[ RECORD YEAR ]2018

Operation Soft Cell: Nation-State Espionage Theft of Global Telco Call Detail Records (CDRs)

Cybereason revealed Operation Soft Cell, a massive multi-year cyber espionage campaign by suspected nation-state actors that completely compromised multiple telecommunications providers to exfiltrate raw subscriber Call Detail Records.

THREAT SEVERITY
9.4 / 10
Target TechnologyCall Detail Records (CDR), Active Directory, Oracle/MSSQL CDR Databases, Web Shells
OSI Network LayerLayer 7 / Carrier BSS Database & OSS Management Layer
Threat Actor / AttributionGallium / suspected Chinese State-Sponsored APT
Protocol Standard3GPP TS 32.240 Charging Management & CDR Architecture

01Video Presentation & Conference Keynote

02Deep-Dive Technical Analysis

The threat actors breached carrier networks via web-server vulnerabilities, escalated privileges to Active Directory Domain Admins, and moved laterally to databases hosting Call Detail Records (CDRs). They deployed custom PowerShell scripts and modified WMI persistence to continuously query and exfiltrate years of raw CDR logs — detailing every subscriber call, SMS, cell-tower location coordinate, device IMEI, and IMSI for high-value diplomatic, military, and corporate targets without modifying call routing or causing service disruptions.

03Vulnerability & Exploit Flow

Exploit Vector

Web application privilege escalation, lateral movement to CDR databases, and scheduled batch exfiltration.

04Recommended Defense & Mitigation Protocol

Operator Hardening Strategy

Isolate CDR storage networks behind strict micro-segmentation, implement zero-trust privileged access management (PAM), and deploy database activity monitoring (DAM).

05Security Impact & Geopolitical Consequence

Demonstrated that telecom CDR databases are primary strategic targets for global intelligence collection, leading to heightened regulatory scrutiny over telecommunications metadata protection and privileged access management.

06Authoritative Standards & External References

07Related Topic Cluster Records

TelcoSec Global Ecosystem · Academy & Enterprise Audits

Master 5G Core, SS7 Defense & Subsea Cable Auditing

Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.

Hands-on SS7, Diameter & 5G SBA Firewall Defense
5G SA Zero Trust Security Architecture & ProLabs
Enterprise Carrier Auditing & Rogue Base Station Interception
Explore SaaS Academy Labs?Enterprise Consultancy (telco-sec.com)?
SaaS Academy free tier · Enterprise audits for operators