China-Nexus Hackers Target Telecommunication Providers with New Malware Attack
A sophisticated cyber threat group, identified as UAT-9244 and linked to China, has been actively targeting critical telecommunications infrastructure in South America since 2024.
A sophisticated cyber threat group, identified as UAT-9244 and linked to China, has been actively targeting critical telecommunications infrastructure in South America since 2024.
UAT-9244 is assessed to have operational similarities with known espionage groups such as FamousSparrow and Tropic Trooper. The group employs a three-stage malware arsenal to maintain a foothold in victim networks.
The primary implant, "TernDoor," is a custom Windows backdoor derived from the older CrowDoor malware. It uses dynamic-link library (DLL) side-loading to evade security measures. TernDoor executes remote commands, manages files, and gathers sensitive data. It includes an AES-encrypted Windows driver capable of suspending security processes and a command-line switch to uninstall the malware.
The second implant, "PeerTime," is an ELF-based backdoor designed for Linux and embedded systems, utilizing the BitTorrent protocol for communication with command and control (C2) servers. It downloads additional payloads and deploys them across networks using the BusyBox utility.
UAT-9244 is assessed to have operational similarities with known espionage groups such as FamousSparrow and Tropic Trooper.
The final tool, "BruteEntry," is a GoLang-based brute-force scanner installed on compromised network edge devices. It transforms these devices into Operational Relay Boxes (ORBs) to automate scanning against SSH, Postgres, and Tomcat servers.
UAT-9244 employs specific deployment mechanisms to maintain persistence and evade detection. On Windows, persistence is achieved through hidden scheduled tasks or Registry Run key modifications. On Linux, custom shell scripts are used for deployment, with specific checks for container environments.
BruteEntry registers infected hosts with the C2 server, obtains target lists, and reports successful intrusions using structured JSON format.
Overall, UAT-9244's infrastructure, combining TernDoor, PeerTime, and BruteEntry, presents a significant threat to telecommunications environments.
Based on reporting by GBHackers.
