logo

Stealthy GTPDOOR Linux malware targets mobile operator networks

ID: d074b65e-b42c-5f62-9cfe-3194a0859245

STIX ID: report--d074b65e-b42c-5f62-9cfe-3194a0859245

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-03-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Security researcher HaxRob disclosed GTPDOOR, a stealthy Linux backdoor tailored to telecom infrastructure that uses GTP-C packets as covert C2 to blend with legitimate roaming traffic; two versions (v1/v2) support remote command execution, file writes, and ACL controls, and the malware is attributed to the LightBasin/UNC1945 threat group with detection guidance and a YARA rule provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.