On a malware targeting private telephony networks during cyber conflict
Iosif I. Androulidakis, Y. Kamphuis, Vasileios Vlachos · 2012
Telecommunication networks have long ago entered the Critical Infrastructure domain. The contribution of this work focuses on a malware effectively targeting Private Branch eXchanges (PBXs). Such an occurrence would have a devastating effect on the communication confidentiality, integrity and availability. This effect can further be amplified in warlike situations. At the same time, the close connection and convergence of telephony and IT infrastructure can lead to PBX disruptions having a broader impact. PBX malware could take down telecommunications, intercept sensitive calls, harvest data from call logs and lead to performing psyops during war. It can also be used to support economic fraud and money laundering and has the potential to lead to millions of Euros of damage per day, critically affecting the economic well-being of any company or organization. This contribution explores the possibilities and the technical details for such a malware, the effects it could have, the actors involved in these attacks and what the most likely targets are.