Trans-Pacific & European Backbone Core Routing Compromise
Coordinated exploitation of carrier SS7/Diameter interconnects and edge hypervisors targeting government voice routes and subsea fiber management planes.
An advanced threat cluster exhibiting operational overlap with Volt Typhoon and UNC3236 has established stealth access inside core telecommunications switches across three Tier-1 transit providers. Attackers weaponized a zero-day vulnerability in SS7 ASN.1 packet decoding (CVE-2026-1194) to redirect signaling data and selectively monitor unencrypted SMS 2FA tokens and targeted government satellite uplink metadata.
Anomalous SRI-SM transaction bursts observed originating from unauthorized roaming prefix.
Attackers deploy CVE-2026-1194 zero-day payload, achieving root execution on signaling switches.
CISA, ENISA, and JPCERT issue synchronized TLP:AMBER warning to Tier-1 operators.
82% of affected core gateway clusters isolated behind strict Diameter packet filtering policies.
Initial memory crash telemetry and payload dump collected from gateway switch.
Reverse-engineering confirms novel ASN.1 packet parser deserialization primitive.
Official inter-governmental classification as state-sponsored critical infrastructure incident.
State-Sponsored Intrusion into Carrier Backbone Switches
Signaling Security in European Telecommunication Backbones