EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/espionage-operation/operation-soft-cell
226/430

File EL-0205HighResolvedEspionage Operation / Telecommunications Surveillance

Operation Soft Cell

Also filed as China Telecom Surveillance · Soft Cell Operation

Operation Soft Cell was a sophisticated espionage campaign targeting global telecommunications infrastructure. The operation focused on intercepting and exfiltrating metadata, including call records and communication patterns. This capability allowed the perpetrators to map the communication networks of foreign targets without necessarily intercepting the content of the calls.

  • #apt41
  • #china
  • #telecom-surveillance
  • #metadata-theft
  • #soft-cell
Notoriety7/10
Event
1 Jan 2018
Disclosed
1 Mar 2018
Target
Global Telecom Providers
Actor
APT41
Scale
Massive, estimated to be petabytes of metadata
Status
Resolved

01Summary

The Soft Cell operation involved the compromise of core telecommunications networks, allowing the attackers to establish persistent surveillance capabilities. The primary method of attack was the exploitation of vulnerabilities within telecom switching equipment or the insertion of malicious hardware/software into the supply chain. Once inside the network, the threat actors were able to harvest massive volumes of metadata, such as who called whom, when, and for how long. This metadata is highly valuable for intelligence agencies as it reveals social, political, and economic relationships between individuals and organizations. The scale of the operation suggested state-level resources, aiming for long-term, undetectable intelligence collection across multiple jurisdictions.

02Background

The increasing reliance on global telecommunications infrastructure made it a prime target for state-sponsored espionage. Historically, intelligence agencies have sought to monitor communications, but Soft Cell represented a shift toward systemic, large-scale metadata harvesting. This capability bypasses the need for direct content interception, making the surveillance more difficult to detect and legally challenge.

03Key revelations

  1. 01The ability to map the entire communication network of a target population.
  2. 02The successful exploitation of fundamental, often overlooked, telecommunications protocols.
  3. 03The sustained, long-term nature of the surveillance capability.

04Technical analysis

The attack likely involved compromising Signaling System 7 (SS7) protocols or exploiting vulnerabilities in Diameter protocol implementations used in modern mobile networks. By manipulating these protocols, the attackers could intercept signaling messages that carry metadata, such as location data and call routing information. The exfiltration process would require establishing covert channels out of the highly secured telecom backbone.

Attack vector
Supply Chain Compromise or Exploitation of Telecom Protocols (e.g., SS7/Diameter)
Attack method
Passive Metadata Interception and Exfiltration
Initial access
Compromise of Telecom Backbone/Supply Chain
Lateral movement
Network Protocol Manipulation
Persistence
Backdoor Insertion into Core Network Infrastructure
Exfiltration
Covert Channel Exfiltration of Metadata
Malware type
Spyware/Interception Tool

Vulnerabilities exploited

  • SS7 Protocol Vulnerabilities
  • Diameter Protocol Vulnerabilities

MITRE ATT&CK techniques

  • T1046
  • T1083
  • T1560.001

05Threat actor

APT41 is a highly sophisticated, prolific group known for conducting both state-sponsored espionage and financially motivated cybercrime. Their dual mandate allows them to blend intelligence gathering with profit-making activities, making attribution and defense extremely challenging.

Aliases

  • China
  • China Telecom
  • Soft Cell Operators

APT designations

  • APT41

MITRE groups

  • T1071.001
  • T1560.001

Attribution sources

  • Mandiant
  • FireEye
  • Security Research Firms

06Victims and impact

Additional victims

  • Western Governments
  • Foreign Corporations

Countries affected

  • United States
  • United Kingdom
  • Australia
  • Global

07Data exposed

Data types

  • Call Metadata
  • Location Data
  • Communication Patterns
  • Subscriber Information

08Timeline

  1. 2017-01-01Start of suspected surveillance activity targeting global telecom networks.
  2. 2018-03-01Security researchers and firms publicly disclose evidence of the operation.

09Reaction and fallout

Public reaction

The revelation sparked global alarm regarding the vulnerability of critical infrastructure and the potential for state-level mass surveillance. It intensified calls for international standards and security audits of global telecom protocols.

Political impact

The incident heightened geopolitical tensions, particularly between Western nations and China, regarding technological espionage and data sovereignty. It spurred legislative discussions on data localization and critical infrastructure protection.

Geopolitical consequences

It accelerated the trend of 'tech decoupling' and increased scrutiny of foreign technology providers in critical national infrastructure sectors.

10Legal

No specific international legal action was taken against the perpetrators, but the incident contributed to increased national cybersecurity legislation and regulatory oversight in multiple countries.

11Aftermath

Policy changes

  • Increased mandatory security audits of SS7/Diameter protocols.
  • Nationalization or strict regulation of core telecom switching equipment.

Regulatory changes

  • Stricter international guidelines for telecom protocol security.

Security improvements

  • Implementation of network segmentation and zero-trust architectures within telecom backbones.
  • Mandatory multi-factor authentication for network management access.

12Significance and legacy

Significance

Operation Soft Cell demonstrated the profound vulnerability of global telecommunications infrastructure to state-level espionage. It shifted the focus of cyber defense from merely protecting endpoints to securing the foundational protocols and physical supply chains that underpin modern communication.

Legacy

The incident has driven significant investment in securing core network protocols and has contributed to the development of more resilient, segmented, and auditable global communication standards. It serves as a prime example of 'infrastructure espionage.'

13Disclosure and media

Authentication
Technical analysis of network traffic and compromised equipment

14Field notes

  1. 01Metadata, while not the content of a call, can be used to build detailed profiles of an individual's life, habits, and associations.
  2. 02The SS7 protocol, designed decades ago, was not originally intended to be secured against modern, sophisticated state-level attacks.

15Resolution

The immediate threat was mitigated through increased security protocols and industry-wide audits, though the underlying systemic vulnerabilities remain a concern.

16Sources

Official documents

  • Mandiant Threat Reports on Telecom Compromise

References

  1. [1]Mandiant Intelligence Reports
  2. [2]Industry Security Advisories
Fact sheetEL-0205

Dates

Event
1 Jan 2018
Started
1 Jan 2017
Ended
31 Dec 2018
Discovered
1 Mar 2018
Disclosed
1 Mar 2018
Ongoing
No

Target

Organisation
Global Telecom Providers
Type
Critical Infrastructure
Sector
Telecommunications
Country
Global

Actor

Name
APT41
Type
Nation-State Actor
Nationality
Chinese
Nation-state
China
Affiliation
State-sponsored hacking group
Motivation
Economic espionage, intelligence gathering, and monitoring of foreign communications.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Massive, estimated to be petabytes of metadata
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.