Threat reportSupply ChainTL-2026-1947

FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructure

criticalACTIVE

FirewallFalcon Manager (TL-2026-1947), also tracked as DT Tunnel backdoor, is a critical-severity supply-chain compromise, first published 2026-08-07. It is attributed to FirewallFalcon with low confidence, affects FirewallFalcon (threat actor) FirewallFalcon Manager, maps to 11 MITRE ATT&CK techniques (T1078, T1082, T1090), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
11MITRE ATT&CK
Actors
1FirewallFalcon
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-1947

Threat ID
TL-2026-1947
Also known as
DT Tunnel backdoor, FalconFire rogue CA
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
FirewallFalcon
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
telecoms, internet service providers, vpn and proxy resellers, consumer individual internet users
Target regions
Middle East and North Africa (MENA), 202 - Sub-Saharan Africa, South Asia, Europe, 005 - South America
Detection rules
9
Indicators of compromise
20

Malware and tooling in FirewallFalcon Manager

Malware and tooling: FirewallFalcon install_mod/arminstall_mod loader family, SHC (Shell Script Compiler), Telegram Bot API

How FirewallFalcon Manager works

Flare Systems documented FirewallFalcon Manager, a Linux server management tool marketed as free/open-source to VPN and proxy resellers, that installs a hardcoded SSH backdoor with universal credentials, a rogue CA certificate, and a /etc/hosts hijack redirecting DTunnel proxy traffic to an attacker-controlled MitM server. DNS record analysis identified at least 650 distinct live servers tied to the threat actor's infrastructure, primarily across MENA and secondary Sub-Saharan Africa.

FirewallFalcon Manager is a Linux server-management toolkit distributed for free via GitHub (github.com/firewallfalcons/FirewallFalcon-Manager) and promoted through a dedicated Telegram community (t.me/firewallfalcons, ~800 members) to underground VPN/proxy resellers who run 'free internet' SSH-tunneling services across MENA and Sub-Saharan Africa. Installation is a single root-level command that downloads install.sh and a 2,876-line menu.sh offering legitimate-looking tunneling features built on real open-source projects (V2Ray/XRay, DNSTT/SlowDNS, BadVPN, X-UI, HAProxy, Nginx) plus automatic DNS/TLS provisioning via the deSEC.io API and Let's Encrypt.

Selecting the menu's 'DT Tunnel' option (choice [10]) triggers a hidden malicious binary, install_mod, that runs as root via sudo and performs three actions: (1) it drops a self-signed rogue CA certificate (falconfire.crt) into /usr/local/share/ca-certificates and runs update-ca-certificates to inject it into the system trust store; (2) it appends an entry to /etc/hosts forcing the legitimate Brazilian tunneling service hostname proxy.dtunnel.com.br to resolve to the attacker's server 89.168.51.93 instead of DTunnel's real Cloudflare-fronted addresses (104.21.81.128 / 172.67.160.230); and (3) it embeds a hardcoded proxy_token string ('firewallfalcon') used to authenticate to the rogue MitM endpoint. Flare researchers confirmed the redirect empirically: a curl request using the extracted token against the legitimate hostname returned the attacker's IP with a self-signed certificate that the host now trusts, giving the operator transparent, decrypted visibility into all DTunnel proxy traffic on every server that installed the DT Tunnel option. install_mod is a 2.3MB statically-linked Go ELF binary for x86_64, with an ARM64 counterpart (arminstall_mod).

Older deployments (August-December 2025) used a different, cruder chain: a self-extracting installer (64install_v3.sh) built with SHC-compiled obfuscation that unpacked an encrypted payload containing a hardcoded root-privileged SSH backdoor account plus a Telegram-bot reconnaissance/exfiltration channel that phoned home IPv4/IPv6 addresses, hostname, OS, CPU, RAM, and disk metrics for every new install. On 2025-12-22 the actor pivoted away from this SHC/Telegram-bot design toward the cleaner menu.sh + separately hosted install_mod chain, and by August 2026 GitHub commit history showed roughly ten upload/delete cycles of the installer script over four months as the actor iterated and covered tracks.

DNS-record analysis tied at least 650 live servers (314 individually profiled) to the actor's infrastructure, hosted across a mix of commodity VPS providers (Contabo, DigitalOcean, IONOS, Hetzner, OVH, Linode), hyperscalers (AWS, Oracle Cloud, Alibaba, Azure, GCP) and gray/boutique hosts, with automated provisioning patterns visible in subdomain naming (vps-*, ns-*, tun-*) under the actor-controlled dynamic-DNS domains manager.firewallfalcon.qzz.io (current) and firewallfalcon.thefirewoods.org (legacy), both backed by a hardcoded, abused deSEC.io API token. Geographically the affected server population concentrates in Egypt, Morocco, Saudi Arabia, and Algeria, with secondary clusters in Iraq, Tunisia, Turkey, and Sub-Saharan Africa (Ghana, Tanzania, Kenya, Senegal, Ivory Coast), plus smaller South Asian, European, and South American footprints. The underlying business model exploits mobile-carrier zero-rating programs (Meta/Facebook FreeBasics and carrier 'social' data packages from Telecom Egypt, Mobily, Zain, and Ooredoo): resellers use SNI manipulation to disguise general internet traffic as zero-rated traffic, and FirewallFalcon Manager (and a related shared-access endpoint, zfalcon.quantumz.co.uk, using default credentials falcon/falcon and distributed via the HTTP Custom Android app) supplies the tunneling infrastructure for this fraud.

Flare discovered the campaign after one of its own VPS honeypots was compromised and repurposed to run the toolkit; the disproportionate engineering effort behind a 'free' tool for an anonymous underground audience prompted deeper analysis (GitHub commit/binary forensics, Ghidra disassembly, Telegram linguistic/activity analysis, DNS reconnaissance, and TLS certificate comparison) that surfaced the layered backdoors. Linguistic and operational analysis of the actor's Telegram activity (admin handle 'FirewallFalcon,' 135 of 949 group messages between Nov 2025-Mar 2026) points to Egyptian origin with Saudi/Gulf influence, though this is an inferred stylistic assessment, not a confirmed identity; a PayPal donation address associated with the project contains the name 'Mahmoud.' The actor demonstrates multi-language development skill (Go, Rust/tokio, C++/Asio) and deep Linux administration knowledge (PAM, systemd, iptables, SSH hardening internals), used here to *weaken* rather than harden target systems. Net effect: every server on which the DT Tunnel option is enabled hands the operator root-equivalent persistent access, a trusted MitM position over that server's proxied traffic, and by extension exposure for the (potentially hundreds of thousands of) end-user devices that route through these gray-market VPN/proxy services.

MITRE ATT&CK techniques used in TL-2026-1947

Persistence

T1078 Valid Accounts; T1136 Create Account; T1556 Modify Authentication Process

Discovery

T1082 System Information Discovery

Command and Control

T1090 Proxy

Initial Access

T1195 Supply Chain Compromise

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Credential Access

T1557 Adversary-in-the-Middle

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Affected products and versions in FirewallFalcon Manager

  • FirewallFalcon (threat actor) — FirewallFalcon Manager
    Vulnerable versions: All builds distributed from github.com/firewallfalcons/FirewallFalcon-Manager, August 2025 - present, including the legacy 64install_v3.sh/arminstall.sh installers and the current menu.sh + install_mod/arminstall_mod (x86_64/ARM) chain
    Fixed in: None — malicious tool, no legitimate vendor or fixed version exists

Remediation for FirewallFalcon Manager

Patches

  • No vendor patch applies — FirewallFalcon Manager is a threat-actor-authored tool, not a legitimate vulnerable product; remediation is removal, not patching

Immediate actions

  • Block/deny inbound and outbound traffic to 89.168.51.93 at the network perimeter
  • Audit /etc/hosts on all Linux servers for unauthorized entries redirecting known service domains such as proxy.dtunnel.com.br
  • Remove any unrecognized CA certificate (e.g. falconfire.crt, SHA256 a2ebb7983e53a129f5d0f278b8acb08db591b70dfcdb74ed0e656d429386de29) from the system trust store and re-run update-ca-certificates
  • Rotate all SSH credentials and disable password-based root authentication on any server that ran FirewallFalcon Manager or its DT Tunnel option

Workarounds

  • Do not install FirewallFalcon Manager, its DT Tunnel option, or similar 'free' VPN-reseller management toolkits distributed via GitHub/Telegram
  • If already installed, treat the host as fully compromised at root level: rebuild from a known-good image rather than attempting in-place remediation

Longer-term hardening

  • Prohibit root-level installation of unsigned, unverified third-party server-management tools sourced from GitHub or Telegram
  • Enforce code-signing/provenance verification for administrative tooling deployed to production Linux infrastructure
  • Deploy file-integrity monitoring on /etc/hosts, the CA trust store directory, and sshd_config
  • Monitor DNS resolution results for divergence from expected authoritative answers to detect hosts-file/DNS hijacking

Weaknesses (CWE) in FirewallFalcon Manager

CWE-798, CWE-295, CWE-506, CWE-494

Timeline of FirewallFalcon Manager

  • Initial GitHub commit (9ebe030) establishes the self-extracting installer dispatcher for FirewallFalcon Manager's legacy 64install.sh/arminstall.sh distribution chain.
  • Start of the observed high-activity window on the t.me/firewallfalcons Telegram channel used for tool distribution and support (through March 2026, ~949 messages, ~800 members).
  • FirewallFalcon actor abandons the SHC-obfuscated self-extracting installer approach and pivots to a menu.sh-driven download chain with the malicious payload isolated in a separately hosted install_mod binary.
  • End of the Nov 2025-Mar 2026 Telegram message-volume window used by Flare researchers for linguistic and operational-tempo profiling of the actor.
  • Flare Systems publishes 'FirewallFalcon Manager: Supply-Chain Backdoors in Underground VPN Infrastructure,' disclosing the rogue CA, /etc/hosts hijack, and a DNS-derived footprint of at least 650 live attacker-linked servers (314 individually profiled).
  • Flare researchers empirically confirm the MitM redirect by extracting the hardcoded 'firewallfalcon' proxy token and issuing a curl request that returns 89.168.51.93 with a self-signed certificate instead of DTunnel's legitimate Cloudflare-fronted service.

Sources cited for FirewallFalcon Manager

Detection coverage for TL-2026-1947

As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1947 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats