[ RECORD YEAR ]2019

LightBasin (UNC1945) Compromises 13+ Global MNO Core Networks

CrowdStrike revealed that the LightBasin (UNC1945) APT had compromised 13+ global telecom operators since at least 2016 using custom GTP and SS7 tooling to masquerade as roaming infrastructure.

THREAT SEVERITY
9.8 / 10
Target TechnologyGPRS Tunnelling Protocol (GTP-C / GTP-U), SIGTRAN
OSI Network LayerLayer 7 / Core GPRS Roaming Network
Threat Actor / AttributionLightBasin (UNC1945) Chinese APT
Protocol Standard3GPP TS 29.060 (GTP Specification)

01Video Presentation & Conference Keynote

02Deep-Dive Technical Analysis

LightBasin deployed custom malware (e.g., SLGTRAN) emulating GPRS Roaming Exchange (GRX/IPX) nodes, tunneling through signaling firewalls into MNO internal networks to stage exfiltration of subscriber data and Call Detail Records on compromised roaming-partner infrastructure. The operators' mutual trust across the roaming plane meant neither side authenticated the other — the same 1988 assumption, now exploited by a nation-state-grade actor for espionage at scale. CrowdStrike's Counter Adversary Operations documented the campaign publicly in November 2021; the actor is now tracked as LIMINAL PANDA.

03Vulnerability & Exploit Flow

Exploit Vector

GTP-C tunneling injection & GRX roaming proxy emulation.

04Recommended Defense & Mitigation Protocol

Operator Hardening Strategy

Enforce GTP Firewall validation (GSMA FS.20), IPsec encryption on GRX links, and EDR on Linux core switches.

05Security Impact & Geopolitical Consequence

Defined the roaming/interconnect plane as a national-security attack surface; MNOs now segment GRX from signaling cores and audit interconnect peer assets.

06Authoritative Standards & External References

07Related Topic Cluster Records

TelcoSec Global Ecosystem · Academy & Enterprise Audits

Master 5G Core, SS7 Defense & Subsea Cable Auditing

Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.

Hands-on SS7, Diameter & 5G SBA Firewall Defense
5G SA Zero Trust Security Architecture & ProLabs
Enterprise Carrier Auditing & Rogue Base Station Interception
Explore SaaS Academy Labs?Enterprise Consultancy (telco-sec.com)?
SaaS Academy free tier · Enterprise audits for operators