logo

GTPDOOR Linux Malware Targets Telecoms, Exploiting GPRS Roaming Networks

ID: be0504f8-50e1-57cf-b0b6-4f88b972c756

STIX ID: report--be0504f8-50e1-57cf-b0b6-4f88b972c756

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat hunters discovered GTPDOOR, a Linux backdoor designed for hosts adjacent to GPRS Roaming Exchanges (GRX) that leverages GTP-C Echo Request messages for covert C2 and command execution. Analysis shows the implant disguises itself (process-name stomping to 'syslog'), opens raw sockets to capture UDP messages, and can be probed from external networks; samples uploaded to VirusTotal suggest a likely link to the LightBasin (UNC1945) actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.