Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Operation Soft Cell

Operation Soft Cell

TLP:CLEAR
Active

Description

In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor using tools and techniques commonly associated with Chinese-affiliated threat actors, such as APT10. This multi-wave attacks focused on obtaining data of specific, high-value targets and resulted in a complete takeover of the network.

AI Analysis

· 1 week ago

Executive Summary

Operation Soft Cell is an advanced persistent threat group suspected of Chinese state sponsorship, targeting telecommunications providers globally since at least 2018. Their primary tactics involve multi-stage attacks aimed at network takeover and data exfiltration, leveraging tools associated with other Chinese-affiliated APTs like APT10.

Goals & Targeting

Operation Soft Cell's strategic goals align with those of typical state-sponsored actors: intelligence gathering and network compromise. Their targeting of telecommunications providers suggests an interest in securing access to communications infrastructure, potentially for mass surveillance capabilities. The group’s focus on complete network takeover indicates a desire not just to exfiltrate data but also to establish long-term persistence within targeted organizations.

Enhanced Description

Operation Soft Cell represents a sophisticated cyber espionage campaign documented by Cybereason Nocturnus in 2018. This group targeted global telecommunications providers with highly customized attacks designed to infiltrate and exfiltrate sensitive data. The operation was characterized by multiple waves of attacks, each increasingly more aggressive, leading to complete network compromise. The attackers utilized tools and techniques reminiscent of Chinese-linked APTs such as APT10, suggesting a state-sponsored or -affiliated campaign. The primary focus appears to be on acquiring high-value telecommunications data, which could be useful for surveillance, economic gain, or strategic advantage.

Key Capabilities

  • Multi-stage attack framework
  • Network exploration and lateral movement
  • Credential dumping techniques
  • Persistent access mechanisms
  • Data exfiltration protocols

MITRE ATT&CK Tactics

Covert Collection
Cyber Espionage
Resource Development

ATT&CK Techniques

T1086|0002
T1583
T1594
T1003
T1074
T1218
T1021
T1055

Software / Tooling

Mimikatz
Custom compiled binaries
Process injection tools (e.g., BeEF)
C2 frameworks (e.g., Moloquist)
LNK files

Campaigns & Victims

Operation Soft Cell has demonstrated an operational rhythm aligned with state-sponsored campaigns, likely indicating a well-resourced and persistent threat actor. Their focus on telecommunications providers suggests an interest in targeting critical infrastructure, possibly for both economic and national security purposes. Notable operations include the complete takeover of targeted networks, leading to significant data loss or compromise.

IOC Patterns

  • Spear-phishing emails with malicious links
  • VBA-based macros in Office documents
  • LNK files dropped via compromised websites
  • Registry and file persistence mechanisms
  • Unusual network traffic patterns

Recommended Actions

  • Implement advanced email filtering solutions to detect phishing attempts.
  • Monitor for known MITRE ATT&CK-based indicators of compromise (IOC).
  • Enhance credential protection mechanisms, such as multi-factor authentication (MFA).
  • Conduct regular network security audits and penetration testing exercises.
  • Ingest threat intelligence feeds into SIEM tools to detect related attack patterns.

Suggested Tags

APT
Cyber Espionage
State-sponsored
Telecommunications

Confidence Assessment

High confidence in the identification of Operation Soft Cell as a state-sponsored actor due to its use of known APT tools and techniques. However, gaps exist regarding specific details such as exact first/last seen timestamps and unique identifying toolset features beyond those shared with other Chinese-linked groups.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Cyber Espionage
State-sponsored
Telecommunications

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.