Singapore’s Cyber Security Agency (CSA) reported that the China-linked cyber espionage group UNC3886 conducted a deliberate campaign targeting the country’s telecommunications sector, with all four major telcos (Singtel, StarHub, M1, and SIMBA Telecom) confirmed as targets and breached at least once. Authorities assessed the activity as focused on strategic access and intelligence collection rather than disruption; while attackers reached some network segments and had limited access to certain critical systems, Singapore reported no service outages and no evidence of customer data theft.
CSA said UNC3886 used sophisticated tooling, including weaponizing a zero-day exploit to bypass a telco’s perimeter firewall and exfiltrate a small amount of technical data, and deploying rootkits to maintain persistence and evade detection. In response, Singapore launched Operation Cyber Guardian, with CSA and the Infocomm Media Development Authority (IMDA) coordinating a multi-agency investigation and containment effort to close access paths, expand monitoring, and reduce the risk of lateral movement into other critical sectors such as banking, transport, and healthcare; reporting also noted UNC3886’s broader tradecraft of targeting edge devices and virtualization infrastructure (e.g., VMware ESXi/vCenter) consistent with prior public research linking similar activity to the Fire Ant cluster.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
Singapore's Cyber Security Agency publicly disclosed that UNC3886 had targeted all four major telecom providers and attributed the campaign to the China-linked group. Officials said the attackers sought mainly technical network and architecture data, but found no evidence of customer personal data theft or internet and mobile service disruption.
During Operation Cyber Guardian, responders constrained the adversary's activity, remediated exploited access points, and expanded monitoring to prevent further movement into telecom and other critical infrastructure networks. Authorities said the compromise was contained before it could cause service disruption or deeper damage.
Singapore launched Operation Cyber Guardian in response to the UNC3886 intrusions, mounting what officials described as the country's largest multi-agency cyber operation. The effort lasted more than 11 months and involved over 100 investigators and cyber experts from multiple government agencies working with the telcos to contain the threat.
After the intrusions were detected, the affected telecommunications providers reported suspicious activity to Singapore authorities. This triggered a coordinated government response led by the Cyber Security Agency of Singapore and the Infocomm Media Development Authority.
Singapore later said the China-linked espionage group UNC3886 targeted Singtel, StarHub, M1, and SIMBA Telecom during 2025, using advanced techniques including a zero-day exploit to bypass a perimeter firewall and rootkits to maintain stealth and persistence. The intrusions resulted in unauthorized access to parts of telco networks, including limited access to critical systems in at least one case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
11 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourceteiss.co.uk
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcedatabreaches.net
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcecsa.gov.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.