UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom — Threadlinqs Intelligence
As of 2026-05-30, UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom is a high-severity apt threat attributed to UAT-9244 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0191 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: UAT-9244 · China · ESPIONAGE
Cisco Talos-attributed China-nexus threat cluster UAT-9244 (overlapping with FamousSparrow/Salt Typhoon) is actively targeting critical telecommunications infrastructure across South America with
UAT-9244 is a China-nexus advanced persistent threat actor assessed by Cisco Talos with high confidence to be closely associated with FamousSparrow, with tactical overlaps to Earth Estries and Tropic Trooper based on shared tooling, TTPs, and victimology. The group has been actively targeting critical telecommunications providers in South America since at least 2024, deploying three distinct malware families across Windows endpoints, Linux systems, and network edge devices.
**TernDoor (Windows Backdoor):** TernDoor is a new variant of CrowDoor, itself a variant of the SparrowDoor malware family associated with FamousSparrow operations. It is deployed via DLL side-loading using the legitimate executable wsprint.exe to load a rogue DLL named BugSplatRc64.dll. The loader reads an encoded payload (WSPrint.dll) from disk, decrypts it using the hardcoded key 'qwiozpVngruhg123', and executes position-independent shellcode that decompresses the final TernDoor payload in memory. TernDoor establishes persistence through a scheduled task named WSPrint running as SYSTEM on startup, and via Registry Run key entries at HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The malware hides its scheduled task by deleting the SD (Security Descriptor) value and setting Index to 0 in the TaskCache registry. TernDoor's shellcode embeds an AES-encrypted Windows driver (WSPrint.sys) that creates device \\Device\\VMTool with symlink \\DosDevices\\VMTool, providing kernel-level capabilities to suspend, resume, and terminate processes. Core capabilities include C2 communications over HTTPS (port 443), process creation and arbitrary command execution, file read/write operations, system information collection (computer name, username, IP, OS bitness), self-uninstallation via the -u switch, and process injection into msiexec.exe. All discovered C2 servers share a common self-signed SSL certificate (CN=8.8.8.8) issued September 4, 2022.
**PeerTime / angrypeer (Linux Multi-Architecture Backdoor):** PeerTime is an ELF-based backdoor targeting ARM, AARCH64, PPC, and MIPS architectures, indicating it was designed to compromise embedded systems and network devices common in telecom environments. Deployment occurs via shell scripts that download the PeerTime loader ELF binary along with an instrumentor binary. The instrumentor checks for Docker presence (via 'docker' and 'docker -q' commands) and contains debug strings in Simplified Chinese, a key attribution indicator. The loader decrypts and decompresses the ELF payload, executing it in memory. PeerTime employs the BitTorrent protocol for C2 communications — a novel evasion technique that blends malicious traffic with legitimate peer-to-peer file sharing. It downloads and executes payloads from peers, uses BusyBox to write files to specified disk locations, and renames itself as harmless processes to evade detection. Two variants exist: the original C/C++ version and a newer Rust-based variant, tracked on VirusTotal as 'angrypeer'.
**BruteEntry (Golang ORB Scanner):** BruteEntry is a Golang-based brute-force scanner deployed via shell scripts on network edge devices. It converts compromised devices into mass-scanning proxy nodes within an Operational Relay Box (ORB) network. Upon deployment, the agent registers with its C2 via HTTP POST containing the device IP and hostname, receiving an agent_id and version string. It then fetches scanning tasks (GET /tasks/<agent_id>?limit=1000) containing target IP lists. BruteEntry targets PostgreSQL (port 5432), SSH (port 22), and Apache Tomcat management interfaces (HTTPS /manager/html). Successful credential compromises are reported back to C2 with notes identifying the cracking agent and version. This ORB infrastructure provides UAT-9244 with distributed, anonymized scanning capabilities across victim networks.
**Attribution:** Talos assesses with high confidence that UAT-9244 is a China-nexus APT closely associated with FamousSparrow, with overlaps to Earth Estrie
Weaknesses (CWE)
CWE-426, CWE-798, CWE-307
Target sectors: telecommunications, critical-infrastructure
Target regions: South America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1190, T1059.004, T1059.003, T1053.005, T1547.001, T1505.003, T1053.005, T1574.002, T1140, T1036.005