Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Verizon, AT&T Targeted by Second Threat Actor Who Claims Trump, Harris Call Logs

    Verizon, AT&T Targeted by Second Threat Actor Who Claims Trump, Harris Call Logs

    November 27, 2024

    Verizon, AT&T hacker

    Breaches of major U.S. telecom networks by the China-linked Salt Typhoon group have received widespread media attention, but a second threat actor has also been targeting telecom service providers in recent months, and claims to possess the call logs of President-elect Donald Trump and Vice President Kamala Harris.

    Cyble dark web researchers have been tracking the activities of a threat actor (TA) known as “kiberphant0m” since they emerged on English- and Russian-speaking cybercrime forums earlier this year.

    Since late August, kiberphant0m has been selling data and access allegedly obtained from Verizon and AT&T – in addition to “spy schema” allegedly belonging to the U.S. National Security Agency (NSA) that the TA claims came from the massive Snowflake data breach earlier this year.

    We’ll look at kiberphant0m’s activities, credibility and possible connections, in addition to the state of telecom network security that got us to this point.

    kiberphant0m’s Background and Ties

    kiberphant0m first appeared on the English-language Breach Forums in January 2024. After a few replies to other threads in March, the TA first appeared to begin selling data in April, starting with a Chinese crypto casino database. A Telegram channel began operating around the same time.

    Other activities have included selling:

    • Access to a Ukraine government research server
    • Access to a defense contractor
    • A 175TB application breach
    • Root access to a Chinese server with 95 domains, including some critical infrastructure sectors
    • UK bank server access
    • Indian and Asian telecom data and access
    • Access to a European biomedical company
    • Access to a mobile social media app
    • SSH bot and server access
    • Linux DDoS botnet source code

    More recently, kiberphant0m has claimed a connection to UNC5537, the financially motivated threat group behind the Snowflake breach. Some posts have included the hashtag #FREEWAIFU, a reference to an alias of Alexander “Connor” Moucka, who was recently arrested and charged in the Snowflake breach by Canadian officials.

    Threat intelligence researchers believe that kiberphant0m is more than a broker, having demonstrated proficiency in technical matters. The claimed connection to UNC5537 appeared more recently and needs additional indicators to make the association certain. The FREEWAIFU campaign may be a cover masking other connections. The timing of telecom network breaches close in time to the China-linked campaign is also of interest.

    Krebs on Security reported yesterday that kiberphant0m may be “a U.S. Army soldier who is or was recently stationed in South Korea,” with activity going back to 2022 under other aliases.

    There has been some degree of confidence that kiberphant0m is reliable and has a credible history of claims, and their Breach Forums reputation score is positive with no neutral or negative feedback.

    Telecom Breach Claims, Including Trump and Harris Logs

    On Nov. 5-6, kiberphant0m created four threads on Breach Forums – three related to Verizon and AT&T, and the NSA post.

    The Trump and Harris call logs included a sample of Harris’ calls from 2022 and urged AT&T (ATNT) to contact them (image below). Another post offered Verizon Wireless PTT (push-to-talk) logs, including an SQL database, server logs and credentials, possibly obtained from a third-party service provider.

    A third post offered Verizon Wireless SIM swapping services, and the fourth appears to be a Snowflake technical database schema allegedly belonging to the NSA (image below).

    Threat actor kiberphant0m claims Trump and Harris call logs

    NSA spy schema Snowflake hack

    Those recent breaches don’t appear to include extremely sensitive information, but are nonetheless concerning, particularly given the lax state of telecom network security.

    Lax Telecom Network Security

    As Senate Intelligence Committee Chairman Mark R. Warner (D-Virginia) told the Washington Post last week, large U.S. telecom networks are “a hodgepodge of old networks … combinations of a whole series of acquisitions, and you have equipment out there that’s so old it’s unpatchable.”

    Presumably much of that is end-of-life equipment like routers and switches. Warner told the Post that the networks remain compromised, and that fixing them could involve physically replacing “literally thousands and thousands and thousands of pieces of equipment across the country.”

    Top national security officials met with telecom industry executives late last week to discuss a cooperative solution to the problem.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCritical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers
    Next Article Latest Multi-Stage Attack Scenarios with Real-World Examples

    Related Posts

    Machine Learning

    LLMs Struggle with Real Conversations: Microsoft and Salesforce Researchers Reveal a 39% Performance Drop in Multi-Turn Underspecified Tasks

    May 17, 2025
    Machine Learning

    This AI paper from DeepSeek-AI Explores How DeepSeek-V3 Delivers High-Performance Language Modeling by Minimizing Hardware Overhead and Maximizing Computational Efficiency

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    I tested an ink pen that records your handwriting and makes a digital copy. Spoiler: It works

    News & Updates

    Kyutai Releases Hibiki: A 2.7B Real-Time Speech-to-Speech and Speech-to-Text Translation with Near-Human Quality and Voice Transfer

    Machine Learning

    Best Free and Open Source Alternatives to Microsoft Disk Cleanup

    Development

    How to rename and retain the endpoint name for Amazon RDS

    Databases
    Hostinger

    Highlights

    News & Updates

    Microsoft Teams marches closer to letting you skip meetings, don’t tell your boss

    January 14, 2025

    Microsoft Teams will soon have a Copilot feature that suggests questions to ask in a…

    LAION AI Unveils LAION-DISCO-12M: Enabling Machine Learning Research in Foundation Models with 12 Million YouTube Audio Links and Metadata

    November 19, 2024

    New Front-End Features For Designers In 2025

    January 1, 2025

    Xbox Game Pass is “not for everybody,” says Phil Spencer

    April 17, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.