logo

Chinese state hackers target telcos with new malware toolkit

ID: 1b3ffde3-cac0-5194-989e-c544113d741b

STIX ID: report--1b3ffde3-cac0-5194-989e-c544113d741b

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-03-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco Talos reports that China-linked APT activity tracked as UAT-9244 has targeted South American telecommunications providers since 2024 using three previously undocumented malware families: TernDoor (Windows backdoor using DLL side‑loading and an embedded driver), PeerTime (multi-architecture ELF backdoor leveraging BitTorrent for P2P C2), and BruteEntry (brute-force scanner that builds Operational Relay Boxes). The report describes deployment and persistence techniques across Windows, Linux, and network-edge devices, and provides indicators of compromise and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.