ColCERT Warns on CHARLIE in Telecom
ColCERT warned about the CHARLIE relay network, linked to APT5 and APT15, affecting telecom operators and providers in Colombia.
ColCERT issued Alert 102 on the CHARLIE Operational Relay Network, linked to APT5 and APT15 and used to compromise telecom operators and communications providers in South America, with infrastructure presence in Colombia.
ColCERT issued Alert 102 on the CHARLIE Operational Relay Network and warned that the relay infrastructure is being used by APT5 and APT15 to compromise telecom operators and communications providers across South America, including infrastructure in Colombia.
Scope of the alert
According to the advisory, the activity observed is not limited to a single type of operator. ColCERT said the network associated with APT5 and APT15 has been used against mobile operators, broadband internet providers, fiber optic operators and backhaul infrastructure within the regional telecom sector. In response, it urged Colombian entities in the sector to apply specific mitigation measures across their network environments.
What ColCERT recommends
Alert 102 advises segmenting the management plane and keeping network administration off the WAN. It also recommends using secure isolated channels or local access for administering equipment affected by the relay network activity.
ColCERT also says the network functions as a covert channel for tactical operations tied to the actors involved, and therefore calls for identity and access controls based on Zero Trust models. Those measures include phishing-resistant multifactor authentication, such as FIDO2 or hardware security keys, for all users with access to telecom infrastructure.
Technical indicators observed
The technical analysis included in the alert describes at least 16 confirmed active nodes within the CHARLIE network, also referred to as ORB3. According to ColCERT, once an exposed server is compromised, it begins large-scale brute-force scans against SSH services on TCP port 22, PostgreSQL on TCP 5432 and Apache Tomcat on TCP 8080. Successful intrusions are reported automatically to the command-and-control server in JSON format.
The document adds that CHARLIE and ORB3 nodes abuse infrastructure hosted by cloud and hosting providers such as Tencent Cloud, Vultr, BrainStorm Network and Industries. For Colombian operators, the recommendation is to review administrative logins originating from those providers when they do not match the user's usual geographic profile.
As a specific compromise indicator, ColCERT says the nodes reuse generic SSL certificates with Subject or Issuer C=US, CN=SERVER and C=US, CN=CA. It also warns that these certificates can have anomalous validity periods longer than 10 years, with examples such as 2022 to 2042, in HTTPS connections to unusual IP ranges. That pattern is presented as a concrete IOC for monitoring and detection in Colombian networks.
Sources
- 102 Alerta Red de Retransmisión Operativa CHARLIEcolcert.gov.co· ColCERT



