Stealthy GTPDOOR Linux malware targets mobile operator networks
ID: d074b65e-b42c-5f62-9cfe-3194a0859245
STIX ID: report--d074b65e-b42c-5f62-9cfe-3194a0859245
Feed Name: Bleeping Computer
Threat Score
Security researcher HaxRob disclosed GTPDOOR, a stealthy Linux backdoor tailored to telecom infrastructure that uses GTP-C packets as covert C2 to blend with legitimate roaming traffic; two versions (v1/v2) support remote command execution, file writes, and ACL controls, and the malware is attributed to the LightBasin/UNC1945 threat group with detection guidance and a YARA rule provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
