Threat reportAPTTL-2026-0191

UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom

highACTIVE

UAT-9244 (China-Nexus FamousSparrow Cluster) (TL-2026-0191), also tracked as UAT-9244, is a high-severity advanced persistent threat campaign, first published 2026-03-07. It is attributed to UAT-9244 (China) with high confidence, affects Telecommunications Providers Critical Telecom Infrastructure, maps to 24 MITRE ATT&CK techniques (T1005, T1014, T1021.004), and is covered by 9 detection rules and 40 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
2UAT-9244
Detection rules
9SPL · KQL · Sigma
IOCs
40Indicators of compromise

Key facts for TL-2026-0191

Threat ID
TL-2026-0191
Also known as
UAT-9244, Operation TernDoor
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
UAT-9244, GhostEmperor
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
telecommunications, critical-infrastructure
Target regions
South America
Detection rules
9
Indicators of compromise
40

Malware and tooling in UAT-9244 (China-Nexus FamousSparrow Cluster)

Malware and tooling: BruteEntry, PeerTime, TernDoor

How UAT-9244 (China-Nexus FamousSparrow Cluster) works

Cisco Talos-attributed China-nexus threat cluster UAT-9244 (overlapping with FamousSparrow/Salt Typhoon) is actively targeting critical telecommunications infrastructure across South America with three previously undocumented malware families: TernDoor (Windows DLL-sideloading backdoor derived from CrowDoor/SparrowDoor), PeerTime/angrypeer (multi-architecture Linux implant using BitTorrent protocol for C2), and BruteEntry (Golang-based brute-force scanner converting edge devices into Operational Relay Box proxy nodes).

UAT-9244 is a China-nexus advanced persistent threat actor assessed by Cisco Talos with high confidence to be closely associated with FamousSparrow, with tactical overlaps to Earth Estries and Tropic Trooper based on shared tooling, TTPs, and victimology. The group has been actively targeting critical telecommunications providers in South America since at least 2024, deploying three distinct malware families across Windows endpoints, Linux systems, and network edge devices.

**TernDoor (Windows Backdoor):** TernDoor is a new variant of CrowDoor, itself a variant of the SparrowDoor malware family associated with FamousSparrow operations. It is deployed via DLL side-loading using the legitimate executable wsprint.exe to load a rogue DLL named BugSplatRc64.dll. The loader reads an encoded payload (WSPrint.dll) from disk, decrypts it using the hardcoded key 'qwiozpVngruhg123', and executes position-independent shellcode that decompresses the final TernDoor payload in memory. TernDoor establishes persistence through a scheduled task named WSPrint running as SYSTEM on startup, and via Registry Run key entries at HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The malware hides its scheduled task by deleting the SD (Security Descriptor) value and setting Index to 0 in the TaskCache registry. TernDoor's shellcode embeds an AES-encrypted Windows driver (WSPrint.sys) that creates device \\Device\\VMTool with symlink \\DosDevices\\VMTool, providing kernel-level capabilities to suspend, resume, and terminate processes. Core capabilities include C2 communications over HTTPS (port 443), process creation and arbitrary command execution, file read/write operations, system information collection (computer name, username, IP, OS bitness), self-uninstallation via the -u switch, and process injection into msiexec.exe. All discovered C2 servers share a common self-signed SSL certificate (CN=8.8.8.8) issued September 4, 2022.

**PeerTime / angrypeer (Linux Multi-Architecture Backdoor):** PeerTime is an ELF-based backdoor targeting ARM, AARCH64, PPC, and MIPS architectures, indicating it was designed to compromise embedded systems and network devices common in telecom environments. Deployment occurs via shell scripts that download the PeerTime loader ELF binary along with an instrumentor binary. The instrumentor checks for Docker presence (via 'docker' and 'docker -q' commands) and contains debug strings in Simplified Chinese, a key attribution indicator. The loader decrypts and decompresses the ELF payload, executing it in memory. PeerTime employs the BitTorrent protocol for C2 communications — a novel evasion technique that blends malicious traffic with legitimate peer-to-peer file sharing. It downloads and executes payloads from peers, uses BusyBox to write files to specified disk locations, and renames itself as harmless processes to evade detection. Two variants exist: the original C/C++ version and a newer Rust-based variant, tracked on VirusTotal as 'angrypeer'.

**BruteEntry (Golang ORB Scanner):** BruteEntry is a Golang-based brute-force scanner deployed via shell scripts on network edge devices. It converts compromised devices into mass-scanning proxy nodes within an Operational Relay Box (ORB) network. Upon deployment, the agent registers with its C2 via HTTP POST containing the device IP and hostname, receiving an agent_id and version string. It then fetches scanning tasks (GET /tasks/<agent_id>?limit=1000) containing target IP lists. BruteEntry targets PostgreSQL (port 5432), SSH (port 22), and Apache Tomcat management interfaces (HTTPS /manager/html). Successful credential compromises are reported back to C2 with notes identifying the cracking agent and version. This ORB infrastructure provides UAT-9244 with distributed, anonymized scanning capabilities across victim networks.

**Attribution:** Talos assesses with high confidence that UAT-9244 is a China-nexus APT closely associated with FamousSparrow, with overlaps to Earth Estries and Tropic Trooper. Key attribution indicators include Simplified Chinese debug strings in the PeerTime instrumentor binary, the CrowDoor/SparrowDoor malware lineage, and shared TTPs and victimology. While FamousSparrow shares tactical overlaps with Salt Typhoon (Microsoft designation), Talos was unable to verify a direct connection between UAT-9244 and Salt Typhoon despite both targeting telecommunications providers.

---

**Revalidated on 2026-03-12**

One week after the initial Cisco Talos disclosure on March 5, 2026, UAT-9244 has been extensively corroborated across the threat intelligence community with no conflicting assessments. The three-malware toolkit (TernDoor, PeerTime, BruteEntry) targeting South American telecom providers represents a confirmed and active campaign. Key revalidation findings include:

**Attribution Strengthened:** The FamousSparrow cluster connection is now supported by two independent research tracks. ESET's March 2025 report confirmed FamousSparrow was never dormant during 2022-2024, deploying upgraded SparrowDoor variants and ShadowPad against US financial, Mexican research, and Honduran government targets. TernDoor's CrowDoor/SparrowDoor lineage directly links UAT-9244 to this same tool evolution chain. ESET maintains FamousSparrow is distinct from but operationally adjacent to Earth Estries and GhostEmperor, with overlaps possibly stemming from a shared 'digital quartermaster' rather than unified command.

**Broader Campaign Context:** The CISA/FBI/NSA joint advisory AA25-239A (August 2025) documented Chinese state-sponsored actors including Salt Typhoon compromising telecom, government, and military networks in 80+ countries since 2021, exploiting known vulnerabilities in backbone routers. FBI's February 2026 confirmation that Salt Typhoon threats remain 'very much ongoing' places UAT-9244's South American telecom targeting within a larger, sustained Chinese state espionage campaign against global telecommunications infrastructure. The advisory attributed this activity to MSS and PLA-linked entities.

**ORB Network Pattern:** BruteEntry's conversion of edge devices into Operational Relay Boxes aligns with Mandiant's documented ORB network research showing China-nexus actors increasingly using compromised IoT devices, SOHO routers, and VPS infrastructure as proxy mesh networks to evade detection and complicate attribution. This represents an evolution beyond traditional C2 infrastructure.

**Detection Coverage:** ClamAV signatures (Win.Loader.PeerTime, Win.Malware.TernDoor, Unix.Malware.BruteEntry, Txt.Malware.PeerTime, Unix.Malware.PeerTime) and Snort SID 65551 are available from Cisco Talos. Broadcom/Symantec has published a protection bulletin. Comprehensive IOCs including 50+ SHA256 file hashes, 22+ C2 IP addresses, 3 C2 domains (bloopencil.net, xcit76.com, xtibh.com), and a shared SSL certificate fingerprint are publicly available for defensive deployment.

**No Remediation Observed:** As of March 12, 2026, no takedowns, infrastructure disruptions, or law enforcement actions have been reported against UAT-9244's C2 infrastructure. The campaign should be considered actively ongoing.

MITRE ATT&CK techniques used in TL-2026-0191

collection

T1005 Data from Local System

defense-evasion

T1014 Rootkit; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts

lateral-movement

T1021.004 SSH

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1053.005 Scheduled Task; T1059.003 Windows Command Shell; T1059.004 Unix Shell

discovery

T1057 Process Discovery; T1082 System Information Discovery

command-and-control

T1071.001 Web Protocols; T1095 Non-Application Layer Protocol; T1573.001 Symmetric Cryptography

credential-access

T1110.001 Password Guessing

initial-access

T1190 Exploit Public-Facing Application

persistence

T1505.003 Web Shell; T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL

resource-development

T1583.003 Virtual Private Server; T1587.001 Malware

Affected products and versions in UAT-9244 (China-Nexus FamousSparrow Cluster)

  • Telecommunications Providers — Critical Telecom Infrastructure
    Vulnerable versions: Windows Server (outdated versions); Microsoft Exchange Server (outdated versions); Linux embedded systems (ARM, AARCH64, PPC, MIPS); Network edge devices
  • Microsoft — Windows Server
    Vulnerable versions: Outdated versions targeted for initial access
    Fixed in: Latest patched versions
  • Microsoft — Exchange Server
    Vulnerable versions: Outdated versions targeted for initial access
    Fixed in: Latest patched versions
  • Multiple — Linux Embedded Systems
    Vulnerable versions: ARM, AARCH64, PPC, MIPS architectures
  • Apache — Tomcat
    Vulnerable versions: Instances with weak management credentials
  • PostgreSQL — PostgreSQL Server
    Vulnerable versions: Instances with weak credentials exposed to network

Remediation for UAT-9244 (China-Nexus FamousSparrow Cluster)

Immediate actions

  • Block all identified C2 IP addresses at network perimeter (154.205.154.82, 207.148.121.95, 207.148.120.52, 212.11.64.105, 185.196.10.247, 185.196.10.38)
  • Block C2 domains: xtibh.com, xcit76.com, bloopencil.net at DNS and proxy layers
  • Hunt for DLL side-loading artifacts: wsprint.exe loading BugSplatRc64.dll from C:\ProgramData\WSPrint\
  • Search for scheduled task named WSPrint running as SYSTEM
  • Check Registry Run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for WSPrint entries
  • Scan for WSPrint.sys driver and \\Device\\VMTool device creation
  • Hunt Linux/embedded systems for PeerTime ELF binaries across ARM/AARCH64/PPC/MIPS
  • Monitor for anomalous BitTorrent protocol traffic from server infrastructure
  • Audit edge device integrity for BruteEntry ORB agent installations
  • Rotate all SSH, PostgreSQL, and Tomcat management credentials

Workarounds

  • Disable or restrict Tomcat Manager web interface access to trusted IPs only
  • Enforce SSH key-based authentication and disable password authentication
  • Restrict PostgreSQL remote access to known management IPs
  • Block BusyBox execution on production Linux systems where not required

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL side-loading and process injection into msiexec.exe
  • Implement network segmentation between telecom OT/IT environments and edge device networks
  • Deploy SSL/TLS inspection to detect self-signed certificates mimicking legitimate services (CN=8.8.8.8)
  • Monitor for BitTorrent protocol usage on non-standard infrastructure segments
  • Implement application whitelisting on critical telecom infrastructure
  • Deploy multi-architecture Linux EDR covering ARM, MIPS, PPC platforms on embedded/edge devices
  • Implement privileged access management for Tomcat, PostgreSQL, and SSH services
  • Establish ORB/proxy detection capabilities at network boundaries

Weaknesses (CWE) in UAT-9244 (China-Nexus FamousSparrow Cluster)

CWE-426, CWE-798, CWE-307

Timeline of UAT-9244 (China-Nexus FamousSparrow Cluster)

  • Self-signed SSL certificate (CN=8.8.8.8) issued for UAT-9244 C2 infrastructure, valid until September 4, 2023. All discovered TernDoor C2 servers share this certificate on port 443.
  • TernDoor backdoor enters active development, marking UAT-9244's evolution of the CrowDoor/SparrowDoor malware lineage with new command codes and embedded kernel driver capabilities.
  • UAT-9244 begins targeting South American telecommunications providers, deploying TernDoor on Windows endpoints and PeerTime on Linux/embedded systems.
  • ESET publishes research revealing FamousSparrow resurfaced with two new SparrowDoor backdoor variants and first-time ShadowPad deployment, compromising a US financial sector trade group (July 2024), a Mexican research institute, and a Honduran government institution. Confirms FamousSparrow was active during 2022-2024 despite no public reporting. [Source: https://www.welivesecurity.com/en/eset-research/you-will-always-remember-this-as-the-day-you-finally-caught-famoussparrow/]
  • ESET publishes research on FamousSparrow updated SparrowDoor variants and ShadowPad deployment targeting US financial sector and Mexican research institute, establishing CrowDoor lineage connection.
  • CISA, FBI, NSA, and international partners release joint advisory AA25-239A documenting Chinese state-sponsored actors (Salt Typhoon/GhostEmperor/OPERATOR PANDA) compromising telecommunications, government, and military networks worldwide since 2021. Advisory attributes activity to PLA and MSS-linked Chinese firms. [Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a]
  • Trend Micro identifies Earth Estries/CrowDoor tactical overlap with FamousSparrow operations, strengthening attribution links to the broader China-nexus cluster.
  • FBI Deputy Assistant Director Michael Machtinger states at CyberTalks 2026 that Salt Typhoon threats remain ''still very, very much ongoing,'' with intrusions impacting 80+ countries across public and private sectors. [Source: https://cyberscoop.com/fbi-salt-typhoon-ongoing-threat-cybertalks-2026/]
  • Malpedia creates dedicated UAT-9244 threat actor entry, cataloging the actor profile and associated malware families. [Source: https://malpedia.caad.fkie.fraunhofer.de/actor/uat-9244]
  • Cisco Talos publicly discloses UAT-9244 threat cluster and three previously undocumented malware families (TernDoor, PeerTime, BruteEntry) targeting South American telecommunications providers since November 2024. Assessment links UAT-9244 with high confidence to FamousSparrow with overlaps to Earth Estries and Tropic Trooper. [Source: https://blog.talosintelligence.com/uat-9244/]
  • Wide industry amplification of UAT-9244 disclosure by The Hacker News, BleepingComputer, CyberSecurityNews, GovInfoSecurity, CyberInsider, and multiple threat intelligence aggregators, raising global awareness of the three-implant toolkit targeting telecom infrastructure. [Source: https://thehackernews.com/2026/03/china-linked-hackers-use-terndoor.html]
  • Full IOC package released including 60+ file hashes, 22+ infrastructure IPs, 3 C2 domains, SSL certificate fingerprints, ClamAV signatures, and Snort rule SID 65551.
  • Cisco Talos publishes comprehensive analysis of UAT-9244 campaign, disclosing three new malware families (TernDoor, PeerTime, BruteEntry) and ORB network infrastructure targeting South American telecom.
  • TechCrunch publishes comprehensive Salt Typhoon victim tracker documenting the global scope of Chinese state telecom hacking, describing it as ''one of the broadest hacking campaigns in recent years'' with tens of millions of stolen phone records. [Source: https://techcrunch.com/2026/03/09/salt-typhoon-china-who-has-been-hacked-global-telecom-giants/]
  • As of 2026-05-29, TL-2026-0191 (UAT-9244/FamousSparrow) remains ACTIVE: no CVE to patch, no takedown or disruption reported, and the China-nexus actor is operating with adaptive evolution of its TernDoor toolset. A May 2026 report confirms FamousSparrow deployed TernDoor against an Azerbaijani energy firm (Dec 2025-Feb 2026), corroborating an ongoing, espionage-driven campaign.

Sources cited for UAT-9244 (China-Nexus FamousSparrow Cluster)

Detection coverage for TL-2026-0191

As of 2026-03-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0191 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
40 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats