惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
B
Blog
博客园_首页
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog RSS Feed
M
MIT News - Artificial intelligence
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
量子位
V
V2EX
Y
Y Combinator Blog
Hugging Face - Blog
Hugging Face - Blog
Martin Fowler
Martin Fowler
Recent Announcements
Recent Announcements
I
InfoQ
博客园 - 【当耐特】

Cyberwarzone

LinkedIn Sued Over Browser Extension Scanning Why Cyberwarfare Uses Ambiguity and Delayed Attribution as Pressure Why Cyberwarfare Pressures Trusted Access and Account Recovery Paths Why Cyberwarfare Keeps Pressuring Recovery Paths and Fallback Systems Why Cyberwarfare Keeps Pressuring Shared Service Providers Why Cyberwarfare Pressures Industry Clusters Why Cyberwarfare Turns Nearby Economies Into Spillover Zones Why Cyberwarfare Forces Firms to Scan Networks Early Why Cyberwarfare Targets Crisis Messaging Systems Why Cyberwarfare Keeps Pressuring Energy Networks Why Cyberwarfare Keeps Pressuring Communications Networks Why Cyberwarfare Keeps Pressuring Shipping and Logistics Networks Why Cyberwarfare Keeps Pressuring Banks and Financial Networks Why Endpoint Management Systems Are Becoming Cyberwarfare Choke Points Why Cyberwarfare Targets Healthcare and Medical Supply Chains Why Cyberwarfare Increasingly Exploits Trusted Civilian Apps Why Cyberwarfare Hits Civilian Companies First Critical Quest KACE SMA RCE (CVE-2025-32975) Under Attack Handala Rebounds After FBI Seizure, Exposing Iran Cyberwar Resilience Top 10 Cyber Escalation Risks Security Leaders Should Understand Top 10 Questions to Ask Before Calling an Incident Cyberwarfare Top 10 Cyber Deterrence Problems Security Leaders Should Understand Top 10 OT and ICS Risks in Modern Cyberwarfare Top 10 Cyberwarfare Doctrine Ideas Security Leaders Should Understand Top 10 Attribution Problems in State-Linked Cyber Operations Iran Cyberwar: Identity Systems Become the Target Iran Cyberwar Shifts to Spillover, Retaliation, and Control Top 10 Critical Infrastructure Sectors Most Exposed in Cyberwarfare Top 10 Below-Threshold Cyber Operations States Use Top 10 Differences Between Cyberwarfare and Cyber Espionage
Cisco Talos links UAT-9244 to TernDoor, PeerTime, and Bru...
2026-03-16 · via Cyberwarzone

Peter Chofield Avatar

Peter Chofield

·

2–3 minutes

Cisco Talos says a China-nexus threat actor it tracks as UAT-9244 has targeted telecommunications providers in South America since at least 2024, using a toolkit that includes the TernDoor and PeerTime backdoors and a scanner Talos calls BruteEntry. The researchers said the actor maintained access across Windows, Linux, and edge devices, giving it multiple options for persistence inside victim environments.

According to Cisco Talos’ report, the activity overlaps with tradecraft previously associated with Chinese state-linked intrusion sets targeting telecom infrastructure. Talos said UAT-9244 focused on obtaining long-term access to provider networks and used a mix of custom malware, valid accounts, remote administration tools, and living-off-the-land techniques to move laterally after the initial compromise.

“The actor demonstrated a clear interest in long-term, multi-platform persistence within telecom environments.” — Cisco Talos

TernDoor and PeerTime gave the actor cross-platform persistence

Talos said TernDoor is a backdoor used to establish remote access on both Windows and Linux systems, while PeerTime provides an additional persistence and command-and-control layer. The researchers said the actor deployed the malware after gaining footholds in telecom environments, then used it to retain access, execute commands, and support follow-on intrusion activity.

The report also describes BruteEntry as a network-scanning tool used by UAT-9244 to probe internet-facing infrastructure and identify potential paths deeper into targeted networks. Talos said the actor paired the malware with valid credentials and remote management access, allowing it to blend malicious activity with legitimate administrative traffic.

Talos tied the activity to South American telecom intrusions

Cisco Talos said UAT-9244 targeted telecommunications providers in South America, a sector that remains strategically valuable because provider networks can expose subscriber information, support interception operations, and provide access to broader regional infrastructure. The researchers said the campaign demonstrates continued interest by China-linked actors in telecom targets outside the United States and Europe.

Talos did not publicly name the affected providers in the report, but said the actor’s intrusion set shows a consistent focus on stealth, persistence, and long-term access. The findings add to Cyberwarzone’s recent coverage of FortiGate appliances being used as entry points for deeper enterprise compromise and broader tracking of cross-border cyber operations affecting critical digital infrastructure.

About the Author

Peter Chofield Avatar

Peter Chofield

Passionate about cybersecurity, Peter dedicates his days to reading, analyzing, and writing about the trends shaping the online world.