/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

FireEye: Chinese state-backed hacker group APT41 is using malware called MESSAGETAP to parse and save SMS traffic from a telecom's network at scale

FireEye Mandiant recently discovered a new malware family used by APT41 (a Chinese APT group) that is designed to monitor and save SMS traffic …

FireEye

Context & Ripple Effects

FireEye Mandiant's disclosure of MESSAGETAP is the third APT41 finding it has published in months: in August it reported the group hacking video-game companies and monetizing stolen virtual currency, and by March 2020 the same actor was attempting to exploit Citrix and Zoho bugs across organizations in 20+ countries. What distinguishes this one is the target class — instead of corporate IP, the implant sits inside a telecom network parsing SMS traffic in bulk.

The corpus shows a decade-long arc of China-linked collection work, from APT30's Southeast Asia espionage running since 2005 to Cybereason's report of Winnti exfiltrating hundreds of GBs from ~30 companies. MESSAGETAP moves that pattern from stealing files to intercepting a communications channel itself.

First-order effects

  • The compromised telecom now has an adversary storing copies of subscriber text traffic at scale, exposing message content — including anything sensitive carried over SMS — until the implant is found and removed.
  • FireEye Mandiant gains a marquee disclosure that reinforces its positioning as the firm that keeps unmasking APT41 operations, ahead of its announced $1.2B split of the products business from Mandiant.

Second-order effects

  • Every carrier running similar network gear faces pressure to hunt for comparable implants, since one confirmed telecom compromise implies the technique generalizes across the sector.
  • The disclosure compounds doubts about SMS-based authentication already raised by reports like APT20 bypassing key-fob 2FA — enterprises relying on texted codes face a second, independent reason to migrate to app- or hardware-based factors.

Third-order effects

  • If state-backed actors keep prioritizing telecommunications infrastructure for bulk interception, carriers get treated like critical national infrastructure in security budgets and regulation, shifting the burden from endpoint defense to network-core monitoring.
  • The APT41 record — espionage tooling plus criminal monetization — points toward a structural blur between state intelligence collection and profit-driven intrusion, complicating attribution and sanctions policy for the private firms tracking these campaigns.

The trend: Chinese state-linked intrusion activity is escalating from stealing documents on targeted networks to persisting inside telecom infrastructure where entire populations' communications can be collected.

Discussion

  • @fireeye @fireeye on x
    BLOG | MESSAGETAP: Who's Reading Your Text Messages? We recently discovered a new #malware family used by #APT41 that is designed to monitor and save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft. >> Read more: http://r.socialstudio.radia…
  • @mrdanperez Dan Perez on x
    Another interesting tidbit, #MESSAGETAP is not targeting a specific processing software it's processing SMS network traffic at the provider level! pic.twitter.com/HGgOYQCTow
  • @mrdanperez Dan Perez on x
    Why does this matter? Two things, it shows INTENT to target rather than just bulk collection of CDRs. It also shows that #APT41 is able to collect and process hundreds of thousands of text messages for specific keywords and IMSI/Phone numbers AT SCALE! #Unprecedented. pic.twitter…
  • @mrdanperez Dan Perez on x
    #MESSAGETAP uses two config files containing IMSI/Phone numbers, and a keyword list. It uses libpcap to process ALL traffic being routed through the servers looking for the very specific IMSI/Phone numbers to then same off that data for later collection! pic.twitter.com/oHUJG0VEs…
  • @mrdanperez Dan Perez on x
    In theory this means they can use this tool at other telecoms without issue. There wouldn't be any reason #APT41 wouldn't use this tool elsewhere if they are looking to do this same activity in other regions! pic.twitter.com/3T4S9zd5Nv
  • @mrdanperez Dan Perez on x
    Today @FireEye is publicly unveiling #MESSAGETAP, #APT41s newest espionage dataminer that we've observed being used at a telecom providers. https://www.fireeye.com/...