In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor using tools and techniques commonly associated with Chinese-affiliated threat actors, such as APT10. This multi-wave attacks focused on obtaining data of specific, high-value targets and resulted in a complete takeover of the network.
Executive Summary
Operation Soft Cell is an advanced persistent threat group suspected of Chinese state sponsorship, targeting telecommunications providers globally since at least 2018. Their primary tactics involve multi-stage attacks aimed at network takeover and data exfiltration, leveraging tools associated with other Chinese-affiliated APTs like APT10.
Goals & Targeting
Operation Soft Cell's strategic goals align with those of typical state-sponsored actors: intelligence gathering and network compromise. Their targeting of telecommunications providers suggests an interest in securing access to communications infrastructure, potentially for mass surveillance capabilities. The group’s focus on complete network takeover indicates a desire not just to exfiltrate data but also to establish long-term persistence within targeted organizations.
Enhanced Description
Operation Soft Cell represents a sophisticated cyber espionage campaign documented by Cybereason Nocturnus in 2018. This group targeted global telecommunications providers with highly customized attacks designed to infiltrate and exfiltrate sensitive data. The operation was characterized by multiple waves of attacks, each increasingly more aggressive, leading to complete network compromise. The attackers utilized tools and techniques reminiscent of Chinese-linked APTs such as APT10, suggesting a state-sponsored or -affiliated campaign. The primary focus appears to be on acquiring high-value telecommunications data, which could be useful for surveillance, economic gain, or strategic advantage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operation Soft Cell has demonstrated an operational rhythm aligned with state-sponsored campaigns, likely indicating a well-resourced and persistent threat actor. Their focus on telecommunications providers suggests an interest in targeting critical infrastructure, possibly for both economic and national security purposes. Notable operations include the complete takeover of targeted networks, leading to significant data loss or compromise.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the identification of Operation Soft Cell as a state-sponsored actor due to its use of known APT tools and techniques. However, gaps exist regarding specific details such as exact first/last seen timestamps and unique identifying toolset features beyond those shared with other Chinese-linked groups.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics