Threat reportSupply ChainTL-2026-1947
FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructure
FirewallFalcon Manager (TL-2026-1947), also tracked as DT Tunnel backdoor, is a critical-severity supply-chain compromise, first published 2026-08-07. It is attributed to FirewallFalcon with low confidence, affects FirewallFalcon (threat actor) FirewallFalcon Manager, maps to 11 MITRE ATT&CK techniques (T1078, T1082, T1090), and is covered by 9 detection rules and 20 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 1FirewallFalcon
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1947
- Threat ID
- TL-2026-1947
- Also known as
- DT Tunnel backdoor, FalconFire rogue CA
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- FirewallFalcon
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- telecoms, internet service providers, vpn and proxy resellers, consumer individual internet users
- Target regions
- Middle East and North Africa (MENA), 202 - Sub-Saharan Africa, South Asia, Europe, 005 - South America
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in FirewallFalcon Manager
Malware and tooling: FirewallFalcon install_mod/arminstall_mod loader family, SHC (Shell Script Compiler), Telegram Bot API
How FirewallFalcon Manager works
Flare Systems documented FirewallFalcon Manager, a Linux server management tool marketed as free/open-source to VPN and proxy resellers, that installs a hardcoded SSH backdoor with universal credentials, a rogue CA certificate, and a /etc/hosts hijack redirecting DTunnel proxy traffic to an attacker-controlled MitM server. DNS record analysis identified at least 650 distinct live servers tied to the threat actor's infrastructure, primarily across MENA and secondary Sub-Saharan Africa.
FirewallFalcon Manager is a Linux server-management toolkit distributed for free via GitHub (github.com/firewallfalcons/FirewallFalcon-Manager) and promoted through a dedicated Telegram community (t.me/firewallfalcons, ~800 members) to underground VPN/proxy resellers who run 'free internet' SSH-tunneling services across MENA and Sub-Saharan Africa. Installation is a single root-level command that downloads install.sh and a 2,876-line menu.sh offering legitimate-looking tunneling features built on real open-source projects (V2Ray/XRay, DNSTT/SlowDNS, BadVPN, X-UI, HAProxy, Nginx) plus automatic DNS/TLS provisioning via the deSEC.io API and Let's Encrypt.
Selecting the menu's 'DT Tunnel' option (choice [10]) triggers a hidden malicious binary, install_mod, that runs as root via sudo and performs three actions: (1) it drops a self-signed rogue CA certificate (falconfire.crt) into /usr/local/share/ca-certificates and runs update-ca-certificates to inject it into the system trust store; (2) it appends an entry to /etc/hosts forcing the legitimate Brazilian tunneling service hostname proxy.dtunnel.com.br to resolve to the attacker's server 89.168.51.93 instead of DTunnel's real Cloudflare-fronted addresses (104.21.81.128 / 172.67.160.230); and (3) it embeds a hardcoded proxy_token string ('firewallfalcon') used to authenticate to the rogue MitM endpoint. Flare researchers confirmed the redirect empirically: a curl request using the extracted token against the legitimate hostname returned the attacker's IP with a self-signed certificate that the host now trusts, giving the operator transparent, decrypted visibility into all DTunnel proxy traffic on every server that installed the DT Tunnel option. install_mod is a 2.3MB statically-linked Go ELF binary for x86_64, with an ARM64 counterpart (arminstall_mod).
Older deployments (August-December 2025) used a different, cruder chain: a self-extracting installer (64install_v3.sh) built with SHC-compiled obfuscation that unpacked an encrypted payload containing a hardcoded root-privileged SSH backdoor account plus a Telegram-bot reconnaissance/exfiltration channel that phoned home IPv4/IPv6 addresses, hostname, OS, CPU, RAM, and disk metrics for every new install. On 2025-12-22 the actor pivoted away from this SHC/Telegram-bot design toward the cleaner menu.sh + separately hosted install_mod chain, and by August 2026 GitHub commit history showed roughly ten upload/delete cycles of the installer script over four months as the actor iterated and covered tracks.
DNS-record analysis tied at least 650 live servers (314 individually profiled) to the actor's infrastructure, hosted across a mix of commodity VPS providers (Contabo, DigitalOcean, IONOS, Hetzner, OVH, Linode), hyperscalers (AWS, Oracle Cloud, Alibaba, Azure, GCP) and gray/boutique hosts, with automated provisioning patterns visible in subdomain naming (vps-*, ns-*, tun-*) under the actor-controlled dynamic-DNS domains manager.firewallfalcon.qzz.io (current) and firewallfalcon.thefirewoods.org (legacy), both backed by a hardcoded, abused deSEC.io API token. Geographically the affected server population concentrates in Egypt, Morocco, Saudi Arabia, and Algeria, with secondary clusters in Iraq, Tunisia, Turkey, and Sub-Saharan Africa (Ghana, Tanzania, Kenya, Senegal, Ivory Coast), plus smaller South Asian, European, and South American footprints. The underlying business model exploits mobile-carrier zero-rating programs (Meta/Facebook FreeBasics and carrier 'social' data packages from Telecom Egypt, Mobily, Zain, and Ooredoo): resellers use SNI manipulation to disguise general internet traffic as zero-rated traffic, and FirewallFalcon Manager (and a related shared-access endpoint, zfalcon.quantumz.co.uk, using default credentials falcon/falcon and distributed via the HTTP Custom Android app) supplies the tunneling infrastructure for this fraud.
Flare discovered the campaign after one of its own VPS honeypots was compromised and repurposed to run the toolkit; the disproportionate engineering effort behind a 'free' tool for an anonymous underground audience prompted deeper analysis (GitHub commit/binary forensics, Ghidra disassembly, Telegram linguistic/activity analysis, DNS reconnaissance, and TLS certificate comparison) that surfaced the layered backdoors. Linguistic and operational analysis of the actor's Telegram activity (admin handle 'FirewallFalcon,' 135 of 949 group messages between Nov 2025-Mar 2026) points to Egyptian origin with Saudi/Gulf influence, though this is an inferred stylistic assessment, not a confirmed identity; a PayPal donation address associated with the project contains the name 'Mahmoud.' The actor demonstrates multi-language development skill (Go, Rust/tokio, C++/Asio) and deep Linux administration knowledge (PAM, systemd, iptables, SSH hardening internals), used here to *weaken* rather than harden target systems. Net effect: every server on which the DT Tunnel option is enabled hands the operator root-equivalent persistent access, a trusted MitM position over that server's proxied traffic, and by extension exposure for the (potentially hundreds of thousands of) end-user devices that route through these gray-market VPN/proxy services.
MITRE ATT&CK techniques used in TL-2026-1947
Persistence
T1078 Valid Accounts; T1136 Create Account; T1556 Modify Authentication Process
Discovery
T1082 System Information Discovery
Command and Control
Initial Access
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
Credential Access
Resource Development
Affected products and versions in FirewallFalcon Manager
- FirewallFalcon (threat actor) — FirewallFalcon Manager
Vulnerable versions: All builds distributed from github.com/firewallfalcons/FirewallFalcon-Manager, August 2025 - present, including the legacy 64install_v3.sh/arminstall.sh installers and the current menu.sh + install_mod/arminstall_mod (x86_64/ARM) chain
Fixed in: None — malicious tool, no legitimate vendor or fixed version exists
Remediation for FirewallFalcon Manager
Patches
- No vendor patch applies — FirewallFalcon Manager is a threat-actor-authored tool, not a legitimate vulnerable product; remediation is removal, not patching
Immediate actions
- Block/deny inbound and outbound traffic to 89.168.51.93 at the network perimeter
- Audit /etc/hosts on all Linux servers for unauthorized entries redirecting known service domains such as proxy.dtunnel.com.br
- Remove any unrecognized CA certificate (e.g. falconfire.crt, SHA256 a2ebb7983e53a129f5d0f278b8acb08db591b70dfcdb74ed0e656d429386de29) from the system trust store and re-run update-ca-certificates
- Rotate all SSH credentials and disable password-based root authentication on any server that ran FirewallFalcon Manager or its DT Tunnel option
Workarounds
- Do not install FirewallFalcon Manager, its DT Tunnel option, or similar 'free' VPN-reseller management toolkits distributed via GitHub/Telegram
- If already installed, treat the host as fully compromised at root level: rebuild from a known-good image rather than attempting in-place remediation
Longer-term hardening
- Prohibit root-level installation of unsigned, unverified third-party server-management tools sourced from GitHub or Telegram
- Enforce code-signing/provenance verification for administrative tooling deployed to production Linux infrastructure
- Deploy file-integrity monitoring on /etc/hosts, the CA trust store directory, and sshd_config
- Monitor DNS resolution results for divergence from expected authoritative answers to detect hosts-file/DNS hijacking
Weaknesses (CWE) in FirewallFalcon Manager
Timeline of FirewallFalcon Manager
- Initial GitHub commit (9ebe030) establishes the self-extracting installer dispatcher for FirewallFalcon Manager's legacy 64install.sh/arminstall.sh distribution chain.
- Start of the observed high-activity window on the t.me/firewallfalcons Telegram channel used for tool distribution and support (through March 2026, ~949 messages, ~800 members).
- FirewallFalcon actor abandons the SHC-obfuscated self-extracting installer approach and pivots to a menu.sh-driven download chain with the malicious payload isolated in a separately hosted install_mod binary.
- End of the Nov 2025-Mar 2026 Telegram message-volume window used by Flare researchers for linguistic and operational-tempo profiling of the actor.
- Flare Systems publishes 'FirewallFalcon Manager: Supply-Chain Backdoors in Underground VPN Infrastructure,' disclosing the rogue CA, /etc/hosts hijack, and a DNS-derived footprint of at least 650 live attacker-linked servers (314 individually profiled).
- Flare researchers empirically confirm the MitM redirect by extracting the hardcoded 'firewallfalcon' proxy token and issuing a curl request that returns 89.168.51.93 with a self-signed certificate instead of DTunnel's legitimate Cloudflare-fronted service.
Sources cited for FirewallFalcon Manager
- FirewallFalcon Manager: Supply-Chain Backdoors in Underground VPN Infrastructure
- github.com/firewallfalcons/FirewallFalcon-Manager — malicious repository cited by Flare (returns 404 / taken down as of this research)
- t.me/firewallfalcons — FirewallFalcon's Telegram distribution/support channel (~800 members, ~949 messages Nov 2025-Mar 2026)
- DTunnel — legitimate Brazilian proxy/tunneling service impersonated by the /etc/hosts MitM redirect
- deSEC.io — free dynamic-DNS API service abused via a hardcoded token to auto-provision attacker subdomains
Detection coverage for TL-2026-1947
As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1947 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.