{"id":18398,"date":"2026-08-13T01:08:02","date_gmt":"2026-08-12T18:08:02","guid":{"rendered":"https:\/\/droneth.or.th\/?p=18398"},"modified":"2026-08-13T01:08:02","modified_gmt":"2026-08-12T18:08:02","slug":"unc3886-singapore-telcos-zero-day-firewall-rootkit","status":"publish","type":"post","link":"https:\/\/droneth.or.th\/en\/unc3886-singapore-telcos-zero-day-firewall-rootkit\/","title":{"rendered":"UNC3886 \u0e40\u0e08\u0e32\u0e30\u0e1c\u0e39\u0e49\u0e43\u0e2b\u0e49\u0e1a\u0e23\u0e34\u0e01\u0e32\u0e23\u0e21\u0e37\u0e2d\u0e16\u0e37\u0e2d\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c 4 \u0e23\u0e32\u0e22: Zero-Day, Firewall \u0e41\u0e25\u0e30 Rootkit"},"content":{"rendered":"<p>\u0e40\u0e14\u0e37\u0e2d\u0e19\u0e01\u0e38\u0e21\u0e20\u0e32\u0e1e\u0e31\u0e19\u0e18\u0e4c 2026 Cyber Security Agency of Singapore (CSA) \u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14 <strong>Operation Cyber Guardian<\/strong> \u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e01\u0e32\u0e23\u0e19\u0e32\u0e19 11 \u0e40\u0e14\u0e37\u0e2d\u0e19\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e23\u0e31\u0e1a\u0e21\u0e37\u0e2d UNC3886 \u0e01\u0e25\u0e38\u0e48\u0e21\u0e08\u0e32\u0e23\u0e01\u0e23\u0e23\u0e21\u0e44\u0e0b\u0e40\u0e1a\u0e2d\u0e23\u0e4c\u0e02\u0e31\u0e49\u0e19\u0e2a\u0e39\u0e07\u0e17\u0e35\u0e48\u0e21\u0e38\u0e48\u0e07\u0e40\u0e1b\u0e49\u0e32\u0e44\u0e1b\u0e22\u0e31\u0e07\u0e1c\u0e39\u0e49\u0e43\u0e2b\u0e49\u0e1a\u0e23\u0e34\u0e01\u0e32\u0e23\u0e42\u0e17\u0e23\u0e04\u0e21\u0e19\u0e32\u0e04\u0e21\u0e23\u0e32\u0e22\u0e43\u0e2b\u0e0d\u0e48\u0e17\u0e31\u0e49\u0e07 4 \u0e23\u0e32\u0e22\u0e02\u0e2d\u0e07\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c \u0e44\u0e14\u0e49\u0e41\u0e01\u0e48 M1, SIMBA Telecom, Singtel \u0e41\u0e25\u0e30 StarHub<\/p>\n<p>\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e43\u0e0a\u0e49\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48 Zero-Day \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e02\u0e49\u0e32\u0e21 perimeter firewall \u0e43\u0e19\u0e2b\u0e19\u0e36\u0e48\u0e07\u0e01\u0e23\u0e13\u0e35 \u0e41\u0e25\u0e30\u0e43\u0e0a\u0e49 rootkit \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e0b\u0e48\u0e2d\u0e19\u0e15\u0e31\u0e27\u0e43\u0e19 infrastructure \u0e2d\u0e35\u0e01\u0e01\u0e23\u0e13\u0e35 \u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c\u0e19\u0e35\u0e49\u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e15\u0e48\u0e2d\u0e20\u0e39\u0e21\u0e34\u0e20\u0e32\u0e04\u0e40\u0e2d\u0e40\u0e0a\u0e35\u0e22\u0e40\u0e1e\u0e23\u0e32\u0e30 telco \u0e40\u0e1b\u0e47\u0e19\u0e17\u0e31\u0e49\u0e07 critical infrastructure \u0e41\u0e25\u0e30\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\/\u0e40\u0e2a\u0e49\u0e19\u0e17\u0e32\u0e07\u0e2a\u0e37\u0e48\u0e2d\u0e2a\u0e32\u0e23\u0e17\u0e35\u0e48\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e08\u0e33\u0e19\u0e27\u0e19\u0e21\u0e32\u0e01<\/p>\n<p>\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23\u0e01\u0e47\u0e15\u0e32\u0e21 \u0e01\u0e32\u0e23\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e43\u0e19\u0e40\u0e14\u0e37\u0e2d\u0e19\u0e01\u0e38\u0e21\u0e20\u0e32\u0e1e\u0e31\u0e19\u0e18\u0e4c 2026 \u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e41\u0e1b\u0e25\u0e27\u0e48\u0e32\u0e01\u0e32\u0e23\u0e40\u0e08\u0e32\u0e30\u0e17\u0e31\u0e49\u0e07\u0e2b\u0e21\u0e14\u0e40\u0e23\u0e34\u0e48\u0e21\u0e43\u0e19\u0e40\u0e14\u0e37\u0e2d\u0e19\u0e19\u0e31\u0e49\u0e19 CSA \u0e40\u0e04\u0e22\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e20\u0e31\u0e22\u0e15\u0e48\u0e2d critical infrastructure \u0e15\u0e31\u0e49\u0e07\u0e41\u0e15\u0e48\u0e40\u0e14\u0e37\u0e2d\u0e19\u0e01\u0e23\u0e01\u0e0e\u0e32\u0e04\u0e21 2025 \u0e41\u0e25\u0e30\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e01\u0e32\u0e23\u0e2a\u0e37\u0e1a\u0e2a\u0e27\u0e19\u0e01\u0e34\u0e19\u0e40\u0e27\u0e25\u0e32\u0e2b\u0e25\u0e32\u0e22\u0e40\u0e14\u0e37\u0e2d\u0e19 \u0e1a\u0e17\u0e04\u0e27\u0e32\u0e21\u0e19\u0e35\u0e49\u0e08\u0e31\u0e14 timeline \u0e43\u0e2b\u0e49\u0e16\u0e39\u0e01\u0e15\u0e49\u0e2d\u0e07 \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e41\u0e22\u0e01\u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e17\u0e35\u0e48\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e41\u0e25\u0e49\u0e27\u0e2d\u0e2d\u0e01\u0e08\u0e32\u0e01\u0e2a\u0e34\u0e48\u0e07\u0e17\u0e35\u0e48\u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e1e\u0e1a\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19<\/p>\n<h2>UNC3886 \u0e04\u0e37\u0e2d\u0e43\u0e04\u0e23<\/h2>\n<p>UNC3886 \u0e40\u0e1b\u0e47\u0e19 threat cluster \u0e17\u0e35\u0e48 Mandiant \u0e15\u0e34\u0e14\u0e15\u0e32\u0e21\u0e41\u0e25\u0e30\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e42\u0e22\u0e07\u0e01\u0e31\u0e1a\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e01\u0e32\u0e23\u0e08\u0e32\u0e23\u0e01\u0e23\u0e23\u0e21\u0e23\u0e30\u0e22\u0e30\u0e22\u0e32\u0e27 \u0e01\u0e25\u0e38\u0e48\u0e21\u0e21\u0e35\u0e04\u0e27\u0e32\u0e21\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e43\u0e19\u0e01\u0e32\u0e23\u0e42\u0e08\u0e21\u0e15\u0e35\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c network\/virtualization \u0e17\u0e35\u0e48\u0e21\u0e31\u0e01\u0e44\u0e21\u0e48\u0e21\u0e35 EDR \u0e41\u0e1a\u0e1a endpoint \u0e17\u0e31\u0e48\u0e27\u0e44\u0e1b \u0e40\u0e0a\u0e48\u0e19 firewall, router, hypervisor \u0e41\u0e25\u0e30 appliance<\/p>\n<p>\u0e25\u0e31\u0e01\u0e29\u0e13\u0e30\u0e40\u0e14\u0e48\u0e19\u0e17\u0e35\u0e48\u0e23\u0e32\u0e22\u0e07\u0e32\u0e19\u0e43\u0e19\u0e2b\u0e25\u0e32\u0e22 campaign \u0e44\u0e14\u0e49\u0e41\u0e01\u0e48:<\/p>\n<ul>\n<li>\u0e43\u0e0a\u0e49 Zero-Day \u0e2b\u0e23\u0e37\u0e2d\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e17\u0e35\u0e48\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e41\u0e1e\u0e15\u0e0a\u0e4c\u0e22\u0e32\u0e01<\/li>\n<li>\u0e21\u0e38\u0e48\u0e07\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c\u0e17\u0e35\u0e48\u0e2d\u0e22\u0e39\u0e48\u0e02\u0e2d\u0e1a\u0e40\u0e04\u0e23\u0e37\u0e2d\u0e02\u0e48\u0e32\u0e22\u0e41\u0e25\u0e30\u0e21\u0e35\u0e2a\u0e34\u0e17\u0e18\u0e34\u0e4c\u0e2a\u0e39\u0e07<\/li>\n<li>\u0e43\u0e0a\u0e49 rootkit\/backdoor \u0e17\u0e35\u0e48\u0e2d\u0e2d\u0e01\u0e41\u0e1a\u0e1a\u0e15\u0e32\u0e21 platform<\/li>\n<li>\u0e02\u0e42\u0e21\u0e22 credential \u0e41\u0e25\u0e30\u0e40\u0e04\u0e25\u0e37\u0e48\u0e2d\u0e19\u0e17\u0e35\u0e48\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e40\u0e07\u0e35\u0e22\u0e1a<\/li>\n<li>\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19\u0e23\u0e30\u0e1a\u0e1a\u0e23\u0e30\u0e22\u0e30\u0e22\u0e32\u0e27\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e02\u0e48\u0e32\u0e27\u0e01\u0e23\u0e2d\u0e07 \u0e44\u0e21\u0e48\u0e40\u0e19\u0e49\u0e19\u0e2a\u0e23\u0e49\u0e32\u0e07 disruption \u0e17\u0e31\u0e19\u0e17\u0e35<\/li>\n<li>\u0e1b\u0e01\u0e1b\u0e34\u0e14 command-and-control \u0e1c\u0e48\u0e32\u0e19 trusted infrastructure \u0e2b\u0e23\u0e37\u0e2d protocol \u0e1b\u0e01\u0e15\u0e34<\/li>\n<\/ul>\n<p>CSA \u0e23\u0e30\u0e1a\u0e38\u0e20\u0e31\u0e22\u0e19\u0e35\u0e49\u0e43\u0e19\u0e1a\u0e23\u0e34\u0e1a\u0e17 national security \u0e02\u0e13\u0e30\u0e17\u0e35\u0e48\u0e2b\u0e25\u0e32\u0e22\u0e41\u0e2b\u0e25\u0e48\u0e07 threat intelligence \u0e2d\u0e18\u0e34\u0e1a\u0e32\u0e22 UNC3886 \u0e27\u0e48\u0e32\u0e40\u0e1b\u0e47\u0e19 China-nexus espionage actor \u0e01\u0e32\u0e23\u0e23\u0e30\u0e1a\u0e38 attribution \u0e04\u0e27\u0e23\u0e23\u0e31\u0e01\u0e29\u0e32\u0e23\u0e30\u0e14\u0e31\u0e1a\u0e04\u0e27\u0e32\u0e21\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21\u0e31\u0e48\u0e19\u0e41\u0e25\u0e30\u0e2d\u0e49\u0e32\u0e07\u0e41\u0e2b\u0e25\u0e48\u0e07 \u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e02\u0e22\u0e32\u0e22\u0e40\u0e1b\u0e47\u0e19\u0e02\u0e49\u0e2d\u0e01\u0e25\u0e48\u0e32\u0e27\u0e2b\u0e32\u0e17\u0e35\u0e48\u0e40\u0e01\u0e34\u0e19\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19<\/p>\n<h2>\u0e40\u0e01\u0e34\u0e14\u0e2d\u0e30\u0e44\u0e23\u0e02\u0e36\u0e49\u0e19\u0e01\u0e31\u0e1a Telco \u0e17\u0e31\u0e49\u0e07 4 \u0e23\u0e32\u0e22<\/h2>\n<p>CSA \u0e41\u0e25\u0e30\u0e1c\u0e39\u0e49\u0e43\u0e2b\u0e49\u0e1a\u0e23\u0e34\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e27\u0e48\u0e32 UNC3886 \u0e21\u0e38\u0e48\u0e07\u0e40\u0e1b\u0e49\u0e32\u0e17\u0e31\u0e49\u0e07 M1, SIMBA, Singtel \u0e41\u0e25\u0e30 StarHub \u0e40\u0e08\u0e49\u0e32\u0e2b\u0e19\u0e49\u0e32\u0e17\u0e35\u0e48\u0e1e\u0e1a intrusion \u0e2b\u0e25\u0e32\u0e22\u0e41\u0e1a\u0e1a\u0e41\u0e25\u0e30\u0e14\u0e33\u0e40\u0e19\u0e34\u0e19\u0e01\u0e32\u0e23\u0e23\u0e48\u0e27\u0e21\u0e01\u0e31\u0e19\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e02\u0e31\u0e1a\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e2d\u0e2d\u0e01\u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e17\u0e33\u0e43\u0e2b\u0e49\u0e40\u0e04\u0e23\u0e37\u0e2d\u0e02\u0e48\u0e32\u0e22\u0e2b\u0e22\u0e38\u0e14\u0e0a\u0e30\u0e07\u0e31\u0e01<\/p>\n<p>\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e35\u0e48\u0e22\u0e37\u0e19\u0e22\u0e31\u0e19\u0e43\u0e19\u0e20\u0e32\u0e1e\u0e23\u0e27\u0e21:<\/p>\n<ul>\n<li>\u0e21\u0e35\u0e01\u0e32\u0e23\u0e43\u0e0a\u0e49 Zero-Day \u0e40\u0e1e\u0e37\u0e48\u0e2d bypass perimeter firewall \u0e43\u0e19\u0e2b\u0e19\u0e36\u0e48\u0e07\u0e01\u0e23\u0e13\u0e35<\/li>\n<li>\u0e21\u0e35\u0e01\u0e32\u0e23 exfiltrate \u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e32\u0e07\u0e40\u0e17\u0e04\u0e19\u0e34\u0e04\u0e02\u0e2d\u0e07\u0e40\u0e04\u0e23\u0e37\u0e2d\u0e02\u0e48\u0e32\u0e22\u0e1b\u0e23\u0e34\u0e21\u0e32\u0e13\u0e40\u0e25\u0e47\u0e01\u0e19\u0e49\u0e2d\u0e22\u0e43\u0e19\u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c\u0e2b\u0e19\u0e36\u0e48\u0e07<\/li>\n<li>\u0e1e\u0e1a rootkit \u0e1a\u0e19 infrastructure \u0e43\u0e19\u0e2d\u0e35\u0e01\u0e01\u0e23\u0e13\u0e35<\/li>\n<li>\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e44\u0e14\u0e49 limited access \u0e15\u0e48\u0e2d\u0e1a\u0e32\u0e07\u0e2a\u0e48\u0e27\u0e19\u0e02\u0e2d\u0e07 critical infrastructure<\/li>\n<li>\u0e44\u0e21\u0e48\u0e1e\u0e1a\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e27\u0e48\u0e32\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2a\u0e48\u0e27\u0e19\u0e1a\u0e38\u0e04\u0e04\u0e25\u0e02\u0e2d\u0e07\u0e25\u0e39\u0e01\u0e04\u0e49\u0e32\u0e16\u0e39\u0e01\u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07\u0e15\u0e32\u0e21\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22<\/li>\n<li>\u0e44\u0e21\u0e48\u0e40\u0e01\u0e34\u0e14 service disruption \u0e15\u0e48\u0e2d\u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49<\/li>\n<li>\u0e17\u0e35\u0e21\u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19\u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32 100 \u0e04\u0e19\u0e08\u0e32\u0e01\u0e2b\u0e25\u0e32\u0e22\u0e2b\u0e19\u0e48\u0e27\u0e22\u0e07\u0e32\u0e19\u0e23\u0e48\u0e27\u0e21\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e01\u0e32\u0e23<\/li>\n<\/ul>\n<p>\u0e04\u0e33\u0e27\u0e48\u0e32 \u201c\u0e40\u0e08\u0e32\u0e30 telco \u0e17\u0e31\u0e49\u0e07 4 \u0e23\u0e32\u0e22\u201d \u0e08\u0e36\u0e07\u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e16\u0e39\u0e01\u0e41\u0e1b\u0e25\u0e27\u0e48\u0e32 core network \u0e17\u0e38\u0e01\u0e2a\u0e48\u0e27\u0e19\u0e16\u0e39\u0e01\u0e22\u0e36\u0e14\u0e2b\u0e23\u0e37\u0e2d\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e25\u0e39\u0e01\u0e04\u0e49\u0e32\u0e17\u0e31\u0e49\u0e07\u0e1b\u0e23\u0e30\u0e40\u0e17\u0e28\u0e23\u0e31\u0e48\u0e27 \u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c\u0e23\u0e49\u0e32\u0e22\u0e41\u0e23\u0e07\u0e40\u0e1e\u0e23\u0e32\u0e30 intent, persistence \u0e41\u0e25\u0e30 criticality \u0e41\u0e21\u0e49 public impact \u0e16\u0e39\u0e01\u0e08\u0e33\u0e01\u0e31\u0e14\u0e44\u0e27\u0e49\u0e44\u0e14\u0e49<\/p>\n<h2>Timeline \u0e17\u0e35\u0e48\u0e04\u0e27\u0e23\u0e40\u0e02\u0e49\u0e32\u0e43\u0e08<\/h2>\n<div style=\"overflow-x:auto;margin:1.5em 0;\">\n<table style=\"width:100%;border-collapse:collapse;\">\n<thead>\n<tr>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e0a\u0e48\u0e27\u0e07\u0e40\u0e27\u0e25\u0e32<\/th>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Incident<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e01\u0e48\u0e2d\u0e19 \u0e01.\u0e04. 2025<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2b\u0e19\u0e48\u0e27\u0e22\u0e07\u0e32\u0e19\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c\u0e15\u0e23\u0e27\u0e08\u0e1e\u0e1a activity \u0e17\u0e35\u0e48\u0e40\u0e01\u0e35\u0e48\u0e22\u0e27\u0e02\u0e49\u0e2d\u0e07\u0e41\u0e25\u0e30\u0e40\u0e23\u0e34\u0e48\u0e21\u0e15\u0e2d\u0e1a\u0e2a\u0e19\u0e2d\u0e07<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">18 \u0e01.\u0e04. 2025<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e27\u0e48\u0e32 UNC3886 \u0e21\u0e38\u0e48\u0e07\u0e40\u0e1b\u0e49\u0e32 critical infrastructure \u0e41\u0e15\u0e48\u0e22\u0e31\u0e07\u0e08\u0e33\u0e01\u0e31\u0e14\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e44\u0e21\u0e48\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e01\u0e32\u0e23<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e0a\u0e48\u0e27\u0e07 11 \u0e40\u0e14\u0e37\u0e2d\u0e19<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Operation Cyber Guardian \u0e23\u0e30\u0e14\u0e21 CSA, Digital and Intelligence Service, telco \u0e41\u0e25\u0e30 partner \u0e21\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32 100 \u0e04\u0e19<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">9 \u0e01.\u0e1e. 2026<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">CSA \u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14\u0e21\u0e32\u0e01\u0e02\u0e36\u0e49\u0e19\u0e2b\u0e25\u0e31\u0e07 containment\/eradication \u0e23\u0e30\u0e14\u0e31\u0e1a\u0e2a\u0e33\u0e04\u0e31\u0e0d<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2b\u0e25\u0e31\u0e07\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e14\u0e33\u0e40\u0e19\u0e34\u0e19 hardening, monitoring \u0e41\u0e25\u0e30 sector-wide learning \u0e15\u0e48\u0e2d\u0e40\u0e19\u0e37\u0e48\u0e2d\u0e07<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>\u0e01\u0e32\u0e23\u0e23\u0e30\u0e1a\u0e38\u0e02\u0e48\u0e32\u0e27\u0e40\u0e1b\u0e47\u0e19 \u201c\u0e01.\u0e1e. 2026\u201d \u0e08\u0e36\u0e07\u0e2b\u0e21\u0e32\u0e22\u0e16\u0e36\u0e07\u0e0a\u0e48\u0e27\u0e07\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14 \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e27\u0e31\u0e19\u0e40\u0e23\u0e34\u0e48\u0e21\u0e01\u0e32\u0e23\u0e42\u0e08\u0e21\u0e15\u0e35<\/p>\n<h2>\u0e17\u0e33\u0e44\u0e21 Telco \u0e08\u0e36\u0e07\u0e40\u0e1b\u0e47\u0e19\u0e40\u0e1b\u0e49\u0e32\u0e2b\u0e21\u0e32\u0e22\u0e21\u0e39\u0e25\u0e04\u0e48\u0e32\u0e2a\u0e39\u0e07<\/h2>\n<h3>\u0e21\u0e2d\u0e07\u0e40\u0e2b\u0e47\u0e19\u0e42\u0e04\u0e23\u0e07\u0e2a\u0e23\u0e49\u0e32\u0e07\u0e01\u0e32\u0e23\u0e2a\u0e37\u0e48\u0e2d\u0e2a\u0e32\u0e23<\/h3>\n<p>\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25 configuration, topology \u0e41\u0e25\u0e30 operational metadata \u0e0a\u0e48\u0e27\u0e22 actor \u0e40\u0e02\u0e49\u0e32\u0e43\u0e08\u0e27\u0e48\u0e32 traffic \u0e44\u0e2b\u0e25\u0e1c\u0e48\u0e32\u0e19\u0e08\u0e38\u0e14\u0e43\u0e14 \u0e41\u0e25\u0e30 infrastructure \u0e43\u0e14\u0e2a\u0e33\u0e04\u0e31\u0e0d<\/p>\n<h3>\u0e40\u0e1b\u0e47\u0e19\u0e17\u0e32\u0e07\u0e1c\u0e48\u0e32\u0e19\u0e2a\u0e39\u0e48\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e2d\u0e37\u0e48\u0e19<\/h3>\n<p>Telco \u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e21 government, enterprise, data center, cloud \u0e41\u0e25\u0e30\u0e1c\u0e39\u0e49\u0e43\u0e0a\u0e49\u0e08\u0e33\u0e19\u0e27\u0e19\u0e21\u0e32\u0e01 \u0e01\u0e32\u0e23\u0e44\u0e14\u0e49 foothold \u0e1a\u0e32\u0e07\u0e15\u0e33\u0e41\u0e2b\u0e19\u0e48\u0e07\u0e2d\u0e32\u0e08\u0e2a\u0e23\u0e49\u0e32\u0e07\u0e42\u0e2d\u0e01\u0e32\u0e2a surveillance \u0e2b\u0e23\u0e37\u0e2d follow-on operation<\/p>\n<h3>Availability \u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e23\u0e30\u0e14\u0e31\u0e1a\u0e1b\u0e23\u0e30\u0e40\u0e17\u0e28<\/h3>\n<p>\u0e41\u0e21\u0e49 espionage actor \u0e44\u0e21\u0e48\u0e17\u0e33\u0e25\u0e32\u0e22\u0e23\u0e30\u0e1a\u0e1a\u0e17\u0e31\u0e19\u0e17\u0e35 \u0e01\u0e32\u0e23\u0e21\u0e35 persistence \u0e1a\u0e19 critical infrastructure \u0e2a\u0e23\u0e49\u0e32\u0e07 strategic option \u0e43\u0e19\u0e2d\u0e19\u0e32\u0e04\u0e15<\/p>\n<h3>Appliance Visibility \u0e15\u0e48\u0e33<\/h3>\n<p>Firewall\/router \u0e21\u0e31\u0e01\u0e21\u0e35 log \u0e08\u0e33\u0e01\u0e31\u0e14 agent \u0e15\u0e34\u0e14\u0e15\u0e31\u0e49\u0e07\u0e44\u0e21\u0e48\u0e44\u0e14\u0e49 \u0e41\u0e25\u0e30 forensic acquisition \u0e22\u0e32\u0e01\u0e01\u0e27\u0e48\u0e32 server \u0e17\u0e31\u0e48\u0e27\u0e44\u0e1b \u0e17\u0e33\u0e43\u0e2b\u0e49 attacker \u0e0b\u0e48\u0e2d\u0e19\u0e15\u0e31\u0e27\u0e44\u0e14\u0e49\u0e19\u0e32\u0e19<\/p>\n<h2>Zero-Day Firewall Bypass \u0e2a\u0e2d\u0e19\u0e2d\u0e30\u0e44\u0e23<\/h2>\n<p>Firewall \u0e21\u0e31\u0e01\u0e16\u0e39\u0e01\u0e21\u0e2d\u0e07\u0e40\u0e1b\u0e47\u0e19\u0e41\u0e19\u0e27\u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19 \u0e41\u0e15\u0e48\u0e15\u0e31\u0e27\u0e21\u0e31\u0e19\u0e40\u0e2d\u0e07\u0e40\u0e1b\u0e47\u0e19 computer \u0e17\u0e35\u0e48\u0e21\u0e35 management interface, parser, operating system \u0e41\u0e25\u0e30 privilege \u0e2a\u0e39\u0e07 \u0e2b\u0e32\u0e01\u0e16\u0e39\u0e01 exploit \u0e21\u0e31\u0e19\u0e2d\u0e32\u0e08\u0e01\u0e25\u0e32\u0e22\u0e40\u0e1b\u0e47\u0e19:<\/p>\n<ul>\n<li>\u0e08\u0e38\u0e14\u0e14\u0e31\u0e01 credential\/traffic metadata<\/li>\n<li>pivot \u0e23\u0e30\u0e2b\u0e27\u0e48\u0e32\u0e07 network zone<\/li>\n<li>covert channel \u0e2d\u0e2d\u0e01\u0e19\u0e2d\u0e01\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23<\/li>\n<li>\u0e17\u0e35\u0e48\u0e0b\u0e48\u0e2d\u0e19 persistence \u0e17\u0e35\u0e48 EDR \u0e21\u0e2d\u0e07\u0e44\u0e21\u0e48\u0e40\u0e2b\u0e47\u0e19<\/li>\n<li>\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e41\u0e01\u0e49 policy \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e2a\u0e49\u0e19\u0e17\u0e32\u0e07\u0e43\u0e2b\u0e21\u0e48<\/li>\n<\/ul>\n<p>\u0e41\u0e19\u0e27\u0e04\u0e34\u0e14 \u201c\u0e21\u0e35 firewall \u0e41\u0e25\u0e49\u0e27\u0e1b\u0e25\u0e2d\u0e14\u0e20\u0e31\u0e22\u201d \u0e08\u0e36\u0e07\u0e44\u0e21\u0e48\u0e1e\u0e2d \u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35 <strong>security of the security control<\/strong> \u0e44\u0e14\u0e49\u0e41\u0e01\u0e48 patching, configuration baseline, management isolation, integrity monitoring \u0e41\u0e25\u0e30 out-of-band log<\/p>\n<h2>Rootkit \u0e1a\u0e19 Network Infrastructure \u0e2d\u0e31\u0e19\u0e15\u0e23\u0e32\u0e22\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e44\u0e23<\/h2>\n<p>Rootkit \u0e21\u0e35\u0e40\u0e1b\u0e49\u0e32\u0e2b\u0e21\u0e32\u0e22\u0e0b\u0e48\u0e2d\u0e19 process, file, network connection \u0e2b\u0e23\u0e37\u0e2d modification \u0e08\u0e32\u0e01\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e21\u0e37\u0e2d\u0e1b\u0e01\u0e15\u0e34 \u0e1a\u0e19 appliance \u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e23\u0e38\u0e19\u0e41\u0e23\u0e07\u0e02\u0e36\u0e49\u0e19\u0e40\u0e1e\u0e23\u0e32\u0e30 defender \u0e2d\u0e32\u0e08\u0e44\u0e21\u0e48\u0e21\u0e35 trusted sensor \u0e20\u0e32\u0e22\u0e43\u0e19\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07<\/p>\n<p>\u0e2a\u0e31\u0e0d\u0e0d\u0e32\u0e13\u0e17\u0e35\u0e48\u0e04\u0e27\u0e23\u0e1e\u0e34\u0e08\u0e32\u0e23\u0e13\u0e32:<\/p>\n<ul>\n<li>image\/hash \u0e41\u0e15\u0e01\u0e15\u0e48\u0e32\u0e07\u0e08\u0e32\u0e01 vendor baseline<\/li>\n<li>process \u0e2b\u0e23\u0e37\u0e2d module \u0e17\u0e35\u0e48\u0e44\u0e21\u0e48\u0e2d\u0e22\u0e39\u0e48\u0e43\u0e19 supported inventory<\/li>\n<li>boot\/startup behavior \u0e1c\u0e34\u0e14\u0e1b\u0e01\u0e15\u0e34<\/li>\n<li>outbound session \u0e17\u0e35\u0e48 config \u0e44\u0e21\u0e48\u0e2d\u0e18\u0e34\u0e1a\u0e32\u0e22<\/li>\n<li>account\/key \u0e43\u0e2b\u0e21\u0e48\u0e1a\u0e19 management plane<\/li>\n<li>log gap \u0e2b\u0e23\u0e37\u0e2d timestamp anomaly<\/li>\n<li>device behavior \u0e44\u0e21\u0e48\u0e15\u0e23\u0e07\u0e01\u0e31\u0e1a running configuration<\/li>\n<\/ul>\n<p>\u0e40\u0e21\u0e37\u0e48\u0e2d\u0e2a\u0e07\u0e2a\u0e31\u0e22 rootkit \u0e01\u0e32\u0e23 \u201c\u0e25\u0e1a\u0e44\u0e1f\u0e25\u0e4c\u201d \u0e44\u0e21\u0e48\u0e1e\u0e2d \u0e04\u0e27\u0e23\u0e1b\u0e23\u0e30\u0e2a\u0e32\u0e19 vendor\/IR \u0e40\u0e1e\u0e37\u0e48\u0e2d re-image \u0e08\u0e32\u0e01 trusted image, rotate credential \u0e41\u0e25\u0e30\u0e15\u0e23\u0e27\u0e08 neighbor system \u0e40\u0e1e\u0e23\u0e32\u0e30\u0e04\u0e27\u0e32\u0e21\u0e40\u0e0a\u0e37\u0e48\u0e2d\u0e16\u0e37\u0e2d\u0e02\u0e2d\u0e07 OS \u0e16\u0e39\u0e01\u0e17\u0e33\u0e25\u0e32\u0e22\u0e41\u0e25\u0e49\u0e27<\/p>\n<h2>Operation Cyber Guardian \u0e17\u0e33\u0e44\u0e21\u0e15\u0e49\u0e2d\u0e07\u0e43\u0e0a\u0e49 11 \u0e40\u0e14\u0e37\u0e2d\u0e19<\/h2>\n<p>\u0e01\u0e32\u0e23\u0e02\u0e31\u0e1a APT \u0e2d\u0e2d\u0e01\u0e08\u0e32\u0e01 telco \u0e44\u0e21\u0e48\u0e40\u0e2b\u0e21\u0e37\u0e2d\u0e19 cleanup malware \u0e1a\u0e19 laptop \u0e2b\u0e19\u0e36\u0e48\u0e07\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07 \u0e17\u0e35\u0e21\u0e15\u0e49\u0e2d\u0e07:<\/p>\n<ol>\n<li>\u0e40\u0e02\u0e49\u0e32\u0e43\u0e08 foothold \u0e41\u0e25\u0e30 persistence \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e40\u0e15\u0e37\u0e2d\u0e19 attacker \u0e40\u0e23\u0e47\u0e27\u0e40\u0e01\u0e34\u0e19\u0e44\u0e1b<\/li>\n<li>\u0e23\u0e30\u0e1a\u0e38 dependency \u0e02\u0e2d\u0e07\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c critical<\/li>\n<li>\u0e2a\u0e23\u0e49\u0e32\u0e07 patched image\/mitigation \u0e23\u0e48\u0e27\u0e21\u0e01\u0e31\u0e1a vendor<\/li>\n<li>\u0e40\u0e15\u0e23\u0e35\u0e22\u0e21 credential rotation \u0e41\u0e25\u0e30 network change \u0e08\u0e33\u0e19\u0e27\u0e19\u0e21\u0e32\u0e01<\/li>\n<li>\u0e01\u0e33\u0e2b\u0e19\u0e14 cutover \u0e43\u0e2b\u0e49\u0e1c\u0e39\u0e49\u0e42\u0e08\u0e21\u0e15\u0e35\u0e44\u0e21\u0e48\u0e21\u0e35\u0e40\u0e2a\u0e49\u0e19\u0e17\u0e32\u0e07\u0e01\u0e25\u0e31\u0e1a<\/li>\n<li>\u0e23\u0e31\u0e01\u0e29\u0e32\u0e04\u0e27\u0e32\u0e21\u0e15\u0e48\u0e2d\u0e40\u0e19\u0e37\u0e48\u0e2d\u0e07\u0e1a\u0e23\u0e34\u0e01\u0e32\u0e23\u0e02\u0e2d\u0e07\u0e1b\u0e23\u0e30\u0e0a\u0e32\u0e0a\u0e19<\/li>\n<li>monitor \u0e01\u0e32\u0e23 re-entry \u0e2b\u0e25\u0e31\u0e07 eradication<\/li>\n<\/ol>\n<p>\u0e2b\u0e32\u0e01\u0e23\u0e35\u0e1a\u0e1b\u0e34\u0e14 device \u0e2b\u0e19\u0e36\u0e48\u0e07\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07 attacker \u0e2d\u0e32\u0e08\u0e22\u0e49\u0e32\u0e22\u0e44\u0e1b foothold \u0e17\u0e35\u0e48\u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e1e\u0e1a \u0e41\u0e25\u0e30\u0e40\u0e23\u0e35\u0e22\u0e19\u0e23\u0e39\u0e49\u0e27\u0e34\u0e18\u0e35\u0e15\u0e23\u0e27\u0e08\u0e08\u0e31\u0e1a\u0e02\u0e2d\u0e07 defender \u0e01\u0e32\u0e23\u0e1b\u0e23\u0e30\u0e2a\u0e32\u0e19\u0e23\u0e30\u0e14\u0e31\u0e1a sector \u0e08\u0e36\u0e07\u0e21\u0e35\u0e04\u0e38\u0e13\u0e04\u0e48\u0e32\u0e21\u0e32\u0e01<\/p>\n<h2>\u0e1a\u0e17\u0e40\u0e23\u0e35\u0e22\u0e19\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e1c\u0e39\u0e49\u0e43\u0e2b\u0e49\u0e1a\u0e23\u0e34\u0e01\u0e32\u0e23\u0e41\u0e25\u0e30\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e44\u0e17\u0e22<\/h2>\n<h3>1. \u0e17\u0e33 Inventory \u0e02\u0e2d\u0e07 Network Appliance<\/h3>\n<p>\u0e15\u0e49\u0e2d\u0e07\u0e23\u0e39\u0e49 vendor, model, OS\/firmware, support status, management IP, owner \u0e41\u0e25\u0e30 critical path \u0e02\u0e2d\u0e07 router\/firewall\/VPN \u0e17\u0e38\u0e01\u0e15\u0e31\u0e27 \u0e23\u0e27\u0e21\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c\u0e2a\u0e32\u0e02\u0e32\u0e41\u0e25\u0e30 DR<\/p>\n<h3>2. \u0e41\u0e22\u0e01 Management Plane<\/h3>\n<ul>\n<li>\u0e44\u0e21\u0e48\u0e40\u0e1b\u0e34\u0e14 admin interface \u0e15\u0e48\u0e2d internet<\/li>\n<li>\u0e43\u0e0a\u0e49 dedicated management network<\/li>\n<li>\u0e1a\u0e31\u0e07\u0e04\u0e31\u0e1a MFA\/jump host<\/li>\n<li>\u0e08\u0e33\u0e01\u0e31\u0e14 source IP \u0e41\u0e25\u0e30 protocol<\/li>\n<li>\u0e43\u0e0a\u0e49 admin account \u0e41\u0e22\u0e01\u0e08\u0e32\u0e01 daily account<\/li>\n<li>\u0e40\u0e01\u0e47\u0e1a log \u0e19\u0e2d\u0e01\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c<\/li>\n<\/ul>\n<h3>3. \u0e40\u0e15\u0e23\u0e35\u0e22\u0e21 Emergency Patch Process<\/h3>\n<p>Zero-Day \u0e1a\u0e19 telco appliance \u0e2d\u0e32\u0e08\u0e44\u0e21\u0e48\u0e21\u0e35\u0e40\u0e27\u0e25\u0e32\u0e23\u0e2d change cycle \u0e1b\u0e01\u0e15\u0e34 \u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35 canary, spare capacity, vendor escalation, rollback \u0e41\u0e25\u0e30 business approval \u0e25\u0e48\u0e27\u0e07\u0e2b\u0e19\u0e49\u0e32<\/p>\n<h3>4. Monitor Integrity \u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48\u0e41\u0e04\u0e48 Traffic<\/h3>\n<p>Network monitoring \u0e40\u0e2b\u0e47\u0e19 flow \u0e41\u0e15\u0e48 rootkit \u0e2d\u0e32\u0e08\u0e0b\u0e48\u0e2d\u0e19 activity \u0e15\u0e49\u0e2d\u0e07\u0e40\u0e2a\u0e23\u0e34\u0e21 configuration diff, image validation, boot measurement, privileged audit \u0e41\u0e25\u0e30 vendor-supported forensic collection<\/p>\n<h3>5. \u0e1d\u0e36\u0e01 Sector Coordination<\/h3>\n<p>IoC, TTP \u0e41\u0e25\u0e30 mitigation \u0e02\u0e2d\u0e07 telco \u0e2b\u0e19\u0e36\u0e48\u0e07\u0e23\u0e32\u0e22\u0e2d\u0e32\u0e08\u0e0a\u0e48\u0e27\u0e22\u0e2d\u0e35\u0e01\u0e2b\u0e25\u0e32\u0e22\u0e23\u0e32\u0e22 \u0e04\u0e27\u0e23\u0e01\u0e33\u0e2b\u0e19\u0e14\u0e0a\u0e48\u0e2d\u0e07\u0e17\u0e32\u0e07\u0e41\u0e25\u0e01\u0e40\u0e1b\u0e25\u0e35\u0e48\u0e22\u0e19\u0e17\u0e35\u0e48\u0e23\u0e31\u0e01\u0e29\u0e32\u0e04\u0e27\u0e32\u0e21\u0e25\u0e31\u0e1a\u0e41\u0e25\u0e30\u0e15\u0e31\u0e14\u0e2a\u0e34\u0e19\u0e43\u0e08\u0e44\u0e14\u0e49\u0e40\u0e23\u0e47\u0e27\u0e23\u0e48\u0e27\u0e21\u0e01\u0e31\u0e1a ThaiCERT\/sector regulator\/vendor<\/p>\n<h2>Detection \u0e41\u0e25\u0e30 Threat Hunting \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a Appliance<\/h2>\n<p>\u0e17\u0e35\u0e21\u0e04\u0e27\u0e23\u0e2a\u0e23\u0e49\u0e32\u0e07 telemetry \u0e08\u0e32\u0e01\u0e2b\u0e25\u0e32\u0e22\u0e0a\u0e31\u0e49\u0e19:<\/p>\n<div style=\"overflow-x:auto;margin:1.5em 0;\">\n<table style=\"width:100%;border-collapse:collapse;\">\n<thead>\n<tr>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e0a\u0e31\u0e49\u0e19<\/th>\n<th style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">\u0e2a\u0e34\u0e48\u0e07\u0e17\u0e35\u0e48\u0e15\u0e23\u0e27\u0e08<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Device<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">version, process, module, config, admin event<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Network<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">management access, new outbound flow, tunneling<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Identity<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">admin login, key\/token change, impossible travel<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">Neighbor<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">ARP\/routing change, unexpected session from appliance<\/td>\n<\/tr>\n<tr>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">External<\/td>\n<td style=\"border:1px solid #ddd;padding:.5em .75em;text-align:left;vertical-align:top;\">threat intelligence, vendor IoC, certificate\/domain<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>\u0e2b\u0e25\u0e31\u0e01\u0e01\u0e32\u0e23\u0e2a\u0e33\u0e04\u0e31\u0e0d\u0e04\u0e37\u0e2d\u0e2d\u0e22\u0e48\u0e32\u0e43\u0e0a\u0e49 log \u0e08\u0e32\u0e01\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c\u0e17\u0e35\u0e48\u0e2d\u0e32\u0e08\u0e16\u0e39\u0e01\u0e22\u0e36\u0e14\u0e40\u0e1b\u0e47\u0e19\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e0a\u0e38\u0e14\u0e40\u0e14\u0e35\u0e22\u0e27 \u0e2a\u0e48\u0e07 log \u0e41\u0e1a\u0e1a near-real-time \u0e44\u0e1b immutable\/external collector \u0e41\u0e25\u0e30\u0e40\u0e17\u0e35\u0e22\u0e1a\u0e01\u0e31\u0e1a network sensor<\/p>\n<h2>\u0e41\u0e19\u0e27\u0e17\u0e32\u0e07 Penetration Testing \u0e41\u0e25\u0e30 Red Team<\/h2>\n<p>\u0e01\u0e32\u0e23\u0e17\u0e14\u0e2a\u0e2d\u0e1a telco\/critical network \u0e21\u0e35\u0e04\u0e27\u0e32\u0e21\u0e40\u0e2a\u0e35\u0e48\u0e22\u0e07\u0e2a\u0e39\u0e07 \u0e04\u0e27\u0e23\u0e41\u0e22\u0e01\u0e01\u0e34\u0e08\u0e01\u0e23\u0e23\u0e21:<\/p>\n<ul>\n<li><strong>Configuration assessment:<\/strong> \u0e15\u0e23\u0e27\u0e08 management exposure, legacy protocol, AAA, SNMP, logging<\/li>\n<li><strong>Non-destructive validation:<\/strong> \u0e15\u0e23\u0e27\u0e08 version\/advisory \u0e41\u0e25\u0e30 control path \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48 exploit<\/li>\n<li><strong>Lab exploit validation:<\/strong> reproduce \u0e1a\u0e19\u0e23\u0e38\u0e48\u0e19\u0e40\u0e14\u0e35\u0e22\u0e27\u0e01\u0e31\u0e19\u0e43\u0e19 isolated lab<\/li>\n<li><strong>Assumed-breach exercise:<\/strong> \u0e40\u0e23\u0e34\u0e48\u0e21\u0e08\u0e32\u0e01 foothold \u0e08\u0e33\u0e25\u0e2d\u0e07\u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e17\u0e14\u0e2a\u0e2d\u0e1a segmentation\/detection<\/li>\n<li><strong>Purple-team emulation:<\/strong> \u0e08\u0e33\u0e25\u0e2d\u0e07 TTP \u0e02\u0e2d\u0e07 UNC3886 \u0e42\u0e14\u0e22\u0e44\u0e21\u0e48\u0e43\u0e0a\u0e49 Zero-Day \u0e08\u0e23\u0e34\u0e07<\/li>\n<li><strong>Tabletop:<\/strong> \u0e1d\u0e36\u0e01 coordinated eradication \u0e41\u0e25\u0e30 public communication<\/li>\n<\/ul>\n<p>Rules of Engagement \u0e15\u0e49\u0e2d\u0e07\u0e21\u0e35 no-go system, latency\/availability threshold, vendor contact \u0e41\u0e25\u0e30 kill switch \u0e40\u0e1e\u0e23\u0e32\u0e30 packet \u0e2b\u0e23\u0e37\u0e2d reboot \u0e1c\u0e34\u0e14\u0e08\u0e31\u0e07\u0e2b\u0e27\u0e30\u0e2d\u0e32\u0e08\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e25\u0e39\u0e01\u0e04\u0e49\u0e32\u0e08\u0e33\u0e19\u0e27\u0e19\u0e21\u0e32\u0e01<\/p>\n<h2>Incident Response \u0e40\u0e21\u0e37\u0e48\u0e2d\u0e2a\u0e07\u0e2a\u0e31\u0e22 Network Appliance \u0e16\u0e39\u0e01\u0e22\u0e36\u0e14<\/h2>\n<ol>\n<li>\u0e40\u0e1b\u0e34\u0e14 incident \u0e23\u0e30\u0e14\u0e31\u0e1a\u0e2a\u0e39\u0e07\u0e41\u0e25\u0e30\u0e23\u0e31\u0e01\u0e29\u0e32\u0e04\u0e27\u0e32\u0e21\u0e25\u0e31\u0e1a\u0e41\u0e1a\u0e1a need-to-know<\/li>\n<li>\u0e40\u0e01\u0e47\u0e1a external telemetry \u0e41\u0e25\u0e30 configuration snapshot \u0e15\u0e32\u0e21 vendor guidance<\/li>\n<li>\u0e23\u0e30\u0e1a\u0e38 adjacent system \u0e41\u0e25\u0e30 credential \u0e17\u0e35\u0e48 appliance \u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07\u0e44\u0e14\u0e49<\/li>\n<li>\u0e2b\u0e25\u0e35\u0e01\u0e40\u0e25\u0e35\u0e48\u0e22\u0e07 reboot \u0e17\u0e31\u0e19\u0e17\u0e35\u0e2b\u0e32\u0e01\u0e08\u0e30\u0e17\u0e33\u0e43\u0e2b\u0e49 volatile evidence \u0e2b\u0e32\u0e22 \u0e40\u0e27\u0e49\u0e19\u0e41\u0e15\u0e48\u0e15\u0e49\u0e2d\u0e07\u0e2b\u0e22\u0e38\u0e14\u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e40\u0e23\u0e48\u0e07\u0e14\u0e48\u0e27\u0e19<\/li>\n<li>\u0e1b\u0e23\u0e30\u0e2a\u0e32\u0e19 vendor\/sector authority \u0e40\u0e1e\u0e37\u0e48\u0e2d\u0e23\u0e31\u0e1a fixed image \u0e41\u0e25\u0e30 IoC<\/li>\n<li>\u0e27\u0e32\u0e07\u0e41\u0e1c\u0e19 synchronized containment \u0e2b\u0e25\u0e32\u0e22 foothold<\/li>\n<li>re-image \u0e08\u0e32\u0e01 trusted source \u0e41\u0e17\u0e19 cleanup \u0e40\u0e09\u0e1e\u0e32\u0e30\u0e44\u0e1f\u0e25\u0e4c\u0e40\u0e21\u0e37\u0e48\u0e2d\u0e2a\u0e07\u0e2a\u0e31\u0e22 rootkit<\/li>\n<li>rotate admin key, certificate \u0e41\u0e25\u0e30 service credential<\/li>\n<li>monitor re-entry \u0e41\u0e25\u0e30\u0e40\u0e1b\u0e23\u0e35\u0e22\u0e1a\u0e40\u0e17\u0e35\u0e22\u0e1a baseline \u0e15\u0e48\u0e2d\u0e40\u0e19\u0e37\u0e48\u0e2d\u0e07<\/li>\n<li>\u0e2a\u0e37\u0e48\u0e2d\u0e2a\u0e32\u0e23\u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e42\u0e14\u0e22\u0e41\u0e22\u0e01 confirmed fact \u0e08\u0e32\u0e01 assessment<\/li>\n<\/ol>\n<h2>Checklist \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a Critical Network<\/h2>\n<ul>\n<li>inventory appliance \u0e41\u0e25\u0e30 support status \u0e04\u0e23\u0e1a<\/li>\n<li>\u0e1b\u0e34\u0e14 internet-facing management<\/li>\n<li>\u0e41\u0e22\u0e01 management plane \u0e41\u0e25\u0e30\u0e43\u0e0a\u0e49 MFA<\/li>\n<li>\u0e40\u0e01\u0e47\u0e1a log \u0e19\u0e2d\u0e01\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c<\/li>\n<li>\u0e21\u0e35 config\/image integrity baseline<\/li>\n<li>\u0e17\u0e14\u0e2a\u0e2d\u0e1a emergency patch\/canary\/rollback<\/li>\n<li>\u0e21\u0e35 vendor escalation contact 24\u00d77<\/li>\n<li>rotate credential \u0e15\u0e32\u0e21 risk \u0e41\u0e25\u0e30\u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c<\/li>\n<li>tabletop APT persistence \u0e1a\u0e19\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c<\/li>\n<li>\u0e21\u0e35\u0e0a\u0e48\u0e2d\u0e07\u0e17\u0e32\u0e07\u0e41\u0e1a\u0e48\u0e07\u0e1b\u0e31\u0e19 IoC \u0e01\u0e31\u0e1a\u0e2b\u0e19\u0e48\u0e27\u0e22\u0e07\u0e32\u0e19\/\u0e04\u0e39\u0e48\u0e04\u0e49\u0e32<\/li>\n<\/ul>\n<h2>FAQ<\/h2>\n<h3>UNC3886 \u0e40\u0e08\u0e32\u0e30\u0e1c\u0e39\u0e49\u0e43\u0e2b\u0e49\u0e1a\u0e23\u0e34\u0e01\u0e32\u0e23\u0e21\u0e37\u0e2d\u0e16\u0e37\u0e2d\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c\u0e17\u0e31\u0e49\u0e07 4 \u0e23\u0e32\u0e22\u0e08\u0e23\u0e34\u0e07\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>CSA \u0e23\u0e30\u0e1a\u0e38\u0e27\u0e48\u0e32\u0e01\u0e25\u0e38\u0e48\u0e21\u0e21\u0e38\u0e48\u0e07\u0e40\u0e1b\u0e49\u0e32\u0e41\u0e25\u0e30\u0e21\u0e35 intrusion \u0e17\u0e35\u0e48\u0e40\u0e01\u0e35\u0e48\u0e22\u0e27\u0e02\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e1a\u0e17\u0e31\u0e49\u0e07 M1, SIMBA, Singtel \u0e41\u0e25\u0e30 StarHub \u0e41\u0e15\u0e48\u0e23\u0e30\u0e14\u0e31\u0e1a\u0e1c\u0e25\u0e01\u0e23\u0e30\u0e17\u0e1a\u0e41\u0e25\u0e30\u0e40\u0e17\u0e04\u0e19\u0e34\u0e04\u0e02\u0e2d\u0e07\u0e41\u0e15\u0e48\u0e25\u0e30\u0e23\u0e32\u0e22\u0e44\u0e21\u0e48\u0e40\u0e2b\u0e21\u0e37\u0e2d\u0e19\u0e01\u0e31\u0e19<\/p>\n<h3>\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e25\u0e39\u0e01\u0e04\u0e49\u0e32\u0e16\u0e39\u0e01\u0e02\u0e42\u0e21\u0e22\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e15\u0e32\u0e21\u0e01\u0e32\u0e23\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e02\u0e2d\u0e07 CSA \u0e44\u0e21\u0e48\u0e1e\u0e1a\u0e2b\u0e25\u0e31\u0e01\u0e10\u0e32\u0e19\u0e27\u0e48\u0e32\u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e2a\u0e48\u0e27\u0e19\u0e1a\u0e38\u0e04\u0e04\u0e25\u0e02\u0e2d\u0e07\u0e25\u0e39\u0e01\u0e04\u0e49\u0e32\u0e16\u0e39\u0e01\u0e40\u0e02\u0e49\u0e32\u0e16\u0e36\u0e07 \u0e41\u0e25\u0e30\u0e44\u0e21\u0e48\u0e21\u0e35 service disruption \u0e02\u0e49\u0e2d\u0e21\u0e39\u0e25\u0e17\u0e32\u0e07\u0e40\u0e17\u0e04\u0e19\u0e34\u0e04\u0e02\u0e2d\u0e07\u0e40\u0e04\u0e23\u0e37\u0e2d\u0e02\u0e48\u0e32\u0e22\u0e1b\u0e23\u0e34\u0e21\u0e32\u0e13\u0e40\u0e25\u0e47\u0e01\u0e19\u0e49\u0e2d\u0e22\u0e16\u0e39\u0e01 exfiltrate \u0e43\u0e19\u0e2b\u0e19\u0e36\u0e48\u0e07\u0e01\u0e23\u0e13\u0e35<\/p>\n<h3>\u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c\u0e40\u0e23\u0e34\u0e48\u0e21\u0e40\u0e14\u0e37\u0e2d\u0e19\u0e01\u0e38\u0e21\u0e20\u0e32\u0e1e\u0e31\u0e19\u0e18\u0e4c 2026 \u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e44\u0e21\u0e48\u0e43\u0e0a\u0e48 \u0e01\u0e38\u0e21\u0e20\u0e32\u0e1e\u0e31\u0e19\u0e18\u0e4c\u0e40\u0e1b\u0e47\u0e19\u0e0a\u0e48\u0e27\u0e07\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e23\u0e32\u0e22\u0e25\u0e30\u0e40\u0e2d\u0e35\u0e22\u0e14 Operation Cyber Guardian \u0e43\u0e0a\u0e49\u0e40\u0e27\u0e25\u0e32\u0e1b\u0e23\u0e30\u0e21\u0e32\u0e13 11 \u0e40\u0e14\u0e37\u0e2d\u0e19 \u0e41\u0e25\u0e30\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c\u0e40\u0e04\u0e22\u0e40\u0e1b\u0e34\u0e14\u0e40\u0e1c\u0e22\u0e20\u0e31\u0e22\u0e15\u0e48\u0e2d critical infrastructure \u0e15\u0e31\u0e49\u0e07\u0e41\u0e15\u0e48\u0e01\u0e23\u0e01\u0e0e\u0e32\u0e04\u0e21 2025<\/p>\n<h3>Firewall \u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19 Zero-Day \u0e17\u0e35\u0e48\u0e42\u0e08\u0e21\u0e15\u0e35\u0e15\u0e31\u0e27 Firewall \u0e40\u0e2d\u0e07\u0e44\u0e14\u0e49\u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e1e\u0e36\u0e48\u0e07 control \u0e15\u0e31\u0e27\u0e40\u0e14\u0e35\u0e22\u0e27 \u0e15\u0e49\u0e2d\u0e07\u0e25\u0e14 management exposure, patch\/mitigate, \u0e41\u0e22\u0e01 zone, \u0e40\u0e01\u0e47\u0e1a log \u0e20\u0e32\u0e22\u0e19\u0e2d\u0e01 \u0e41\u0e25\u0e30\u0e21\u0e35 sensor \u0e17\u0e35\u0e48\u0e21\u0e2d\u0e07 activity \u0e08\u0e32\u0e01\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c\u0e44\u0e14\u0e49<\/p>\n<h3>\u0e04\u0e27\u0e23\u0e17\u0e14\u0e2a\u0e2d\u0e1a public exploit \u0e01\u0e31\u0e1a Firewall production \u0e2b\u0e23\u0e37\u0e2d\u0e44\u0e21\u0e48<\/h3>\n<p>\u0e44\u0e21\u0e48\u0e04\u0e27\u0e23\u0e42\u0e14\u0e22\u0e1b\u0e23\u0e34\u0e22\u0e32\u0e22 \u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a critical network \u0e43\u0e2b\u0e49 validate version\/configuration \u0e41\u0e25\u0e30 reproduce \u0e43\u0e19 lab \u0e01\u0e32\u0e23\u0e17\u0e14\u0e2a\u0e2d\u0e1a production \u0e15\u0e49\u0e2d\u0e07\u0e44\u0e14\u0e49\u0e23\u0e31\u0e1a\u0e2d\u0e19\u0e38\u0e21\u0e31\u0e15\u0e34\u0e0a\u0e31\u0e14\u0e40\u0e08\u0e19 \u0e21\u0e35 vendor support \u0e41\u0e25\u0e30 stop condition<\/p>\n<h2>Summary<\/h2>\n<p>\u0e40\u0e2b\u0e15\u0e38\u0e01\u0e32\u0e23\u0e13\u0e4c UNC3886 \u0e43\u0e19\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c\u0e1e\u0e34\u0e2a\u0e39\u0e08\u0e19\u0e4c\u0e27\u0e48\u0e32 perimeter device \u0e44\u0e21\u0e48\u0e44\u0e14\u0e49\u0e40\u0e1b\u0e47\u0e19\u0e40\u0e1e\u0e35\u0e22\u0e07\u0e40\u0e04\u0e23\u0e37\u0e48\u0e2d\u0e07\u0e1b\u0e49\u0e2d\u0e07\u0e01\u0e31\u0e19 \u0e41\u0e15\u0e48\u0e40\u0e1b\u0e47\u0e19\u0e40\u0e1b\u0e49\u0e32\u0e2b\u0e21\u0e32\u0e22\u0e17\u0e35\u0e48\u0e21\u0e35\u0e21\u0e39\u0e25\u0e04\u0e48\u0e32\u0e2a\u0e39\u0e07 Zero-Day, rootkit \u0e41\u0e25\u0e30\u0e04\u0e27\u0e32\u0e21\u0e2a\u0e32\u0e21\u0e32\u0e23\u0e16\u0e43\u0e19\u0e01\u0e32\u0e23\u0e2d\u0e22\u0e39\u0e48\u0e40\u0e07\u0e35\u0e22\u0e1a\u0e17\u0e33\u0e43\u0e2b\u0e49\u0e01\u0e32\u0e23\u0e15\u0e2d\u0e1a\u0e2a\u0e19\u0e2d\u0e07\u0e15\u0e49\u0e2d\u0e07\u0e02\u0e49\u0e32\u0e21\u0e02\u0e2d\u0e1a\u0e40\u0e02\u0e15\u0e02\u0e2d\u0e07\u0e17\u0e35\u0e21 SOC \u0e44\u0e1b\u0e2a\u0e39\u0e48 vendor, telco \u0e41\u0e25\u0e30\u0e2b\u0e19\u0e48\u0e27\u0e22\u0e07\u0e32\u0e19\u0e23\u0e30\u0e14\u0e31\u0e1a\u0e1b\u0e23\u0e30\u0e40\u0e17\u0e28<\/p>\n<p>\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e2d\u0e07\u0e04\u0e4c\u0e01\u0e23\u0e44\u0e17\u0e22 \u0e1a\u0e17\u0e40\u0e23\u0e35\u0e22\u0e19\u0e17\u0e35\u0e48\u0e19\u0e33\u0e44\u0e1b\u0e43\u0e0a\u0e49\u0e44\u0e14\u0e49\u0e17\u0e31\u0e19\u0e17\u0e35\u0e04\u0e37\u0e2d\u0e2a\u0e33\u0e23\u0e27\u0e08 network appliance \u0e43\u0e2b\u0e49\u0e04\u0e23\u0e1a \u0e41\u0e22\u0e01 management plane \u0e40\u0e01\u0e47\u0e1a log \u0e19\u0e2d\u0e01\u0e2d\u0e38\u0e1b\u0e01\u0e23\u0e13\u0e4c \u0e41\u0e25\u0e30\u0e40\u0e15\u0e23\u0e35\u0e22\u0e21 re-image\/credential rotation \u0e25\u0e48\u0e27\u0e07\u0e2b\u0e19\u0e49\u0e32 \u0e01\u0e32\u0e23\u0e2a\u0e23\u0e49\u0e32\u0e07 resilience \u0e40\u0e2b\u0e25\u0e48\u0e32\u0e19\u0e35\u0e49\u0e0a\u0e48\u0e27\u0e22\u0e44\u0e14\u0e49\u0e17\u0e31\u0e49\u0e07\u0e40\u0e21\u0e37\u0e48\u0e2d\u0e40\u0e1c\u0e0a\u0e34\u0e0d APT \u0e23\u0e30\u0e14\u0e31\u0e1a\u0e2a\u0e39\u0e07\u0e41\u0e25\u0e30\u0e40\u0e21\u0e37\u0e48\u0e2d\u0e40\u0e01\u0e34\u0e14\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48\u0e43\u0e2b\u0e21\u0e48\u0e17\u0e35\u0e48\u0e22\u0e31\u0e07\u0e44\u0e21\u0e48\u0e21\u0e35 signature<\/p>\n<h2>\u0e41\u0e2b\u0e25\u0e48\u0e07\u0e2d\u0e49\u0e32\u0e07\u0e2d\u0e34\u0e07<\/h2>\n<ol>\n<li><a href=\"https:\/\/www.csa.gov.sg\/news-events\/press-releases\/largest-multi-agency-cyber-operation-mounted-to-counter-threat-posed-by-advanced-persistent-threat--apt--actor-unc3886-to-singapore-s-telecommunications-sector\/\" target=\"_blank\" rel=\"noopener\">Cyber Security Agency of Singapore \u2014 Operation Cyber Guardian and UNC3886<\/a><\/li>\n<li><a href=\"https:\/\/www.thaicert.or.th\/2026\/02\/11\/%E0%B8%81%E0%B8%A5%E0%B8%B8%E0%B9%88%E0%B8%A1%E0%B9%81%E0%B8%AE%E0%B8%81%E0%B9%80%E0%B8%81%E0%B8%AD%E0%B8%A3%E0%B9%8C-unc3886-%E0%B9%80%E0%B8%88%E0%B8%B2%E0%B8%B0%E0%B8%A3%E0%B8%B0%E0%B8%9A%E0%B8%9A-4\/\" target=\"_blank\" rel=\"noopener\">ThaiCERT \u2014 \u0e01\u0e25\u0e38\u0e48\u0e21\u0e41\u0e2e\u0e01\u0e40\u0e01\u0e2d\u0e23\u0e4c UNC3886 \u0e40\u0e08\u0e32\u0e30\u0e23\u0e30\u0e1a\u0e1a 4 \u0e04\u0e48\u0e32\u0e22\u0e21\u0e37\u0e2d\u0e16\u0e37\u0e2d\u0e22\u0e31\u0e01\u0e29\u0e4c\u0e43\u0e2b\u0e0d\u0e48\u0e43\u0e19\u0e2a\u0e34\u0e07\u0e04\u0e42\u0e1b\u0e23\u0e4c<\/a><\/li>\n<li><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/china-nexus-espionage-targets-juniper-routers\" target=\"_blank\" rel=\"noopener\">Google Cloud\/Mandiant \u2014 China-nexus espionage targets Juniper routers<\/a><\/li>\n<li><a href=\"https:\/\/thehackernews.com\/2026\/02\/china-linked-unc3886-targets-singapore.html\" target=\"_blank\" rel=\"noopener\">The Hacker News \u2014 China-Linked UNC3886 Targets Singapore Telecom Sector<\/a><\/li>\n<\/ol>","protected":false},"excerpt":{"rendered":"<p>\u0e27\u0e34\u0e40\u0e04\u0e23\u0e32\u0e30\u0e2b\u0e4c\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e01\u0e32\u0e23 UNC3886 \u0e15\u0e48\u0e2d Singtel, StarHub, M1 \u0e41\u0e25\u0e30 SIMBA \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e02\u0e49\u0e2d\u0e40\u0e17\u0e47\u0e08\u0e08\u0e23\u0e34\u0e07\u0e40\u0e23\u0e37\u0e48\u0e2d\u0e07 Zero-Day, firewall bypass, rootkit, Operation Cyber Guardian \u0e41\u0e25\u0e30\u0e1a\u0e17\u0e40\u0e23\u0e35\u0e22\u0e19\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e44\u0e17\u0e22<\/p>","protected":false},"author":0,"featured_media":18430,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[264,265],"tags":[334,332,330,333,331,327,328,329,326,289],"class_list":["post-18398","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-zero-day-vulnerability","tag-apt","tag-firewall","tag-m1","tag-rootkit","tag-simba","tag-singapore","tag-singtel","tag-starhub","tag-unc3886","tag-zero-day"],"acf":[],"rttpg_featured_image_url":{"full":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11.jpg",1200,630,false],"landscape":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11.jpg",1200,630,false],"portraits":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11.jpg",1200,630,false],"thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11-150x150.jpg",150,150,true],"medium":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11-300x158.jpg",300,158,true],"large":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11-1024x538.jpg",1024,538,true],"1536x1536":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11.jpg",1200,630,false],"2048x2048":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11.jpg",1200,630,false],"trp-custom-language-flag":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11-18x9.jpg",18,9,true],"woocommerce_thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11-300x300.jpg",300,300,true],"woocommerce_single":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11-600x315.jpg",600,315,true],"woocommerce_gallery_thumbnail":["https:\/\/droneth.or.th\/wp-content\/uploads\/2026\/08\/11-100x100.jpg",100,100,true]},"rttpg_author":{"display_name":"","author_link":"https:\/\/droneth.or.th\/en\/author\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/droneth.or.th\/en\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/droneth.or.th\/en\/category\/cybersecurity\/zero-day-vulnerability\/\" rel=\"category tag\">Zero-Day \u0e41\u0e25\u0e30\u0e0a\u0e48\u0e2d\u0e07\u0e42\u0e2b\u0e27\u0e48<\/a>","rttpg_excerpt":"\u0e27\u0e34\u0e40\u0e04\u0e23\u0e32\u0e30\u0e2b\u0e4c\u0e1b\u0e0f\u0e34\u0e1a\u0e31\u0e15\u0e34\u0e01\u0e32\u0e23 UNC3886 \u0e15\u0e48\u0e2d Singtel, StarHub, M1 \u0e41\u0e25\u0e30 SIMBA \u0e1e\u0e23\u0e49\u0e2d\u0e21\u0e02\u0e49\u0e2d\u0e40\u0e17\u0e47\u0e08\u0e08\u0e23\u0e34\u0e07\u0e40\u0e23\u0e37\u0e48\u0e2d\u0e07 Zero-Day, firewall bypass, rootkit, Operation Cyber Guardian \u0e41\u0e25\u0e30\u0e1a\u0e17\u0e40\u0e23\u0e35\u0e22\u0e19\u0e2a\u0e33\u0e2b\u0e23\u0e31\u0e1a\u0e44\u0e17\u0e22","_links":{"self":[{"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/posts\/18398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/comments?post=18398"}],"version-history":[{"count":1,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/posts\/18398\/revisions"}],"predecessor-version":[{"id":18413,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/posts\/18398\/revisions\/18413"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/media\/18430"}],"wp:attachment":[{"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/media?parent=18398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/categories?post=18398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/droneth.or.th\/en\/wp-json\/wp\/v2\/tags?post=18398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}