logo

APT41__2019__MESSAGETAP_Who_s_Reading_Your_Text_Messages.pdf

ID: ef25beae-fba5-49da-85b0-0585bf8d016b

STIX ID: report--ef25beae-fba5-49da-85b0-0585bf8d016b

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2019-11-01

Last Modified Date: 2019-11-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye Mandiant discovered MESSAGETAP, a sophisticated 64-bit ELF malware deployed by APT41 against telecommunications SMSC servers to monitor and capture SMS content and metadata. The malware parses network traffic (SCTP, SCCP, TCAP), uses XOR-decoded configuration files listing IMSIs, phone numbers and keywords to filter targets, and stores encoded results to files for later theft; the report also links the activity to CDR harvesting, provides detection names and an example sample.