Singapore’s Cyber Security Agency (CSA) said it worked with the Infocomm Media Development Authority (IMDA) and the country’s four major telecom providers—M1, Simba Telecom, Singtel, and StarHub—to remove a China-linked threat actor, UNC3886, after an extended intrusion effort against telecom networks and systems. The joint operation (“Cyber Guardian”) involved more than 100 incident responders and followed detection of a zero-day exploit used to bypass a perimeter firewall, along with rootkits used for persistence. Authorities reported no evidence of customer data compromise and no disruption to telecommunications services or Internet access, despite unauthorized access to some systems, including critical systems.
Other items in the provided set are largely separate reporting (or opinion/roundups) on unrelated threats, vulnerabilities, and trends—e.g., a Kaspersky-described Android firmware supply-chain backdoor (Keenadu), a Notepad++ update-channel compromise attributed to Lotus Blossom, and broader industry reporting on RMM abuse, mobile spyware, Chrome zero-days, and ransomware activity. One additional source (Emsisoft) references the Singapore telecom incident only in passing as an example within a broader argument about the state of cybersecurity, and does not add new technical or impact details beyond the CSA-reported event.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Singapore publicly disclosed that a China-linked threat actor, UNC3886, had targeted some of the country’s telecom networks and systems. The disclosure highlighted the operation’s scale, the use of advanced tooling, and the government’s coordinated work with all four major telcos over 11 months.
During and after the response, the Cyber Security Agency and IMDA said they found no evidence that personal data was compromised and no evidence of telecommunications or Internet service disruption. The response also included containment and hardening measures across the affected environments.
Singapore government cyber responders and the country’s four major telecom providers began a joint operation dubbed 'Cyber Guardian' to remove the China-linked actor from affected telecom networks. The actor had used a zero-day exploit to bypass a perimeter firewall and rootkits to maintain persistence, including access to some critical systems.
Singapore’s major telecom providers detected suspicious activity in their networks and notified the Infocomm Media Development Authority and Cyber Security Agency, triggering a coordinated national response. The threat actor was later identified as UNC3886.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.