APT41__2019__MESSAGETAP_Who_s_Reading_Your_Text_Messages.pdf
ID: ef25beae-fba5-49da-85b0-0585bf8d016b
STIX ID: report--ef25beae-fba5-49da-85b0-0585bf8d016b
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-11-01
Last Modified Date: 2019-11-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye Mandiant discovered MESSAGETAP, a sophisticated 64-bit ELF malware deployed by APT41 against telecommunications SMSC servers to monitor and capture SMS content and metadata. The malware parses network traffic (SCTP, SCCP, TCAP), uses XOR-decoded configuration files listing IMSIs, phone numbers and keywords to filter targets, and stores encoded results to files for later theft; the report also links the activity to CDR harvesting, provides detection names and an example sample.
