Evidence Pack: How Singapore's 'Cyber Guardian' Operation Evicted China-Linked Hackers From Its Telecom Grid
A detailed breakdown of the 11-month multi-agency counteroperation that purged the UNC3886 advanced persistent threat from Singapore's four major telecommunications networks.
- National Cyber Defenders
- Focuses on the necessity of methodical, multi-agency coordination to secure critical infrastructure without disrupting public services.
- Threat Intelligence Analysts
- Emphasizes the sophisticated tactics of APTs like UNC3886, particularly their exploitation of edge devices and use of rootkits for long-term persistence.
- Telecommunications Operators
- Prioritizes maintaining network uptime and protecting customer data while cooperating with state security mandates.
Key points
- Singapore successfully evicted the China-linked UNC3886 hacking group from its four major telecommunications networks.
- The 11-month counteroperation, dubbed Cyber Guardian, involved over 100 defenders from multiple government agencies.
- Attackers used a zero-day exploit and rootkits to gain persistent, hidden access without disrupting services.
- The operation prioritized methodical containment and eradication to ensure no customer data was compromised or internet access lost.
- 11 months
- Duration of counteroperation
- 4
- Major telcos targeted
- >100
- Cyber defenders deployed
- 0
- Service disruptions reported
The evidence confirms that defending modern critical infrastructure against state-sponsored espionage requires a level of coordination previously reserved for physical warfare. In February 2026, Singapore concluded an unprecedented 11-month counteroperation that successfully purged a highly sophisticated hacking group from its entire telecommunications grid. The operation stands as a definitive case study in how nations can identify, contain, and evict deeply embedded digital adversaries without disrupting essential public services.[1]
The forensic data centers on Operation Cyber Guardian, a massive multi-agency effort that mobilized over 100 cyber defenders to secure networks operated by the country's four major providers: Singtel, StarHub, M1, and SIMBA Telecom. These networks form the digital backbone of the nation, handling the daily communications, financial transactions, and logistical data for millions of residents and multinational corporations. The simultaneous targeting of all four operators indicates a strategic effort to map the entirety of the state's connectivity infrastructure.[1][3]
The adversary in this campaign was identified as UNC3886, a highly disciplined advanced persistent threat (APT) with a documented history of targeting defense, technology, and telecommunications sectors. Threat intelligence profiles characterize UNC3886 as a China-nexus group that specializes in exploiting edge devices and virtualization software. Unlike opportunistic cybercriminals seeking quick financial gain, this group operates with the patience and resources typical of state-sponsored espionage, focusing on long-term infiltration and intelligence gathering.[1][2][4]
According to the Cyber Security Agency of Singapore (CSA), the initial breach was achieved through the use of a zero-day exploit. This allowed the attackers to bypass the telcos' perimeter firewalls by targeting a software vulnerability that was previously unknown to the vendor, meaning no defensive patch existed at the time of the intrusion. This method of entry is highly prized by APTs, as it enables them to slip past standard security perimeters without triggering automated alarms.[1][4]
Once inside the networks, the evidence shows that UNC3886 deployed advanced rootkits to cement their foothold. Rootkits are a class of malicious software designed to bury themselves deep within an operating system's architecture, granting the attackers persistent, administrative-level control while actively hiding their presence from conventional antivirus scans. The use of these tools made the intrusion exceptionally difficult to detect and required defenders to conduct comprehensive, manual security checks across vast network environments.[1][2]
Despite the depth of the infiltration, the data regarding the attackers' ultimate intent suggests a focus on operational mapping rather than immediate sabotage. The CSA confirmed that the intruders managed to exfiltrate only a small amount of technical data, primarily related to network configurations. This aligns with the established behavioral patterns of advanced persistent threats, which often prioritize understanding the topology of a target network to facilitate future, more impactful operations.[1][4]
Despite the depth of the infiltration, the data regarding the attackers' ultimate intent suggests a focus on operational mapping rather than immediate sabotage.
What remains explicitly unverified is whether the attackers possessed a secondary, more destructive payload intended for deployment during a geopolitical crisis. However, the available evidence confirms that while the hackers reached limited portions of critical systems, they did not attempt to disrupt telecommunications services or access sensitive customer records. The integrity of personal data and the availability of internet and cellular services were maintained throughout the entirety of the intrusion and the subsequent eviction process.[1]
The timeline of the eviction highlights the extreme difficulty of rooting out deeply embedded APTs. The threat actor's activities were initially detected by the telecommunications operators, who notified the CSA and the Infocomm Media Development Authority (IMDA) in July 2025. The public disclosure of the successful eviction did not occur until February 2026, underscoring the painstaking, months-long effort required to ensure the networks were fully sanitized.[1]
Rather than executing a rapid, aggressive purge that could have alerted the attackers or caused inadvertent network blackouts, defenders opted for a methodical containment strategy. Under Operation Cyber Guardian, authorities worked closely with the telcos to monitor the attackers' movements, limit their lateral progression, and systematically close off their access points. This approach prioritized the stability of the telecommunications grid over the immediate gratification of a swift eviction.[1]
This containment and eradication effort required unprecedented coordination between the private sector and multiple government entities. The task force included specialists from the CSA, IMDA, the military's Digital and Intelligence Service, the Government Technology Agency, and the Internal Security Department. This unified front reflects a growing consensus that defending critical infrastructure against nation-state adversaries exceeds the capabilities of any single corporate security team.[1][5]
The success of Operation Cyber Guardian provides a vital blueprint for national cyber defense. It demonstrates that highly resourced state actors can be detected and defeated through rigorous "defense-in-depth" strategies, where multiple layers of security and continuous monitoring are employed to catch threats that bypass initial perimeters. The operation proves that a compromised network is not necessarily a lost network, provided defenders possess the expertise and patience to execute a surgical eviction.[1][4]
Yet, the incident also exposes a systemic vulnerability in global network architectures: the reliance on edge devices that often lack robust security monitoring capabilities. Because firewalls and routers sit at the boundary of a network, they are prime targets for groups like UNC3886, who exploit these blind spots to establish their initial beachheads. Securing these edge devices remains one of the most pressing challenges for cybersecurity professionals worldwide.[2][5]
As telecommunications networks increasingly underpin everything from global finance to national security, the stakes for protecting them have never been higher. The Singaporean case study illustrates that the threat of advanced persistent infiltration is a permanent reality for modern digital economies. Maintaining the integrity of these systems will require continuous investment in threat intelligence, advanced forensic capabilities, and seamless public-private collaboration.[4]
Ultimately, the evidence from Operation Cyber Guardian confirms that the era of passive cyber defense is over. Nations and corporations must operate under the assumption that highly capable adversaries are actively probing their defenses, and they must be prepared to mount coordinated, long-term responses to secure their critical infrastructure.[1][5]
How we got here
Late 2021
UNC3886 is first identified as an advanced persistent threat targeting global critical infrastructure.
July 2025
Singaporean telcos detect the intrusion and notify state cybersecurity authorities.
July 18, 2025
Singapore publicly acknowledges an APT attack on its critical infrastructure, withholding details for operational security.
July 2025 - Feb 2026
Operation Cyber Guardian is executed to systematically map and close the attackers' access points.
February 9, 2026
Authorities officially disclose the successful eviction of the hackers from all four telecom networks.
What we don’t know
- The specific zero-day vulnerability exploited to bypass the initial perimeter firewalls.
- The exact nature of the network configuration data that the attackers managed to exfiltrate.
- Whether the threat group intended to deploy destructive payloads at a later date.
Sources
[1]Cyber Security Agency of SingaporeNational Cyber DefendersLargest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore's Telecommunications Sector
Read on Cyber Security Agency of Singapore →
[2]WikipediaThreat Intelligence AnalystsUNC3886
Read on Wikipedia →
[3]WikipediaThreat Intelligence AnalystsSingtel
Read on Wikipedia →
[4]WikipediaThreat Intelligence AnalystsAdvanced persistent threat
Read on Wikipedia →
[5]Factlen Editorial TeamTelecommunications OperatorsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
Every angle. Every day.
Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.


