# UAT-9244 (China-Nexus FamousSparrow Cluster) — TernDoor Backdoor, PeerTime BitTorrent C2 Linux Implant, and BruteEntry ORB Scanner Targeting South American Telecom

> Cisco Talos-attributed China-nexus threat cluster UAT-9244 (overlapping with FamousSparrow/Salt Typhoon) is actively targeting critical telecommunications infrastructure across South America with three previously undocumented malware families: TernDoor (Windows DLL-sideloading backdoor derived from CrowDoor/SparrowDoor), PeerTime/angrypeer (multi-architecture Linux implant using BitTorrent protocol for C2), and BruteEntry (Golang-based brute-force scanner converting edge devices into Operational Relay Box proxy nodes).

- **Published:** 2026-03-07T12:00:00Z
- **Last reviewed:** 2026-03-07T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0191
- **ID:** TL-2026-0191
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** UAT-9244 (China)
- **Detections:** 9 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UAT-9244 is a China-nexus advanced persistent threat actor assessed by Cisco Talos with high confidence to be closely associated with FamousSparrow, with tactical overlaps to Earth Estries and Tropic Trooper based on shared tooling, TTPs, and victimology. The group has been actively targeting critical telecommunications providers in South America since at least 2024, deploying three distinct malware families across Windows endpoints, Linux systems, and network edge devices.

**TernDoor (Windows Backdoor):** TernDoor is a new variant of CrowDoor, itself a variant of the SparrowDoor malware family associated with FamousSparrow operations. It is deployed via DLL side-loading using the legitimate executable wsprint.exe to load a rogue DLL named BugSplatRc64.dll. The loader reads an encoded payload (WSPrint.dll) from disk, decrypts it using the hardcoded key 'qwiozpVngruhg123', and executes position-independent shellcode that decompresses the final TernDoor payload in memory. TernDoor establishes persistence through a scheduled task named WSPrint running as SYSTEM on startup, and via Registry Run key entries at HKCU\Software\Microsoft\Windows\CurrentVersion\Run. The malware hides its scheduled task by deleting the SD (Security Descriptor) value and setting Index to 0 in the TaskCache registry. TernDoor's shellcode embeds an AES-encrypted Windows driver (WSPrint.sys) that creates device \\Device\\VMTool with symlink \\DosDevices\\VMTool, providing kernel-level capabilities to suspend, resume, and terminate processes. Core capabilities include C2 communications over HTTPS (port 443), process creation and arbitrary command execution, file read/write operations, system information collection (computer name, username, IP, OS bitness), self-uninstallation via the -u switch, and process injection into msiexec.exe. All discovered C2 servers share a common self-signed SSL certificate (CN=8.8.8.8) issued September 4, 2022.

**PeerTime / angrypeer (Linux Multi-Architecture Backdoor):** PeerTime is an ELF-based backdoor targeting ARM, AARCH64, PPC, and MIPS architectures, indicating it was designed to compromise embedded systems and network devices common in telecom environments. Deployment occurs via shell scripts that download the PeerTime loader ELF binary along with an instrumentor binary. The instrumentor checks for Docker presence (via 'docker' and 'docker -q' commands) and contains debug strings in Simplified Chinese, a key attribution indicator. The loader decrypts and decompresses the ELF payload, executing it in memory. PeerTime employs the BitTorrent protocol for C2 communications — a novel evasion technique that blends malicious traffic with legitimate peer-to-peer file sharing. It downloads and executes payloads from peers, uses BusyBox to write files to specified disk locations, and renames itself as harmless processes to evade detection. Two variants exist: the original C/C++ version and a newer Rust-based variant, tracked on VirusTotal as 'angrypeer'.

**BruteEntry (Golang ORB Scanner):** BruteEntry is a Golang-based brute-force scanner deployed via shell scripts on network edge devices. It converts compromised devices into mass-scanning proxy nodes within an Operational Relay Box (ORB) network. Upon deployment, the agent registers with its C2 via HTTP POST containing the device IP and hostname, receiving an agent_id and version string. It then fetches scanning tasks (GET /tasks/<agent_id>?limit=1000) containing target IP lists. BruteEntry targets PostgreSQL (port 5432), SSH (port 22), and Apache Tomcat management interfaces (HTTPS /manager/html). Successful credential compromises are reported back to C2 with notes identifying the cracking agent and version. This ORB infrastructure provides UAT-9244 with distributed, anonymized scanning capabilities across victim networks.

**Attribution:** Talos assesses with high confidence that UAT-9244 is a China-nexus APT closely associated with FamousSparrow, with overlaps to Earth Estries and Tropic Trooper. Key attribution indicators include Simplified Chinese debug strings in the PeerTime instrumentor binary, the CrowDoor/SparrowDoor malware lineage, and shared TTPs and victimology. While FamousSparrow shares tactical overlaps with Salt Typhoon (Microsoft designation), Talos was unable to verify a direct connection between UAT-9244 and Salt Typhoon despite both targeting telecommunications providers.

---

**Revalidated on 2026-03-12**

One week after the initial Cisco Talos disclosure on March 5, 2026, UAT-9244 has been extensively corroborated across the threat intelligence community with no conflicting assessments. The three-malware toolkit (TernDoor, PeerTime, BruteEntry) targeting South American telecom providers represents a confirmed and active campaign. Key revalidation findings include:

**Attribution Strengthened:** The FamousSparrow cluster connection is now supported by two independent research tracks. ESET's March 2025 report confirmed FamousSparrow was never dormant during 2022-2024, deploying upgraded SparrowDoor variants and ShadowPad against US financial, Mexican research, and Honduran government targets. TernDoor's CrowDoor/SparrowDoor lineage directly links UAT-9244 to this same tool evolution chain. ESET maintains FamousSparrow is distinct from but operationally adjacent to Earth Estries and GhostEmperor, with overlaps possibly stemming from a shared 'digital quartermaster' rather than unified command.

**Broader Campaign Context:** The CISA/FBI/NSA joint advisory AA25-239A (August 2025) documented Chinese state-sponsored actors including Salt Typhoon compromising telecom, government, and military networks in 80+ countries since 2021, exploiting known vulnerabilities in backbone routers. FBI's February 2026 confirmation that Salt Typhoon threats remain 'very much ongoing' places UAT-9244's South American telecom targeting within a larger, sustained Chinese state espionage campaign against global telecommunications infrastructure. The advisory attributed this activity to MSS and PLA-linked entities.

**ORB Network Pattern:** BruteEntry's conversion of edge devices into Operational Relay Boxes aligns with Mandiant's documented ORB network research showing China-nexus actors increasingly using compromised IoT devices, SOHO routers, and VPS infrastructure as proxy mesh networks to evade detection and complicate attribution. This represents an evolution beyond traditional C2 infrastructure.

**Detection Coverage:** ClamAV signatures (Win.Loader.PeerTime, Win.Malware.TernDoor, Unix.Malware.BruteEntry, Txt.Malware.PeerTime, Unix.Malware.PeerTime) and Snort SID 65551 are available from Cisco Talos. Broadcom/Symantec has published a protection bulletin. Comprehensive IOCs including 50+ SHA256 file hashes, 22+ C2 IP addresses, 3 C2 domains (bloopencil.net, xcit76.com, xtibh.com), and a shared SSL certificate fingerprint are publicly available for defensive deployment.

**No Remediation Observed:** As of March 12, 2026, no takedowns, infrastructure disruptions, or law enforcement actions have been reported against UAT-9244's C2 infrastructure. The campaign should be considered actively ongoing.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.004 Unix Shell
- T1059.003 Windows Command Shell
- T1053.005 Scheduled Task
- T1547.001 Registry Run Keys / Startup Folder
- T1505.003 Web Shell
- T1574.001 DLL
- T1140 Deobfuscate/Decode Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1014 Rootkit
- T1564 Hide Artifacts
- T1055 Process Injection
- T1070.004 File Deletion
- T1110.001 Password Guessing
- T1082 System Information Discovery
- T1057 Process Discovery
- T1021.004 SSH
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1095 Non-Application Layer Protocol
- T1573.001 Symmetric Cryptography
- T1041 Exfiltration Over C2 Channel
- T1583.003 Virtual Private Server
- T1587.001 Malware

## Sources

- [Cisco Talos: UAT-9244 targets South American telecommunication providers with three new malware implants](https://blog.talosintelligence.com/uat-9244/)
- [The Hacker News: China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks](https://thehackernews.com/2026/03/china-linked-hackers-use-terndoor.html)
- [BleepingComputer: Chinese state hackers target telcos with new malware toolkit](https://www.bleepingcomputer.com/news/security/chinese-state-hackers-target-telcos-with-new-malware-toolkit/)
- [CyberInsider: Chinese hackers target telcos in South America with new malware](https://cyberinsider.com/chinese-hackers-target-telcos-in-south-america-with-new-malware/)
- [CybersecurityNews: China-Nexus Hackers Attacking Telecommunication Providers With New Malware](https://cybersecuritynews.com/china-nexus-hackers-attacking-telecommunication/)
- [GovInfoSecurity: China-Linked Hackers Use Malware Trio for Telecom Espionage](https://www.govinfosecurity.com/china-linked-hackers-use-malware-trio-for-telecom-espionage-a-30940)
- [Threat Intelligence Report: UAT-9244 hits South American telcos with TernDoor, PeerTime and BruteEntry](https://www.threatintelreport.com/2026/03/06/articles/uat-9244-hits-south-american-telcos-with-terndoor-peertime-and-bruteentry/)
- [ESET: FamousSparrow cyberespionage attacks in the United States](https://www.eset.com/us/about/newsroom/research/cyberespionage-attacks-by-the-china-aligned-famoussparrow-group-in-the-united-states-eset-research-discovers/)
- [WeLiveSecurity: You will always remember this as the day you finally caught FamousSparrow](https://www.welivesecurity.com/en/eset-research/you-will-always-remember-this-as-the-day-you-finally-caught-famoussparrow/)
- [Cisco Talos IOCs GitHub Repository](https://github.com/Cisco-Talos/IOCs)
- [Picus Security: Salt Typhoon — A Persistent Threat to Global Telecommunications Infrastructure](https://www.picussecurity.com/resource/blog/salt-typhoon-telecommunications-threat)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0191
