PULSE NAME
South American telecommunication providers targeted with three new malware implants
WHITE UAT-9244 AlienVault 2026-03-05 Modified: 2026-04-04
72
IOCs
HIGH VOLUME
UAT-9244, a China-nexus advanced persistent threat actor, has been targeting critical telecommunications infrastructure in South America since 2024. The group employs three new malware implants: TernDoor, a Windows-based backdoor variant of CrowDoor; PeerTime, an ELF-based backdoor using BitTorrent protocol; and BruteEntry, a brute force scanner for SSH, Postgres, and Tomcat servers. UAT-9244 uses dynamic-link library side-loading, scheduled tasks, and registry modifications for persistence. The group is closely associated with FamousSparrow and Tropic Trooper, sharing similar tooling and tactics. Their infrastructure includes multiple command and control servers and operational relay boxes for scanning and brute-forcing activities.
Indicators of Compromise (12 / 72 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 02b804b02aac1ab4cfc8e88dbcb5ee96 2026-03-05
FileHash-MD5 05580309235fa04c22cf6cbd31ef39ce 2026-03-05
FileHash-MD5 12ad67761f785db7405de3c0ea76ff09 2026-03-05
FileHash-MD5 236c79305336f4dddbe25eb24f5cbd1a 2026-03-05
FileHash-MD5 24f2be6bd956c54db1b93c4c97fdb431 2026-03-05
FileHash-MD5 3a4ccd2ef01f6956decba1038669cbbe 2026-03-05
FileHash-MD5 6cf3ed386024c73e6666416437f2e6a7 2026-03-05
FileHash-MD5 e0ab78a2f5b92d265437fc9dd86e2899 2026-03-05
FileHash-MD5 e0c13dcf6ee7065400c7617bba781d75 2026-03-05
FileHash-MD5 e75df6e03fc11fa8bd75351b0d5bce6c 2026-03-05
FileHash-MD5 fbf96d77f4cc47d9b583313649653377 2026-03-05
FileHash-MD5 ff3a1b28267dd826d4e1c46c6f54bd55 2026-03-05