LightBasin (UNC1945) Compromises 13+ Global MNO Core Networks
CrowdStrike revealed that the LightBasin (UNC1945) APT had compromised 13+ global telecom operators since at least 2016 using custom GTP and SS7 tooling to masquerade as roaming infrastructure.
01Video Presentation & Conference Keynote
02Deep-Dive Technical Analysis
LightBasin deployed custom malware (e.g., SLGTRAN) emulating GPRS Roaming Exchange (GRX/IPX) nodes, tunneling through signaling firewalls into MNO internal networks to stage exfiltration of subscriber data and Call Detail Records on compromised roaming-partner infrastructure. The operators' mutual trust across the roaming plane meant neither side authenticated the other — the same 1988 assumption, now exploited by a nation-state-grade actor for espionage at scale. CrowdStrike's Counter Adversary Operations documented the campaign publicly in November 2021; the actor is now tracked as LIMINAL PANDA.
03Vulnerability & Exploit Flow
GTP-C tunneling injection & GRX roaming proxy emulation.
04Recommended Defense & Mitigation Protocol
Enforce GTP Firewall validation (GSMA FS.20), IPsec encryption on GRX links, and EDR on Linux core switches.
05Security Impact & Geopolitical Consequence
Defined the roaming/interconnect plane as a national-security attack surface; MNOs now segment GRX from signaling cores and audit interconnect peer assets.
06Authoritative Standards & External References
07Related Topic Cluster Records
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.