GTPDOOR Linux Malware Targets Telecoms, Exploiting GPRS Roaming Networks
ID: be0504f8-50e1-57cf-b0b6-4f88b972c756
STIX ID: report--be0504f8-50e1-57cf-b0b6-4f88b972c756
Feed Name: The Hacker News
Threat Score
Threat hunters discovered GTPDOOR, a Linux backdoor designed for hosts adjacent to GPRS Roaming Exchanges (GRX) that leverages GTP-C Echo Request messages for covert C2 and command execution. Analysis shows the implant disguises itself (process-name stomping to 'syslog'), opens raw sockets to capture UDP messages, and can be probed from external networks; samples uploaded to VirusTotal suggest a likely link to the LightBasin (UNC1945) actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
