecommunication companies dating back to at least 2019, CrowdStrike investigations found, though the group's activities started before that date.
- Perhaps more concerning, the LightBasin group "will continue to target the telecommunications sector," CrowdStrike concluded.