logo

China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks

ID: 426be76a-8247-5413-b320-ed3e2388541c

STIX ID: report--426be76a-8247-5413-b320-ed3e2388541c

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-03-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Cisco Talos attributes a sustained China-linked espionage campaign (tracked as UAT-9244) targeting South American telecommunications since 2024, deploying three previously undocumented implants — TernDoor (Windows DLL sideloading backdoor with an embedded driver), PeerTime (multi-architecture Linux/embedded P2P backdoor using BitTorrent and in-memory execution), and BruteEntry (Golang-based brute-force scanner installed on edge devices) — along with supporting scripts and infrastructure used to brute-force and pivot within networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.