SecurityWeek’s 8 November 2024 roundup covered three separate cybersecurity stories: malware found at Singapore telco Singtel, a GuLoader phishing campaign targeting industrial organizations, and fake LastPass support numbers posted in Chrome Web Store comments. The reported Singtel–Volt Typhoon link was not established as an official attribution in the sources cited here; the LastPass story describes a phishing lure, not a demonstrated breach of LastPass’s password vaults.
What happened in the three stories?
| Story | Target and geography | Reported access path | What the available account establishes |
|---|---|---|---|
| Singtel malware report | Singtel, a Singapore telecommunications operator | Malware was reportedly found at the company in June 2024; the initial access method is not stated in the cited account. | Outside reporting linked the malware to Volt Typhoon. The cited sources do not establish official confirmation of that attribution. |
| GuLoader campaign | Electronic manufacturing, engineering, and industrial organizations in Romania, Poland, Germany, and Kazakhstan | Spearphishing emails with order inquiries or hijacked email threads, followed by malicious archives and a described execution chain. | Researchers described GuLoader being used to deploy other malware, including remote access trojans. The account does not show that every recipient was infected or identify a confirmed payload for every target. |
| LastPass fake-support phishing | People viewing the LastPass app listing in the Chrome Web Store | Fraudulent support phone numbers were posted in listing comments; callers were reportedly directed to a phishing website. | The roundup describes a social-engineering attempt, not a demonstrated compromise of LastPass systems or password vaults. |
The three incidents were grouped in one news roundup, but the available accounts do not show that they were connected or part of one campaign. SecurityWeek’s roundup reported the Singtel and LastPass items; Darktrace’s account of Cado Security Labs research describes the GuLoader activity.
What is known about the Singtel malware report?
SecurityWeek’s 8 November 2024 roundup said malware had been found at Singtel in June 2024 and relayed outside reporting that connected the incident to Volt Typhoon. That is a reported attribution, not a settled official conclusion established by the cited sources. The headline phrase “China hacked Singtel” should therefore be read as shorthand for that reported link, not as proof of who was responsible.
The initial access route, the malware’s effects, and the extent of any compromise are not established in the cited account. It would go beyond the available information to say how the malware entered Singtel’s network or what data or systems, if any, were affected.
#1 Best Overall
A separate Singapore telco disclosure in 2026
On 9 February 2026, Singapore’s Cyber Security Agency described a distinct UNC3886 campaign targeting all four major telecommunications operators in Singapore, including Singtel. That later disclosure concerns a different operation and attribution; it does not confirm that Volt Typhoon was behind the malware reported at Singtel in June 2024. See the CSA’s 9 February 2026 announcement and its account of the UNC3886 activity.
How did the GuLoader campaign target industrial organizations?
Cado Security Labs’ findings, summarized by Darktrace and SecurityWeek, describe spearphishing aimed at electronic manufacturing, engineering, and industrial firms in Romania, Poland, Germany, and Kazakhstan. Emails came from fake companies or compromised accounts. Some hijacked existing threads; others posed questions about orders, using familiar business context to make an attachment seem relevant. The reported archive formats included ISO, 7z, gzip, and RAR. Darktrace’s summary of the Cado research provides the campaign details.
The described attachment and execution chain
- Archive delivery: A recipient was sent a compressed or disk-image archive, depending on the message.
- Obfuscated script: The described chain included a batch file containing obfuscated PowerShell.
- Shellcode and process injection: The account describes shellcode execution and injection into the legitimate Windows process
msiexec.exe. - Persistence-related activity: Researchers also described registry activity intended to help maintain access.
Injecting code into a legitimate process can make malicious activity less conspicuous among normal system processes, but it does not mean the activity will always evade security tools. These are techniques described in the campaign reporting, not proof that every attachment ran successfully or that every recipient’s device was compromised.
What the reported GuLoader payloads mean
SecurityWeek’s roundup says GuLoader was used to deploy other malware, including remote access trojans. The available account does not establish a successful infection or a specific final payload for every target. The reliable conclusion is that the campaign used phishing to deliver a loader and was described as a means of deploying additional malware—not that all recipients suffered the same outcome.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
What was the LastPass fake-support campaign?
SecurityWeek reported that LastPass warned about fraudulent reviews or comments on its Chrome Web Store app listing that included fake support phone numbers. People who called were reportedly directed to a phishing website. The cited account does not demonstrate that LastPass’s systems or password vaults were compromised in this activity, and it does not provide a verified number or current support procedure.
For any password manager or other online service, do not treat a phone number in user comments or an unsolicited message as an official support channel. Navigate to the company’s official website or app independently and use the support route published there.
Quick Recap
Best Value
Rank #4
How to read the three reports without conflating them
- Attribution: The Singtel report carried an outside link to Volt Typhoon, with no official confirmation established by the cited sources. The GuLoader account describes a malware campaign; the LastPass item describes fake-support phishing.
- Targets and geography: Singtel is a Singapore telecom operator; the GuLoader campaign targeted industrial organizations in four named countries; the LastPass lure appeared in comments on a Chrome Web Store listing.
- Access path: The Singtel account does not state how malware entered. GuLoader relied on business-themed email attachments. The LastPass scam used fraudulent support numbers to move callers toward a phishing site.
- Impact: The reports do not establish the same outcome across all targets. In particular, the GuLoader account does not verify infection of every recipient, and the LastPass story is not evidence of a vault breach.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

