China-Nexus Hackers Target Telecommunication Providers with New Malware Attack
ID: a615efe0-6011-5dc2-b42a-f778a4242715
STIX ID: report--a615efe0-6011-5dc2-b42a-f778a4242715
Feed Name: GBHackers
The report describes UAT-9244, a China-linked APT active since 2024 against South American telecommunications, using a three-pronged toolset: TernDoor (Windows DLL side-loading backdoor with an AES-encrypted driver), PeerTime (ELF backdoor for Linux/embedded devices that uses BitTorrent for C2 and payload distribution), and BruteEntry (Go-based brute-force scanner that converts compromised edge devices into proxy/relay nodes). It details deployment and persistence techniques, examples of commands and artifacts, and characterizes the campaign as sophisticated, stealthy, and focused on gaining and expanding footholds across network infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
