[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/ "Threat Actor Groups")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# The Covert Operator's Playbook: Infiltration of Global Telecom Networks

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex Xpanse icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Xpanse](https://unit42.paloaltonetworks.com/product-category/cortex-xpanse/ "Cortex Xpanse")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Renzon Cruz](https://unit42.paloaltonetworks.com/author/renzon-cruz/)
  * [Nicolas Bareil](https://unit42.paloaltonetworks.com/author/nicolas-bareil/)
  * [Navin Thomas](https://unit42.paloaltonetworks.com/author/navin-thomas/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:July 29, 2025

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/)
  * [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/)
  * [CL-STA-0969](https://unit42.paloaltonetworks.com/tag/cl-sta-0969/)
  * [GALLIUM](https://unit42.paloaltonetworks.com/tag/gallium/)
  * [GoLang](https://unit42.paloaltonetworks.com/tag/golang/)
  * [Liminal Panda](https://unit42.paloaltonetworks.com/tag/liminal-panda/)
  * [PingPull](https://unit42.paloaltonetworks.com/tag/pingpull/)
  * [Telecoms](https://unit42.paloaltonetworks.com/tag/telecoms/)
  * [UNC1945](https://unit42.paloaltonetworks.com/tag/unc1945/)
  * [UNC2891](https://unit42.paloaltonetworks.com/tag/unc2891/)
  * [UNC3886](https://unit42.paloaltonetworks.com/tag/unc3886/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/infiltration-of-global-telecom-networks/?pdf=download&lg=en&_wpnonce=c280d701ab "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/infiltration-of-global-telecom-networks/?pdf=print&lg=en&_wpnonce=c280d701ab "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=The%20Covert%20Operator's%20Playbook:%20Infiltration%20of%20Global%20Telecom%20Networks&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Finfiltration-of-global-telecom-networks%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Finfiltration-of-global-telecom-networks%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Finfiltration-of-global-telecom-networks%2F&title=The%20Covert%20Operator's%20Playbook:%20Infiltration%20of%20Global%20Telecom%20Networks "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Finfiltration-of-global-telecom-networks%2F&text=The%20Covert%20Operator's%20Playbook:%20Infiltration%20of%20Global%20Telecom%20Networks "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Finfiltration-of-global-telecom-networks%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=The%20Covert%20Operator's%20Playbook:%20Infiltration%20of%20Global%20Telecom%20Networks%20https%3A%2F%2Funit42.paloaltonetworks.com%2Finfiltration-of-global-telecom-networks%2F "Share in Mastodon")

## Executive Summary

Unit 42 has observed multiple incidents targeting the telecommunications industry in Southwest Asia. We are currently tracking this activity as [CL-STA-0969](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/). This activity includes attacking and leveraging interconnected mobile roaming networks. This report provides a technical analysis of the activity cluster based on our incident response engagements including observed tactics, techniques and procedures (TTPs).

We found no clear evidence of data collection or exfiltration from the investigated systems and networks, nor any attempts to track or communicate with target devices within mobile networks. However, the threat actor behind CL-STA-0969 maintained high operational security (OPSEC) and employed various defense evasion techniques to avoid detection.

The actors deployed several tools within the compromised networks and set up communication capabilities that provide resilient remote control for future objectives. They used tools like Cordscan --- designed to collect location data from mobile devices --- which suggests that obtaining victim location data was a likely objective.

With high confidence, we assess this activity is associated with a nation-state nexus. Based on observed activity and victimology, this cluster heavily overlaps with activity attributed to [Liminal Panda](https://www.crowdstrike.com/en-us/blog/an-analysis-of-lightbasin-telecommunications-attacks/), a nation-state adversary tracked by CrowdStrike.

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)
* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) for detection internet-facing servers that may be vulnerable to the additional access path
* [Advanced WildFire](https://docs.paloaltonetworks.com/advanced-wildfire)
* [Next-Generation Firewall (NGFW)](https://docs.paloaltonetworks.com/ngfw) with [Cloud-Delivered Security Services (CDSS)](https://docs.paloaltonetworks.com/cdss)

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**Top Cyber Threats**](https://unit42.paloaltonetworks.com/category/top-cyberthreats/), [**Backdoor**](https://unit42.paloaltonetworks.com/tag/backdoor), [**PingPull**](https://unit42.paloaltonetworks.com/tag/pingpull), [**Gallium**](https://unit42.paloaltonetworks.com/tag/gallium) |
|----------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## CL-STA-0969 Threat Overview

CL-STA-0969 activity we observed occurred between February and November 2024. While this cluster significantly overlaps with Liminal Panda, we have also observed overlaps in attacker tooling with other reported groups and activity clusters, including [Light Basin](https://www.crowdstrike.com/en-us/blog/liminal-panda-telecom-sector-threats/), [UNC3886](https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers), [UNC2891](https://cloud.google.com/blog/topics/threat-intelligence/unc2891-overview/) and [UNC1945](https://cloud.google.com/blog/topics/threat-intelligence/live-off-the-land-an-overview-of-unc1945/).

The threat actor behind this activity used a variety of custom tools. They also used publicly available tools like:

* [Microsocks proxy](#post-148315-_9onlq2rjfxnh)
* [Fast Reverse Proxy (FRP)](#post-148315-_y5thhn9cq4aa)
* [FScan](#post-148315-_k9vdfc7f55fy)
* [Responder](#post-148315-_gjkjryrroe1i)
* Tools to exploit known vulnerabilities [CVE-2016-5195](https://nvd.nist.gov/vuln/detail/cve-2016-5195), [CVE-2021-4034](https://nvd.nist.gov/vuln/detail/cve-2021-4034) and [CVE-2021-3156](https://nvd.nist.gov/vuln/detail/cve-2021-3156)

The threat actor behind the attack maintained a high level of OPSEC and remained undetected by employing various techniques such as:

* Tunneling traffic over DNS
* Routing traffic through compromised mobile operators
* Clearing authentication logs
* Disguising process names

## Timeline of Events

Between February and November 2024, we identified ongoing and targeted threat actor activity aimed at critical telecommunications infrastructure as shown in Figure 1. Our evidence from triage analysis, threat hunting and collaboration with the client's telecommunications vendor suggests the initial compromise likely originated from a brute-force attack against authentication mechanisms within their telecommunication infrastructure.
![Diagram illustrating the lifecycle of a cyber attack in eight stages, including initial compromise, credential access, lateral movement, and discovery, leading to final actions such as data exfiltration, with each stage linked by arrows. Icons representing computers, network connections, and security breaches are used to visualize each step. Palo Alto Networks and Unit 42 logo lockup.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-1348-148315-1.png) Figure 1. High-level chain of events in the attack investigated by Unit 42.

## Attacker Tooling and Tactics

We observed that the threat actors used a wide range of custom tools designed for telecom environments, including implants such as:

* [AuthDoor](#post-148315-_qwygkz5eet0)
* [GTPDoor](#post-148315-_m80k14ahokz6)
* [ChronosRAT](#post-148315-_r9rebcfyer58)
* [NoDepDNS](#post-148315-_2dnvpc6gklr3)

These tools abused common protocols like SSH, ICMP, DNS and GTP to maintain access, execute commands and establish covert command-and-control (C2) channels.

Their tactics to maintain strong OPSEC included using:

* Pluggable authentication module (PAM) backdoors
* Process name masquerading
* Log tampering
* Disabling SELinux to avoid detection

​​Their use of custom tools designed for telecom environments suggests a deep understanding of the targeted infrastructure and an intent to evade standard security controls.

### Initial Access

Despite their high level of OPSEC, substantial evidence points to attackers gaining initial access via SSH brute force. To do this, they used a well-tuned account dictionary list that included built-in accounts specific to telecommunications equipment.

### AuthDoor

The threat actor implemented a backdoor in the PAM on certain hosts by overwriting the legitimate pam\_unix.so (or pam\_unix2.so) file. While [Mandiant](https://cloud.google.com/blog/topics/threat-intelligence/live-off-the-land-an-overview-of-unc1945/) reported a similar backdoor named SLAPSTICK, the version we observed was simpler and less sophisticated. We are tracking this sample as AuthDoor.

The backdoor successfully hooks itself into the pam\_sm\_authenticate function, validates the password and then opens the file /usr/bin/.dbus.log in read-only mode to check if the captured credentials are already present. The captured credentials are encoded in ASCII hex format.

If the credentials do not exist or are different because they were renewed, the library will update the file. To do so, it first creates a new file named a in the working directory, writes the credentials into it and then renames that temporary file to /usr/bin/.dbus.log.
![A screenshot of a computer code snippet written in the C programming language, including conditional statements and file operations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-5157-148315-2.png) Figure 2. Writing of captured credentials by AuthDoor.

The backdoor provided other functionalities similar to SLAPSTICK, including user access to a targeted host via a hard-coded magic password that allows for persistent access, ​​even if user passwords are changed.

The library also includes functionality to enumerate and execute files located in /var/spool/.network/. At the time of investigation, there was no indication that this particular activity had occurred.

### Cordscan

Cordscan is a custom-made network scanning and packet capture utility with built-in logic for the application layer of telecommunications systems. According to [CrowdStrike](https://www.crowdstrike.com/en-us/blog/an-analysis-of-lightbasin-telecommunications-attacks/), this tool is leveraged to target Serving GPRS Support Nodes (SGSN), which are responsible for packet-data delivery to and from mobile stations and contain location information for registered GPRS users.

This sample includes the following usage instructions, as shown in Figure 3, detailing all available switches.
![Screenshot of code containing various network commands and parameters, such as interface specifications, TCP scan settings, FTP version details, and options for network capture and filters.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-8580-148315-3.png) Figure 3. Command line flags for Cordscan tool.

The two key command-line switches in this case are:

* \--imsi: This holds an International Mobile Subscriber Identity ([IMSI](https://imei.org/blog/imsi-number)), a unique 15-digit number that identifies a specific subscriber on a mobile network
* \--oper: This holds a six-digit number that points to a specific mobile operator, also known as a Home Network Identity ([HNI](https://mcc-mnc.com/))

The contents of the configuration extracted from Cordscan are shown in Table 1.

|-------------------------|------------------------------------------------------------|
| **Configuration Field** | **Configuration Value**                                    |
| pingtimeout             | 3                                                          |
| tcpsyntimeOut           | 3                                                          |
| goctetOffset            | 2                                                          |
| tcp\_hdr\_option\_wan      |                                                            |
| tcp\_common\_portlist     | 22,23,80,139,443,445,3389,8000,8080,11101                  |
| huawei\_usn\_portlist     | 22,944,311,101                                             |
| huawei\_ugw\_portlist     | 2,260,008,000                                              |
| huawei\_stp\_portlist     | 60,998,009,800,180,000,000,000,000,000,000,000,000,000,000 |
| pco                     | 0x218080                                                   |
| qos                     |                                                            |
| global\_portlistSize     | 10                                                         |
| maxport                 | 65535                                                      |
| minport                 | 1                                                          |
| pdusendSock             | 0xFFFFFFFF                                                 |
| gtpver                  | 1                                                          |
| targetImsi              | \<redacted\>                                               |
| targetOperator          | \<redacted\>                                               |
| capturefileName         | packet.pcap                                                |

Table 1. Configuration data extracted from the Cordscan sample.

The targetOperator variable holds a value that points to a [mobile operator](https://mcc-mnc.com/). The value for this in the incidents we worked pointed to a telecommunications operator based in East Asia.

CapturefileName defaults to packet.pcap as the output file if the -w switch does not specify an alternative.

Attackers hard coded an IP address within a function called gtpsgsncontextreqMethod, which creates a UDP socket named ggtpscanSocket. This function builds a packet with the hard-coded IP address as the destination and port 2123 as the UDP port. The packet also includes targetOperator and targetImsi values. The function then sends this packet to the created socket. This functionality is executed when the -sG switch is provided on the command line.

### GTPDoor

We observed another Linux-based implant, predominantly known as GTPDoor. According to a detailed analysis by [security researcher HaxRob](https://haxrob.net/gtpdoor-a-novel-backdoor-tailored-for-covert-access-over-the-roaming-exchange/), GTPDoor is deployed in telecommunications networks adjacent to GRX.

This implant communicates C2 traffic over GTP-C (GPRS Tunneling Protocol - Control Plane) signaling messages. This is achieved by listening for UDP packets on port 2123, effectively tunneling C2 traffic and bypassing traditional security controls. GTPDoor also has remote code execution and beaconing capabilities.

### EchoBackdoor

This backdoor passively listens for ICMP echo request packets containing its C2 instructions. The payload within these packets begins with a decryption key. This key is used to decrypt the remainder of the payloads, which consists of 14-byte chunks. Each chunk, sent in independent ICMP echo request packets, represents a portion of the command to be executed on the compromised system. The backdoor reconstructs the complete command from these decrypted chunks.

Upon execution of the command, the backdoor transmits the results back to the C2 server via an unencrypted ICMP Echo Reply packet. This passive approach contrasts with malware families like PingPong, which actively connect to a C2 server upon receiving a trigger ICMP ECHO packet. EchoBackdoor relies solely on inbound ICMP Echo Requests for receiving commands.

### SGSN Emulator

SGSN Emulator (sgsnemu) is part of the [OsmoGGSN](https://osmocom.org/projects/openggsn/wiki/Sgsnemu) project and implements a Serving GPRS support node (SGSN) emulator. It emulates an interface called GN/Gp, which is used with Gateway GPRS support nodes (GGSNs).

This emulator enables the threat actor to establish a point-to-point connection with another roaming operator using specific telecommunication protocols across the GRX network. This allows them to bypass firewall restrictions and network intrusion detection systems often found in enterprise IT networks.

The script executes the SGSN emulator, attempting to connect to a pair of International Mobile Subscriber Identity (IMSI) and Mobile Subscriber Integrated Services Digital Network (MSISDN) numbers. As reported by [CrowdStrike](https://www.crowdstrike.com/en-us/blog/an-analysis-of-lightbasin-telecommunications-attacks/), these numbers identify specific mobile devices or mobile stations, enabling the SGSN emulator to create tunnels. The script also passes Routing Area Information values to the emulator.

Packet Data Protocol (PDP) context requests for mobile stations with the IMSI/MSISDN number pair are generated to establish a connection. Once established, the SGSN emulator connects to the device via the GPRS Tunneling Protocol (GTP) and uses the tun0 interface for the connection.

Next, the script waits for a second. It then adds a route for an internal IP address via the tun0 interface created by the SGSN emulator and pings that IP address to check connectivity through the newly established tunnel. Finally, it starts a SOCKS proxy by executing the Microsocks proxy tool.

### ChronosRAT

ChronosRAT is a new piece of malware. This 32-bit ELF executable will drop two files on the file system: /usr/local/bin/chargen and /usr/local/bin/daytime

* daytime is a watchdog process that supervises the execution of chargen, restarting it if necessary to ensure persistent operation of the backdoor
* chargen is the backdoor communicating with its C2 server using TCP
  * Communication between both sides is encrypted using AES
  * This key can be updated dynamically using an RSA key hard coded in the executable

The backdoor is composed of multiple modules, each implementing one of the following commands:

* Shellcode execution
* File manager
* Keylogger
* Port forwarding
* Remote shell
* Screenshot
* Socks proxy

The configuration of the backdoor can be either hard coded into the executable or stored in an accompanying file named err. It also supports an "online mode" that allows the backdoor to receive a new configuration from an incoming ICMP or UDP packet. When using UDP, the backdoor expects a DNS packet containing the Base64-encoded configuration within the domain name.

### NoDepDNS

This new backdoor is developed in Golang. Its developers internally named it MyDns based on its debugging symbols.

The backdoor creates a raw socket using net/ipv4/NewRawConn and passively listens for UDP traffic on port 53. It uses the [miekg/dns](https://github.com/miekg/dns/) library to parse DNS messages.
![A screenshot displaying a segment of computer code written in C programming language, using functions and conditional statements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-11577-148315-4.png) Figure 4. Snippet showing translation of IP addresses to command line for execution.

Commands are executed by setting the DNS question field to pgw-s5s8.mpgw001.node. Multiple IP addresses in the response then form the XOR-encoded (key: funnyAndHappy) bash command. Each byte of the IP addresses corresponds to one encrypted character of the command. Figure 4 shows a code snippet from the backdoor. This is a great example of the threat actor exhibiting a highly complex and stealthy form of malicious communication through DNS tunneling.

Surprisingly, this command output is not returned to the sender. This makes it a less effective tool for operators.

A shell script checked this backdoor every 10 seconds to see if NoDepDNS became a zombie process. If this was the case, the script would kill the defunct process. This script also maintained a network connection to a specific target and terminated any other threat actors' processes if necessary. Another shell script restarted this process.

### Privilege Escalation

Due to the mission-critical nature of telecommunications nodes and the high cost of downtime, these systems often run older operating systems with unpatched vulnerabilities. Consequently, the threat actor exploited one of the following vulnerabilities to easily escalate to root privileges:

* [CVE-2016-5195 (DirtyCoW)](https://ubuntu.com/security/cve-2016-5195): A race condition in the Linux kernel versions 2.x-4.x before 4.8.3 allows local users to gain privileges by exploiting incorrect handling of the copy-on-write (CoW) feature. This enables them to write to a read-only memory mapping. The exploit created multiple artifacts, including a user named [firefart](https://github.com/firefart/dirtycow/blob/master/dirty.c#L47) that the threat actor carefully deleted after use to further conceal their activity. This activity also demonstrates that the threat actor understands the tools being used and adapts their procedures accordingly.
* [CVE-2021-4034](https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034): This is a memory corruption vulnerability in the Set User ID (SUID) binary pkexec, a part of the Unix component Polkit. SUID binaries run with the privileges of the owner, making them a prime target for privilege escalation. The threat actor used PwnKit, a self-contained [exploit for CVE-2021-4034](https://github.com/ly4k/PwnKit).
* [CVE-2021-3156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3156): This is a heap-based buffer overflow vulnerability in sudo. The threat actor used a Python script, exploit\_userspec.py, which is part of the [CVE-2021-3156 exploit repository](https://github.com/worawit/CVE-2021-3156/).

### SSH Reverse Tunneling

CL-STA-0969 leveraged different shell scripts that established a reverse SSH tunnel along with other functionalities. The SSH commands are typically in the format shown in Figure 5.
![Code describing the use of the SSH command for port forwarding, including syntax for specifying listening and destination addresses, and remote server details.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-15401-148315-5.png) Figure 5. Example of SSH commands used for reverse SSH tunneling.

All reverse SSH tunnels we observed used destination port 22 and remote server port 53. This command connects to the remote server on port 53 and establishes a listener. Connections to the listener are then forwarded through the SSH tunnel back to the originating system and onto an internal server on the target network (port 22). The traffic is then forwarded to the destination address, which is an internal server on the target network.

CL-STA-0969's use of port 53 is unusual but consistent with this cluster's tactics. Port 53 is often open on networks for DNS functionality, particularly within roaming GRX networks for mobile routing.

### Defense Evasion

CL-STA-0969 systematically clears logs and deletes executables when they are no longer needed, to maintain a high degree of OPSEC.

The group relied on utmpdump, a legitimate program installed by default in Linux distributions, to dump the contents of the wtmp log file. It used sed --- a stream editor for filtering and transforming text --- to issue commands that selectively removed lines containing their IP address from the dumped log file. This sanitized the logs without using potentially detectable tools for direct modification, as shown in the code excerpt shown in Figure 6.
![Text showing UNIX commands dealing with log files and searching for an IP address. Commands include utmpdump, sed, rm, find, and last.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-18845-148315-6.png) Figure 6. Commands used to dump and sanitize log files.

The group first systematically set the HISTFILE environment variable to /dev/null to not write their session into ~/.bash\_history.

#### Process Name Masquerading

When deploying tools for persistence, the group often hid executables with convincing names tailored to the client environment:

* These names could mimic kernel thread naming conventions, such as \[kpqd\] or \[watchdog/1\] making them appear to be legitimate system processes
* It employed obscure prefixes used for telecommunication tools, showing deliberate inspection of legitimate tools on the machine to find an appropriate name
* If the host lacked specialization, the group could use names like httpd -D, spawning multiple threads to replicate Apache HTTP server's typical behavior, making the malicious process blend in with legitimate web server activity
* The group also used the dbus- prefix for its executables such as dbus-console or dbus-send

The threat actor timestomped executables using the touch command (e.g., touch -r /usr/bin/time /usr/bin/\<file\>). It used this technique to impede analysis of the file system's timeline during forensic investigation. The backdoored pam\_unix.so (AuthDoor) module hard coded the command shown in Figure 7.
![Text displaying a Unix command.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-22510-148315-7.png) Figure 7. Command hard coded by the AuthDoor module.

#### Impair SELinux

Security-Enhanced Linux (SELinux) was disabled on the hosts. This was likely to:

* Disable the extra logging provided by SELinux
* Prevent AuthDoor from crashing

We observed modifications to the SELinux configuration file /etc/selinux/config to temporarily disable SELinux, followed by executing setenforce 0 to set the SELinux enforcement mode to "Permissive." In permissive mode, SELinux logs policy violations but does not block them.

During threat hunting, we found a web server exposing an open directory with executables named similarly to the CL-STA-0969 toolkit. One of them was a script named installnow.sh with the content shown in Figure 8.
![Image showing a Unix command line interface with a code snippet that modifies a configuration.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-25219-148315-8.png) Figure 8. Content of installnow.sh script.

### Additional Tooling

#### FScan

[FScan](https://github.com/shadow1ng/fscan/) is an intranet scanning tool. FScan or variants have been used by threat groups and campaigns such as [Stately Taurus](https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/), [SLOW#TEMPEST](https://www.securonix.com/blog/from-cobalt-strike-to-mimikatz-slowtempest/), [UNC5174](https://cloud.google.com/blog/topics/threat-intelligence/initial-access-brokers-exploit-f5-screenconnect), [UNC4841](https://cloud.google.com/blog/topics/threat-intelligence/barracuda-esg-exploited-globally), [Earth Estries](https://www.trendmicro.com/en_us/research/24/k/earth-estries.html) and [FishMonger](https://www.eset.com/us/about/newsroom/research/eset-research-reveals-operation-fishmedley-global-espionage-operation-by-chinas-fishmonger-and-i-soon/?srsltid=AfmBOop9bX3Ydl-NP7a_ZNAxEMS0cQmjOao89VTDix-fYRBOG8laRhXY).

We observed the threat actor using this tool to scan the network for the following ports in /24 network ranges:

* 22 (SSH)
* 80 (HTTP)
* 135 (Microsoft RPC)
* 139 (NetBIOS Session Service)
* 443 (HTTPS)

The threat actor pinged each discovered host to check accessibility via ping as shown in Figure 9, potentially to look for available hosts to deploy an ICMP backdoor.
![Image showing a green code snippet with a ping command.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-28807-148315-9.png) Figure 9. Ping command used by the threat actor.

#### Responder

[Responder](https://github.com/lgandx/Responder) is an open-source meddler-in-the-middle (MiTM) tool that exploits broadcast name resolution protocols such as:

* Link Local Multicast Name Resolution (LLMNR)
* NetBIOS name resolution (NBT-NS)
* Multicast Domain Name System (MDNS)

Observed commands suggest Responder was used to exploit Windows Proxy Automatic Detection (WPAD). WPAD allows browsers to automatically discover and use proxy servers without manual configuration. This can be exploited to force the target system to interact with a rogue WPAD proxy server, enabling the capture of NTLM credentials from neighboring hosts.

#### Microsocks

[Microsocks](https://github.com/rofl0r/microsocks) is an open-source tool that sets up a SOCKS5 server for pivoting or tunneling network activity.

#### Fast Reverse Proxy

[Fast Reverse Proxy](https://github.com/fatedier/frp) (FRP) is a tool that exposes local servers behind network address translations (NAT) or firewalls to the internet. The threat actor deployed FRP client version 0.37.1 using the commands shown in Figure 10.
![Code snippet showing commands manipulating files related to an HTTP daemon, including moving, updating timestamps, and editing configuration.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-31502-148315-10.png) Figure 10. Commands used to deploy FRP client.

The content of its configuration file httpd.conf is shown in Figure 11.
![Code snippet displaying configuration settings for a server connection, including IP address, port number, company name, communication type, plugin used, and administration privileges.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-34345-148315-11.png) Figure 11. Content of httpd.conf.

#### ProxyChains

[ProxyChains](https://github.com/haad/proxychains) is an open-source UNIX program that forces the transmission of network traffic through different proxies. The threat actor used this tool to transfer files to neighboring hosts via SCP.

In the following example, it used ProxyChains to tunnel the SCP connection through the proxies defined in /etc/proxychains4.local1084.conf as shown in Figure 12. We also note that it used sshpass to provide the password non-interactively, because some backdoors preclude interactive use.
![Code snippet showing configuration settings for proxychains and sshpass, with file paths and IP address details.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/word-image-37775-148315-12.png) Figure 12. Use of ProxyChains to tunnel an SCP connection.

## Conclusion

CL-STA-0969 demonstrates a deep understanding of telecommunications protocols and infrastructure. Its malware, tools and techniques reveal a calculated effort to maintain persistent, stealthy access. It achieved this by proxying traffic through other telecom nodes, tunneling data using less-scrutinized protocols and employing various defense evasion techniques. Organizations relying on legacy hosts and services within the targeted infrastructure increases vulnerability to such attacks.

CL-STA-0969's multi-pronged operational strategy, combining technical expertise with environmental adaptation, underscores the need for vigilant security measures and proactive threat intelligence.

## Palo Alto Networks Protection and Mitigation

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/wildfire) cloud-delivered malware analysis service accurately identifies the known samples as malicious
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam) prevent the execution of the threats mentioned in this article, using Behavioral Threat Protection and machine learning based on the Local Analysis module
* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) is able to detect internet-facing SSH servers which have been identified as part of the initial access path
* [Next-Generation Firewall (NGFW)](https://docs.paloaltonetworks.com/ngfw) with [Cloud-Delivered Security Services (CDSS)](https://docs.paloaltonetworks.com/cdss) deployed on roaming interfaces monitors through stateful [GTP (GPRS Tunneling Protocol)](https://docs.paloaltonetworks.com/service-providers/11-1/mobile-network-infrastructure-getting-started/gtp/gtp-basics) inspection and user plane traffic analysis, and enforces prevention with dynamic security policies

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

SHA256 hash:

* bacbe2a793d8ddca0a195b67def527e66d280a13a8d4df90b507546b76e87d29
* Filename: dbusquery
* File description: Cordscan

SHA256 hash:

* 1852473ca6a0b5d945e989fb65fa481452c108b718f0f6fd7e8202e9d183e707
* Filename: libcord.so
* File description: Cordscan

SHA256 hash:

* 705a035e54ce328227341ff9d55de15f4e16d387829cba26dc948170dac1c70f
* Filename: /tmp/catlog
* File description: Fscan

SHA256 hash:

* 44e83f84a5d5219e2f7c3cf1e4f02489cae81361227f46946abe4b8d8245b879
* Filename: pslogs
* File description: Pwnkit

SHA256 hash:

* e3b06f860b8584d69a713127f7d3a4ee5f545ad72e41ec71f9e8692c3525efa0
* Filename: httpdd
* File description: Fast Reverse Proxy

SHA256 hash:

* efa04c33b289e97a84ec6ab1f1b161f900ed3b4521a9a69fb6986bd9991ecfc6
* Filename: vmware-daemon.py
* File description: Responder

SHA256 hash:

* 827f41fc1a6f8a4c8a8575b3e2349aeaba0dfc2c9390ef1cceeef1bb85c34161
* Filename: dnsd\_el5
* File description: GTPDoor

SHA256 hash:

* 3c42194d6c18a480d9a7f3f7550f011c69ff276707e2bae5e6143f7943343174
* Filename: dbus-socks | evip-socks
* File description: Microsocks proxy

SHA256 hash:

* b9f67565b56c9464462fa52d937202eef0b5554993c6b2bec8c955db64460cc7
* Filename: dbus-console
* File description: SGSN Emulator

SHA256 hash:

* 188861d7f0861103886543eff63a96c314c8262dbf52c6e0cf9372cf1e889d52
* Filename: evip-echo | pickup
* File description: EchoBackdoor

SHA256 hash:

* 4985de6574ff34009b6c72504af602a21c152ec104b022d6be94e2fec607eb43
* Filename: start\_evip\_daemond
* File description: Launching script for EchoBackdoor

SHA256 hash:

* 0bb3b4d8b72fec995c56a8a0baf55f2a07d2b361ee127c2b9deced24f67426fd
* Filename: stop\_evip\_daemond
* File description: Terminating script of EchoBackdoor

SHA256 hash:

* aa661e149f0a6a9a61cadcca47a83893a9e6a5cdb41c3b075175da28e641a80f
* Filename: cupsd | audittd
* File description: NoDepDNS

SHA256 hash:

* 3191e1516f39d72191e6c89460f7273826e12d493577b75b6fdee036c85e5a7e
* Filename: watchdogdd
* File description: watchdog script to ensure NoDepDNS is running

SHA256 hash:

* 9e1f5a134d13167a9148f2d5a1e6a96136d22ecdfbc502aa974544e7efe16a22
* Filename: sshtun
* File description: Sets up SSH tunneling and executes watchdogdd

SHA256 hash:

* edb6ab4bba4d474e60ff266af230cb6c438056937b262f86d3779bdc14de72a4
* Filename: getfile
* File description: Python-based command to download a file via HTTP

SHA256 hash:

* b1e473dd70732ba34b7e985422bfd44f3883379569d89bee523f4263c7070fd9
* Filename: exploit\_userspec.py
* File description: Python script to exploit a known vulnerability CVE-2021-3156 for privilege escalation

SHA256 hash:

* 8e2dd7ed7c7bec7ff6ab69990c3172b1a9c2028f67b02f6f8c5429e968d2f8d2
* Filename: /usr/bin/dnsd
* File description: C2 tool via SSH tunneling

SHA256 hash:

* 3e186c24bae58de14b14332a6b14d269b84235a25a892f1327002149f0547739
* Filename: /usr/bin/autoreverse
* File description: Similar behavior as sshtun

SHA256 hash:

* 432125ca41a2c5957013c8bff09c4037ad18addccab872d46230dd662a2b8123
* Filename: /tmp/httpds
* File description: ChronosRAT

SHA256 hash:

* 540f60702ee5019cd2b39b38b07e17da69bde1f9ed3b4543ff26e9da7ba6e0be
* Filename: pam\_unix.so
* File description: AuthDoor

SHA256 hash:

* cd754125657f1d52c08f9274fda57600e12929847eee3f7bea2e60ca5ba7711d
* Filename: pam\_unix.so
* File description: AuthDoor

SHA256 hash:

* b9c91face6ddfecc26d444f891c24796dbc953fb33145749f30b17445400c87c
* Filename: /usr/bin/clearinfo
* File description: Similar behavior as watchdogdd

## Additional Resources

* [LIMINAL PANDA: A Roaming Threat to Telecommunications Companies](https://www.crowdstrike.com/en-us/blog/an-analysis-of-lightbasin-telecommunications-attacks/) -- CrowdStrike
* [Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers](https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers) -- Google Cloud Blog
* [Have Your Cake and Eat it Too? An Overview of UNC2891](https://cloud.google.com/blog/topics/threat-intelligence/unc2891-overview/) -- Google Cloud Blog
* [Live off the Land? How About Bringing Your Own Island? An Overview of UNC1945](https://cloud.google.com/blog/topics/threat-intelligence/live-off-the-land-an-overview-of-unc1945/) -- Google Cloud Blog
* [GTPDOOR - A novel backdoor tailored for covert access over the roaming exchange](https://haxrob.net/gtpdoor-a-novel-backdoor-tailored-for-covert-access-over-the-roaming-exchange/) -- haxrob
* [Sgsnemu - OsmoGGSN (former OpenGGSN) - Open Source Mobile Communications](https://osmocom.org/projects/openggsn/wiki/Sgsnemu) -- Osmocom
* [Chinese APT Abuses VSCode to Target Government in Asia](https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/) -- Unit 42, Palo Alto Networks

*Updated on July 29, 2025, at 4:46 p.m. PT to correct second-to-last SHA256 hash.*

*Updated on Aug. 4, 2025, at 11:45 a.m. PT to update product protections information.*

*Updated on Sept. 4, 2025, at 9:42 a.m. PT to correct the Microsocks proxy indicator hash*
Back to top

### Tags

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")
* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")
* [CL-STA-0969](https://unit42.paloaltonetworks.com/tag/cl-sta-0969/ "CL-STA-0969")
* [GALLIUM](https://unit42.paloaltonetworks.com/tag/gallium/ "GALLIUM")
* [GoLang](https://unit42.paloaltonetworks.com/tag/golang/ "GoLang")
* [Liminal Panda](https://unit42.paloaltonetworks.com/tag/liminal-panda/ "Liminal Panda")
* [PingPull](https://unit42.paloaltonetworks.com/tag/pingpull/ "PingPull")
* [Telecoms](https://unit42.paloaltonetworks.com/tag/telecoms/ "Telecoms")
* [UNC1945](https://unit42.paloaltonetworks.com/tag/unc1945/ "UNC1945")
* [UNC2891](https://unit42.paloaltonetworks.com/tag/unc2891/ "UNC2891")
* [UNC3886](https://unit42.paloaltonetworks.com/tag/unc3886/ "UNC3886")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: The Ηоmоgraph Illusion: Not Everything Is As It Seems](https://unit42.paloaltonetworks.com/homograph-attacks/ "The Ηоmоgraph Illusion: Not Everything Is As It Seems")

### Table of Contents

* 

### Related Articles

* [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "article - table of contents")
* [CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure](https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/ "article - table of contents")
* [Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns](https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/ "article - table of contents")

## Related Resources

![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")  
  ![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
