Threat reportAPTTL-2026-0191
UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom
UAT-9244 (China-Nexus FamousSparrow Cluster) (TL-2026-0191), also tracked as UAT-9244, is a high-severity advanced persistent threat campaign, first published 2026-03-07. It is attributed to UAT-9244 (China) with high confidence, affects Telecommunications Providers Critical Telecom Infrastructure, maps to 24 MITRE ATT&CK techniques (T1005, T1014, T1021.004), and is covered by 9 detection rules and 40 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 2UAT-9244
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 40Indicators of compromise
Key facts for TL-2026-0191
- Threat ID
- TL-2026-0191
- Also known as
- UAT-9244, Operation TernDoor
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- UAT-9244, GhostEmperor
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- telecommunications, critical-infrastructure
- Target regions
- South America
- Detection rules
- 9
- Indicators of compromise
- 40
Malware and tooling in UAT-9244 (China-Nexus FamousSparrow Cluster)
Malware and tooling: BruteEntry, PeerTime, TernDoor
How UAT-9244 (China-Nexus FamousSparrow Cluster) works
Cisco Talos-attributed China-nexus threat cluster UAT-9244 (overlapping with FamousSparrow/Salt Typhoon) is actively targeting critical telecommunications infrastructure across South America with three previously undocumented malware families: TernDoor (Windows DLL-sideloading backdoor derived from CrowDoor/SparrowDoor), PeerTime/angrypeer (multi-architecture Linux implant using BitTorrent protocol for C2), and BruteEntry (Golang-based brute-force scanner converting edge devices into Operational Relay Box proxy nodes).
UAT-9244 is a China-nexus advanced persistent threat actor assessed by Cisco Talos with high confidence to be closely associated with FamousSparrow, with tactical overlaps to Earth Estries and Tropic Trooper based on shared tooling, TTPs, and victimology. The group has been actively targeting critical telecommunications providers in South America since at least 2024, deploying three distinct malware families across Windows endpoints, Linux systems, and network edge devices.
**TernDoor (Windows Backdoor):** TernDoor is a new variant of CrowDoor, itself a variant of the SparrowDoor malware family associated with FamousSparrow operations. It is deployed via DLL side-loading using the legitimate executable wsprint.exe to load a rogue DLL named BugSplatRc64.dll. The loader reads an encoded payload (WSPrint.dll) from disk, decrypts it using the hardcoded key 'qwiozpVngruhg123', and executes position-independent shellcode that decompresses the final TernDoor payload in memory. TernDoor establishes persistence through a scheduled task named WSPrint running as SYSTEM on startup, and via Registry Run key entries at HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The malware hides its scheduled task by deleting the SD (Security Descriptor) value and setting Index to 0 in the TaskCache registry. TernDoor's shellcode embeds an AES-encrypted Windows driver (WSPrint.sys) that creates device \\Device\\VMTool with symlink \\DosDevices\\VMTool, providing kernel-level capabilities to suspend, resume, and terminate processes. Core capabilities include C2 communications over HTTPS (port 443), process creation and arbitrary command execution, file read/write operations, system information collection (computer name, username, IP, OS bitness), self-uninstallation via the -u switch, and process injection into msiexec.exe. All discovered C2 servers share a common self-signed SSL certificate (CN=8.8.8.8) issued September 4, 2022.
**PeerTime / angrypeer (Linux Multi-Architecture Backdoor):** PeerTime is an ELF-based backdoor targeting ARM, AARCH64, PPC, and MIPS architectures, indicating it was designed to compromise embedded systems and network devices common in telecom environments. Deployment occurs via shell scripts that download the PeerTime loader ELF binary along with an instrumentor binary. The instrumentor checks for Docker presence (via 'docker' and 'docker -q' commands) and contains debug strings in Simplified Chinese, a key attribution indicator. The loader decrypts and decompresses the ELF payload, executing it in memory. PeerTime employs the BitTorrent protocol for C2 communications — a novel evasion technique that blends malicious traffic with legitimate peer-to-peer file sharing. It downloads and executes payloads from peers, uses BusyBox to write files to specified disk locations, and renames itself as harmless processes to evade detection. Two variants exist: the original C/C++ version and a newer Rust-based variant, tracked on VirusTotal as 'angrypeer'.
**BruteEntry (Golang ORB Scanner):** BruteEntry is a Golang-based brute-force scanner deployed via shell scripts on network edge devices. It converts compromised devices into mass-scanning proxy nodes within an Operational Relay Box (ORB) network. Upon deployment, the agent registers with its C2 via HTTP POST containing the device IP and hostname, receiving an agent_id and version string. It then fetches scanning tasks (GET /tasks/<agent_id>?limit=1000) containing target IP lists. BruteEntry targets PostgreSQL (port 5432), SSH (port 22), and Apache Tomcat management interfaces (HTTPS /manager/html). Successful credential compromises are reported back to C2 with notes identifying the cracking agent and version. This ORB infrastructure provides UAT-9244 with distributed, anonymized scanning capabilities across victim networks.
**Attribution:** Talos assesses with high confidence that UAT-9244 is a China-nexus APT closely associated with FamousSparrow, with overlaps to Earth Estries and Tropic Trooper. Key attribution indicators include Simplified Chinese debug strings in the PeerTime instrumentor binary, the CrowDoor/SparrowDoor malware lineage, and shared TTPs and victimology. While FamousSparrow shares tactical overlaps with Salt Typhoon (Microsoft designation), Talos was unable to verify a direct connection between UAT-9244 and Salt Typhoon despite both targeting telecommunications providers.
---
**Revalidated on 2026-03-12**
One week after the initial Cisco Talos disclosure on March 5, 2026, UAT-9244 has been extensively corroborated across the threat intelligence community with no conflicting assessments. The three-malware toolkit (TernDoor, PeerTime, BruteEntry) targeting South American telecom providers represents a confirmed and active campaign. Key revalidation findings include:
**Attribution Strengthened:** The FamousSparrow cluster connection is now supported by two independent research tracks. ESET's March 2025 report confirmed FamousSparrow was never dormant during 2022-2024, deploying upgraded SparrowDoor variants and ShadowPad against US financial, Mexican research, and Honduran government targets. TernDoor's CrowDoor/SparrowDoor lineage directly links UAT-9244 to this same tool evolution chain. ESET maintains FamousSparrow is distinct from but operationally adjacent to Earth Estries and GhostEmperor, with overlaps possibly stemming from a shared 'digital quartermaster' rather than unified command.
**Broader Campaign Context:** The CISA/FBI/NSA joint advisory AA25-239A (August 2025) documented Chinese state-sponsored actors including Salt Typhoon compromising telecom, government, and military networks in 80+ countries since 2021, exploiting known vulnerabilities in backbone routers. FBI's February 2026 confirmation that Salt Typhoon threats remain 'very much ongoing' places UAT-9244's South American telecom targeting within a larger, sustained Chinese state espionage campaign against global telecommunications infrastructure. The advisory attributed this activity to MSS and PLA-linked entities.
**ORB Network Pattern:** BruteEntry's conversion of edge devices into Operational Relay Boxes aligns with Mandiant's documented ORB network research showing China-nexus actors increasingly using compromised IoT devices, SOHO routers, and VPS infrastructure as proxy mesh networks to evade detection and complicate attribution. This represents an evolution beyond traditional C2 infrastructure.
**Detection Coverage:** ClamAV signatures (Win.Loader.PeerTime, Win.Malware.TernDoor, Unix.Malware.BruteEntry, Txt.Malware.PeerTime, Unix.Malware.PeerTime) and Snort SID 65551 are available from Cisco Talos. Broadcom/Symantec has published a protection bulletin. Comprehensive IOCs including 50+ SHA256 file hashes, 22+ C2 IP addresses, 3 C2 domains (bloopencil.net, xcit76.com, xtibh.com), and a shared SSL certificate fingerprint are publicly available for defensive deployment.
**No Remediation Observed:** As of March 12, 2026, no takedowns, infrastructure disruptions, or law enforcement actions have been reported against UAT-9244's C2 infrastructure. The campaign should be considered actively ongoing.
MITRE ATT&CK techniques used in TL-2026-0191
collection
defense-evasion
T1014 Rootkit; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts
lateral-movement
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053.005 Scheduled Task; T1059.003 Windows Command Shell; T1059.004 Unix Shell
discovery
T1057 Process Discovery; T1082 System Information Discovery
command-and-control
T1071.001 Web Protocols; T1095 Non-Application Layer Protocol; T1573.001 Symmetric Cryptography
credential-access
initial-access
T1190 Exploit Public-Facing Application
persistence
T1505.003 Web Shell; T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL
resource-development
Affected products and versions in UAT-9244 (China-Nexus FamousSparrow Cluster)
- Telecommunications Providers — Critical Telecom Infrastructure
Vulnerable versions: Windows Server (outdated versions); Microsoft Exchange Server (outdated versions); Linux embedded systems (ARM, AARCH64, PPC, MIPS); Network edge devices - Microsoft — Windows Server
Vulnerable versions: Outdated versions targeted for initial access
Fixed in: Latest patched versions - Microsoft — Exchange Server
Vulnerable versions: Outdated versions targeted for initial access
Fixed in: Latest patched versions - Multiple — Linux Embedded Systems
Vulnerable versions: ARM, AARCH64, PPC, MIPS architectures - Apache — Tomcat
Vulnerable versions: Instances with weak management credentials - PostgreSQL — PostgreSQL Server
Vulnerable versions: Instances with weak credentials exposed to network
Remediation for UAT-9244 (China-Nexus FamousSparrow Cluster)
Immediate actions
- Block all identified C2 IP addresses at network perimeter (154.205.154.82, 207.148.121.95, 207.148.120.52, 212.11.64.105, 185.196.10.247, 185.196.10.38)
- Block C2 domains: xtibh.com, xcit76.com, bloopencil.net at DNS and proxy layers
- Hunt for DLL side-loading artifacts: wsprint.exe loading BugSplatRc64.dll from C:\ProgramData\WSPrint\
- Search for scheduled task named WSPrint running as SYSTEM
- Check Registry Run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for WSPrint entries
- Scan for WSPrint.sys driver and \\Device\\VMTool device creation
- Hunt Linux/embedded systems for PeerTime ELF binaries across ARM/AARCH64/PPC/MIPS
- Monitor for anomalous BitTorrent protocol traffic from server infrastructure
- Audit edge device integrity for BruteEntry ORB agent installations
- Rotate all SSH, PostgreSQL, and Tomcat management credentials
Workarounds
- Disable or restrict Tomcat Manager web interface access to trusted IPs only
- Enforce SSH key-based authentication and disable password authentication
- Restrict PostgreSQL remote access to known management IPs
- Block BusyBox execution on production Linux systems where not required
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading and process injection into msiexec.exe
- Implement network segmentation between telecom OT/IT environments and edge device networks
- Deploy SSL/TLS inspection to detect self-signed certificates mimicking legitimate services (CN=8.8.8.8)
- Monitor for BitTorrent protocol usage on non-standard infrastructure segments
- Implement application whitelisting on critical telecom infrastructure
- Deploy multi-architecture Linux EDR covering ARM, MIPS, PPC platforms on embedded/edge devices
- Implement privileged access management for Tomcat, PostgreSQL, and SSH services
- Establish ORB/proxy detection capabilities at network boundaries
Weaknesses (CWE) in UAT-9244 (China-Nexus FamousSparrow Cluster)
Timeline of UAT-9244 (China-Nexus FamousSparrow Cluster)
- Self-signed SSL certificate (CN=8.8.8.8) issued for UAT-9244 C2 infrastructure, valid until September 4, 2023. All discovered TernDoor C2 servers share this certificate on port 443.
- TernDoor backdoor enters active development, marking UAT-9244's evolution of the CrowDoor/SparrowDoor malware lineage with new command codes and embedded kernel driver capabilities.
- UAT-9244 begins targeting South American telecommunications providers, deploying TernDoor on Windows endpoints and PeerTime on Linux/embedded systems.
- ESET publishes research revealing FamousSparrow resurfaced with two new SparrowDoor backdoor variants and first-time ShadowPad deployment, compromising a US financial sector trade group (July 2024), a Mexican research institute, and a Honduran government institution. Confirms FamousSparrow was active during 2022-2024 despite no public reporting. [Source: https://www.welivesecurity.com/en/eset-research/you-will-always-remember-this-as-the-day-you-finally-caught-famoussparrow/]
- ESET publishes research on FamousSparrow updated SparrowDoor variants and ShadowPad deployment targeting US financial sector and Mexican research institute, establishing CrowDoor lineage connection.
- CISA, FBI, NSA, and international partners release joint advisory AA25-239A documenting Chinese state-sponsored actors (Salt Typhoon/GhostEmperor/OPERATOR PANDA) compromising telecommunications, government, and military networks worldwide since 2021. Advisory attributes activity to PLA and MSS-linked Chinese firms. [Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a]
- Trend Micro identifies Earth Estries/CrowDoor tactical overlap with FamousSparrow operations, strengthening attribution links to the broader China-nexus cluster.
- FBI Deputy Assistant Director Michael Machtinger states at CyberTalks 2026 that Salt Typhoon threats remain ''still very, very much ongoing,'' with intrusions impacting 80+ countries across public and private sectors. [Source: https://cyberscoop.com/fbi-salt-typhoon-ongoing-threat-cybertalks-2026/]
- Malpedia creates dedicated UAT-9244 threat actor entry, cataloging the actor profile and associated malware families. [Source: https://malpedia.caad.fkie.fraunhofer.de/actor/uat-9244]
- Cisco Talos publicly discloses UAT-9244 threat cluster and three previously undocumented malware families (TernDoor, PeerTime, BruteEntry) targeting South American telecommunications providers since November 2024. Assessment links UAT-9244 with high confidence to FamousSparrow with overlaps to Earth Estries and Tropic Trooper. [Source: https://blog.talosintelligence.com/uat-9244/]
- Wide industry amplification of UAT-9244 disclosure by The Hacker News, BleepingComputer, CyberSecurityNews, GovInfoSecurity, CyberInsider, and multiple threat intelligence aggregators, raising global awareness of the three-implant toolkit targeting telecom infrastructure. [Source: https://thehackernews.com/2026/03/china-linked-hackers-use-terndoor.html]
- Full IOC package released including 60+ file hashes, 22+ infrastructure IPs, 3 C2 domains, SSL certificate fingerprints, ClamAV signatures, and Snort rule SID 65551.
- Cisco Talos publishes comprehensive analysis of UAT-9244 campaign, disclosing three new malware families (TernDoor, PeerTime, BruteEntry) and ORB network infrastructure targeting South American telecom.
- TechCrunch publishes comprehensive Salt Typhoon victim tracker documenting the global scope of Chinese state telecom hacking, describing it as ''one of the broadest hacking campaigns in recent years'' with tens of millions of stolen phone records. [Source: https://techcrunch.com/2026/03/09/salt-typhoon-china-who-has-been-hacked-global-telecom-giants/]
- As of 2026-05-29, TL-2026-0191 (UAT-9244/FamousSparrow) remains ACTIVE: no CVE to patch, no takedown or disruption reported, and the China-nexus actor is operating with adaptive evolution of its TernDoor toolset. A May 2026 report confirms FamousSparrow deployed TernDoor against an Azerbaijani energy firm (Dec 2025-Feb 2026), corroborating an ongoing, espionage-driven campaign.
Sources cited for UAT-9244 (China-Nexus FamousSparrow Cluster)
- Cisco Talos: UAT-9244 targets South American telecommunication providers with three new malware implants
- The Hacker News: China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks
- BleepingComputer: Chinese state hackers target telcos with new malware toolkit
- CyberInsider: Chinese hackers target telcos in South America with new malware
- CybersecurityNews: China-Nexus Hackers Attacking Telecommunication Providers With New Malware
- GovInfoSecurity: China-Linked Hackers Use Malware Trio for Telecom Espionage
- Threat Intelligence Report: UAT-9244 hits South American telcos with TernDoor, PeerTime and BruteEntry
- ESET: FamousSparrow cyberespionage attacks in the United States
- WeLiveSecurity: You will always remember this as the day you finally caught FamousSparrow
- Cisco Talos IOCs GitHub Repository
- Picus Security: Salt Typhoon — A Persistent Threat to Global Telecommunications Infrastructure
Detection coverage for TL-2026-0191
As of 2026-03-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0191 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.