logo

China-Nexus Hackers Target Telecommunication Providers with New Malware Attack

ID: a615efe0-6011-5dc2-b42a-f778a4242715

STIX ID: report--a615efe0-6011-5dc2-b42a-f778a4242715

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Divya

...
...

The report describes UAT-9244, a China-linked APT active since 2024 against South American telecommunications, using a three-pronged toolset: TernDoor (Windows DLL side-loading backdoor with an AES-encrypted driver), PeerTime (ELF backdoor for Linux/embedded devices that uses BitTorrent for C2 and payload distribution), and BruteEntry (Go-based brute-force scanner that converts compromised edge devices into proxy/relay nodes). It details deployment and persistence techniques, examples of commands and artifacts, and characterizes the campaign as sophisticated, stealthy, and focused on gaining and expanding footholds across network infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.