Institution Profiling / Internet infrastructure institution

Chinese hackers breached Asian telcos for years

Chinese hackers breached Asian telcos for years is tracked as a internet infrastructure institution within the internet infrastructure ecosystem.

Chinese hackers breached Asian telcos for years
Caption: Chinese hackers breached Asian telcos for years visual context for BTW intelligence coverage. · Source context: Existing article media was retained or restored as the subject-specific visual basis. · Relevance reason: Chinese hackers breached Asian telcos for years is the primary subject or event subject; the image supports the article's market reading. · Image provenance: Existing curated article image retained because it is subject- or event-specific and not a generic pool placeholder.

Sources

Public references used for this article.

CategoryInstitution

Chinese hackers breached Asian telcos for years is tracked as a internet infrastructure institution within the internet infrastructure ecosystem.

RegionAsia Pacific

Chinese hackers breached Asian telcos for years has public-source relevance to network operations, governance, dependency mapping, or market structure.

Signal FocusInternet infrastructure institution

Chinese hackers breached Asian telcos for years has public-source relevance to network operations, governance, dependency mapping, or market structure.

Content TypeProfile

Chinese hackers breached Asian telcos for years is tracked as a internet infrastructure institution within the internet infrastructure ecosystem.

Primary DomainSecurity

Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.

TopicInternet infrastructure institution

Chinese hackers breached Asian telcos for years is profiled by BTW Media because published evidence links it to internet infrastructure, governance, operational dependencies, or market visibility.

ImpactMedium

Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.

Confidence?Confidence Grade
0.90–1.00AHigh — direct sources
0.75–0.89A/BStrong
0.55–0.74B/CMedium
0.35–0.54C/DWeak–medium
0.10–0.34DWeak signal
0.00–0.09DInternal monitoring
Limited confidence (82%)

Several public sources

Chinese hackers breached Asian telcos for years is profiled by BTW Media because published evidence links it to internet infrastructure, governance, operational dependencies, or market visibility.

  • Weaver Ant group infiltrated telecom providers using stealthy techniques.
  • The campaign remained undetected for over four years.

What happened: Stealthy telecom espionage campaign exposed

A Chinese-linked hacking group, dubbed Weaver Ant, secretly infiltrated several Asian telecommunications providers over a period of at least four years, according to a report by cybersecurity firm Sygnia. The attackers leveraged advanced techniques, including encrypted tunnelling and web shells, to maintain persistence and avoid detection.

The hackers used compromised Zyxel home routers across Southeast Asia as a relay network, effectively masking their origin. This enabled them to conduct long-term espionage operations, harvest credentials, and monitor internal network activity. The attackers also deployed a previously undiscovered web shell named INMemory, which executes payloads directly in server memory, leaving little forensic trace.

Sygnia’s investigation revealed that Weaver Ant utilised a non-provisioned operational relay box (ORB) network to proxy malicious traffic, further concealing its infrastructure. The group also demonstrated a high level of adaptability, pivoting from one telecom provider to another through compromised devices, evading security measures along the way.

The breach came to light accidentally during an unrelated Sygnia investigation, when a previously disabled account was reactivated by a service account. This reactivation led analysts to uncover the larger espionage campaign, confirming Weaver Ant’s extensive access across multiple telecom networks.

Also read: Telcos at a crossroads: Google Cloud’s AI call to action
Also read: NVIDIA AI: Revolutionising telcos with AI-RAN and GenAI

Why it is important

The revelation of this campaign highlights the vulnerability of critical telecom infrastructure to prolonged cyberespionage operations. Telecom providers, being central to communications, are lucrative targets for nation-state actors seeking intelligence on government, business, and individual activities.

By using home routers as relays, the attackers effectively bypassed traditional network detection systems. This approach, coupled with the use of memory-based web shells, demonstrates an evolution in hacking techniques, making it harder for security teams to trace or block the intrusion.

Moreover, the persistence of the attack over several years suggests that telecom operators may face systemic weaknesses in their security frameworks. The incident underscores the need for continuous monitoring, advanced threat detection systems, and proactive cybersecurity measures to prevent similar breaches.

At A Glance

  • Name: Chinese hackers breached Asian telcos for years
  • Type: Internet infrastructure institution
  • Base: Asia Pacific
  • Profile focus: Institution

What It Does

  • Public records support monitoring of its role, services, and key relationships.

Why It Matters

  • Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.
  • Operational criticality: Medium
  • Time horizon: Next quarter

What To Watch

  • Monitoring focuses on verified service continuity, governance changes, and relationship signals.
NowMedium priority

Track verified source updates, role changes, and current public evidence.

QuarterMedium policy sensitivity

Public-source signals support medium-impact monitoring for infrastructure visibility and dependency analysis.

YearNext quarter outlook

Longer-term relevance depends on verified operating, policy, and relationship changes.

Member Briefing

Deeper Profile Context

Login is required to unlock the full profile briefing and source notes.

Only for Strategy Circle

Strategic Circle Access

Open to all readers. Unlock profile briefings after joining and logging in.

Join Strategic Circle

Only for Leadership Alliance

Leadership Alliance Access

For owners and management of IP-holding companies. Login required to unlock.

Join Leadership Alliance
← BackAll Companies