Tech

Singapore deploys AI tools and shifts to active threat hunting after UNC3886 telco espionage campaign

The campaign targeted all four major telecommunications operators in Singapore: M1, SIMBA Telecom, Singtel, and StarHub. Authorities described the operation as “deliberate, targeted, and well-planned,” indicating a strategic intent to compromise critical information infrastructure (CII). While the initial attack was detected in mid-2025, the full scope of the incident was not made public until this week to preserve operational security.

UNC3886, first identified by security firm Mandiant in 2022, is characterized as a highly disciplined advanced persistent threat (APT) actor with deep technical capabilities. Throughout 2024 and into 2025, the group exploited zero-day vulnerabilities in widely used technologies, including Fortinet FortiOS, VMware vCenter and ESXi hypervisors, and Juniper Networks systems. In one specific instance, the attackers used a zero-day exploit to bypass a perimeter firewall, gaining unauthorized access into internal telecom networks. They subsequently deployed custom malware and rootkits to maintain persistent access and evade detection, allowing them to exfiltrate a small amount of technical data, primarily related to network infrastructure.

Despite the sophistication of the intrusion, authorities stated that the campaign did not result in significant public harm. There is no evidence that sensitive or personal data, such as customer records, was accessed or stolen. Furthermore, there were no indications that telecommunications services, including internet availability, were disrupted. The primary objective of the attackers appears to have been intelligence gathering and establishing covert footholds in critical systems rather than immediate destruction or service denial.

In response to the incident, Singapore has fundamentally reoriented its cyber defense doctrine. Gwenda Fong, who took over as chief executive of the CSA in July, emphasized that the era of relying solely on keeping attackers out is over. “APTs are driven by state-backed objectives and you are their target,” Fong noted. The new strategy assumes that well-resourced attackers will eventually breach perimeters, necessitating a focus on detecting and neutralizing threats already inside the network.

To support this shift, the government has developed and deployed in-house artificial intelligence tools. One such system conducts automated penetration testing on approximately 2,000 government systems, allowing defenders to identify vulnerabilities and unusual activity proactively. This AI-driven approach enables security teams to hunt for anomalies in network behavior, which is critical for detecting stealthy actors like UNC3886 that use advanced obfuscation techniques.

Operation Cyber Guardian involved a coordinated effort across multiple government bodies, including the Centre for Strategic Infocomm Technologies (CSIT), the Digital and Intelligence Service (DIS), the Government Technology Agency of Singapore (GovTech), and the Internal Security Department (ISD). The partnership between the public and private sectors was central to containing the breach, with agencies working closely with the telcos to limit the attacker’s movement and implement remediation measures. Access points used by UNC3886 have since been closed, and monitoring capabilities across the targeted telecoms have been expanded.

The incident highlights the growing risk posed by state-sponsored cyber espionage to critical infrastructure. Singapore has previously faced intrusions linked to Chinese APT groups, including the Volt Typhoon group, which was believed to have breached Singtel in 2024. The Chinese embassy in Singapore did not publicly respond to the latest disclosure, consistent with Beijing’s repeated denials of conducting cyber espionage operations abroad.

As AI-powered threats grow in complexity, Singapore’s response underscores a broader global trend: cybersecurity is evolving from a static defense of borders to a dynamic, intelligence-driven hunt for intruders. The deployment of AI tools for continuous testing and threat detection represents a significant investment in adaptive security capabilities, aiming to stay ahead of state actors who continuously refine their exploitation techniques.

Karen Foster

Karen Foster covers technology news, including artificial intelligence, cybersecurity, software, consumer devices, and developments at major technology companies. She follows product launches, industry announcements, digital policy, and emerging trends while looking beyond promotional claims. Karen focuses on explaining what is new, what is confirmed, and why a technology development may matter to everyday users.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button