China-Nexus Hackers Attacking Telecommunication Providers With New Malware
ID: 0e73e014-f05f-5234-9801-367ebec910eb
STIX ID: report--0e73e014-f05f-5234-9801-367ebec910eb
Feed Name: cybersecurityNews.com
A China-linked advanced persistent threat tracked as UAT-9244 has been actively targeting telecommunications providers in South America since 2024 with a triad of purpose-built implants: TernDoor (Windows backdoor using DLL side-loading, in-memory execution, persistence via scheduled tasks, Registry Run keys, and a malicious kernel driver), PeerTime (Linux backdoor that uses BitTorrent for C2 to blend traffic), and BruteEntry (converts compromised edge devices into operational relay boxes to brute-force SSH, PostgreSQL, and Tomcat), with Cisco Talos linking the group to FamousSparrow/Tropic Trooper through shared tooling and linguistic indicators; the campaign exhibits sophisticated persistence, evasion, and a broad C2 infrastructure (shared SSL cert across ~18 IPs), and the report advises blocking C2 ranges, auditing scheduled tasks/Run keys, restricting unsigned drivers, and deploying signatures and SNORT rules to defend telecom infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
