@h2jazi Thanks for sharing this intel,
I did some follwo-up research and found one of the communicated domains (acroipm2[.]adobe[.]com) which was observed in previous campaign by APT27
Chinese 🇨🇳 APT group Red Menshen plants kernel-level BPFdoor backdoors in global telecom networks, creating "sleeper cells" for long-term espionage. New variants hide in HTTPS traffic and monitor 4G/5G signaling protocols.
Key findings:
• BPFdoor evolved from magic packet activation to Layer-7 HTTPS camouflage with RC4-MD5 encryption
• Implants target SCTP signaling protocols used in 4G/5G core networks for subscriber tracking
• Masquerades as legitimate services like HPE ProLiant hardware daemons and Docker containers
• ICMP tunneling enables covert C2 between compromised hosts using 0xFFFFFFFF terminal markers
• Affects telecom edge infrastructure: Ivanti VPNs, Cisco/Juniper routers, Fortinet firewalls
Attack chain leverages:
• Initial access via T1190 exploitation of public-facing telecom appliances
• CrossC2 beacons for Linux post-exploitation and lateral movement
• TinyShell passive backdoors on boundary devices for persistence
• Custom keyloggers with telecom-specific credential lists (usernames like "imsi")
DFIR artifacts include raw socket usage, anomalous BPF filters in kernel space, unexpected hardware service processes on non-HPE systems, and HTTPS traffic with fixed-offset padding schemes.
Hunt for unusual BPF syscalls, processes mimicking bare-metal hardware services on virtualized systems, and SCTP traffic inspection on non-telecom hosts.
#DFIR_Radar
@xabdul سؤال اخ عبدالرحمن
لاحظت ان فيه مصدر اخر تكلم عن نفس الحادثة بس ربط الحادثة مع مجموعة Sandworm
هل Dragos ذاكرينه على انه Alias اخر لنفس المجموعة ولا وش الفكرة؟
"الكورة العرضية .. اللي بيزيد معها روبن نيفيز، هذا اكثر ما يخوفك يا لوران بلان"
هكذا سجل الهلال هدفه الاول، بنفس السيناريو اللي قلناه في بودكاست شوط قبل 5 ايام 😄💙