Operation Soft Cell: Nation-State Espionage Theft of Global Telco Call Detail Records (CDRs)
Cybereason revealed Operation Soft Cell, a massive multi-year cyber espionage campaign by suspected nation-state actors that completely compromised multiple telecommunications providers to exfiltrate raw subscriber Call Detail Records.
01Video Presentation & Conference Keynote
02Deep-Dive Technical Analysis
The threat actors breached carrier networks via web-server vulnerabilities, escalated privileges to Active Directory Domain Admins, and moved laterally to databases hosting Call Detail Records (CDRs). They deployed custom PowerShell scripts and modified WMI persistence to continuously query and exfiltrate years of raw CDR logs — detailing every subscriber call, SMS, cell-tower location coordinate, device IMEI, and IMSI for high-value diplomatic, military, and corporate targets without modifying call routing or causing service disruptions.
03Vulnerability & Exploit Flow
Web application privilege escalation, lateral movement to CDR databases, and scheduled batch exfiltration.
04Recommended Defense & Mitigation Protocol
Isolate CDR storage networks behind strict micro-segmentation, implement zero-trust privileged access management (PAM), and deploy database activity monitoring (DAM).
05Security Impact & Geopolitical Consequence
Demonstrated that telecom CDR databases are primary strategic targets for global intelligence collection, leading to heightened regulatory scrutiny over telecommunications metadata protection and privileged access management.
06Authoritative Standards & External References
07Related Topic Cluster Records
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.