Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

China-Nexus Hackers Target Telecommunication Providers with New Malware Attack

A sophisticated cyber threat group, identified as UAT-9244 and linked to China, has been actively targeting critical telecommunications infrastructure in South America since 2024.

A sophisticated cyber threat group, identified as UAT-9244 and linked to China, has been actively targeting critical telecommunications infrastructure in South America since 2024.

UAT-9244 is assessed to have operational similarities with known espionage groups such as FamousSparrow and Tropic Trooper. The group employs a three-stage malware arsenal to maintain a foothold in victim networks.

The primary implant, "TernDoor," is a custom Windows backdoor derived from the older CrowDoor malware. It uses dynamic-link library (DLL) side-loading to evade security measures. TernDoor executes remote commands, manages files, and gathers sensitive data. It includes an AES-encrypted Windows driver capable of suspending security processes and a command-line switch to uninstall the malware.

The second implant, "PeerTime," is an ELF-based backdoor designed for Linux and embedded systems, utilizing the BitTorrent protocol for communication with command and control (C2) servers. It downloads additional payloads and deploys them across networks using the BusyBox utility.

UAT-9244 is assessed to have operational similarities with known espionage groups such as FamousSparrow and Tropic Trooper.
Thomas Blake · Thehackingpost

The final tool, "BruteEntry," is a GoLang-based brute-force scanner installed on compromised network edge devices. It transforms these devices into Operational Relay Boxes (ORBs) to automate scanning against SSH, Postgres, and Tomcat servers.

UAT-9244 employs specific deployment mechanisms to maintain persistence and evade detection. On Windows, persistence is achieved through hidden scheduled tasks or Registry Run key modifications. On Linux, custom shell scripts are used for deployment, with specific checks for container environments.

BruteEntry registers infected hosts with the C2 server, obtains target lists, and reports successful intrusions using structured JSON format.

Advertisement

Overall, UAT-9244's infrastructure, combining TernDoor, PeerTime, and BruteEntry, presents a significant threat to telecommunications environments.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories