# FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server Infrastructure

> Flare Systems documented FirewallFalcon Manager, a Linux server management tool marketed as free/open-source to VPN and proxy resellers, that installs a hardcoded SSH backdoor with universal credentials, a rogue CA certificate, and a /etc/hosts hijack redirecting DTunnel proxy traffic to an attacker-controlled MitM server. DNS record analysis identified at least 650 distinct live servers tied to the threat actor's infrastructure, primarily across MENA and secondary Sub-Saharan Africa.

- **Published:** 2026-08-07T00:00:00Z
- **Last reviewed:** 2026-08-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1947
- **ID:** TL-2026-1947
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** FirewallFalcon
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

FirewallFalcon Manager is a Linux server-management toolkit distributed for free via GitHub (github.com/firewallfalcons/FirewallFalcon-Manager) and promoted through a dedicated Telegram community (t.me/firewallfalcons, ~800 members) to underground VPN/proxy resellers who run 'free internet' SSH-tunneling services across MENA and Sub-Saharan Africa. Installation is a single root-level command that downloads install.sh and a 2,876-line menu.sh offering legitimate-looking tunneling features built on real open-source projects (V2Ray/XRay, DNSTT/SlowDNS, BadVPN, X-UI, HAProxy, Nginx) plus automatic DNS/TLS provisioning via the deSEC.io API and Let's Encrypt.

Selecting the menu's 'DT Tunnel' option (choice [10]) triggers a hidden malicious binary, install_mod, that runs as root via sudo and performs three actions: (1) it drops a self-signed rogue CA certificate (falconfire.crt) into /usr/local/share/ca-certificates and runs update-ca-certificates to inject it into the system trust store; (2) it appends an entry to /etc/hosts forcing the legitimate Brazilian tunneling service hostname proxy.dtunnel.com.br to resolve to the attacker's server 89.168.51.93 instead of DTunnel's real Cloudflare-fronted addresses (104.21.81.128 / 172.67.160.230); and (3) it embeds a hardcoded proxy_token string ('firewallfalcon') used to authenticate to the rogue MitM endpoint. Flare researchers confirmed the redirect empirically: a curl request using the extracted token against the legitimate hostname returned the attacker's IP with a self-signed certificate that the host now trusts, giving the operator transparent, decrypted visibility into all DTunnel proxy traffic on every server that installed the DT Tunnel option. install_mod is a 2.3MB statically-linked Go ELF binary for x86_64, with an ARM64 counterpart (arminstall_mod).

Older deployments (August-December 2025) used a different, cruder chain: a self-extracting installer (64install_v3.sh) built with SHC-compiled obfuscation that unpacked an encrypted payload containing a hardcoded root-privileged SSH backdoor account plus a Telegram-bot reconnaissance/exfiltration channel that phoned home IPv4/IPv6 addresses, hostname, OS, CPU, RAM, and disk metrics for every new install. On 2025-12-22 the actor pivoted away from this SHC/Telegram-bot design toward the cleaner menu.sh + separately hosted install_mod chain, and by August 2026 GitHub commit history showed roughly ten upload/delete cycles of the installer script over four months as the actor iterated and covered tracks.

DNS-record analysis tied at least 650 live servers (314 individually profiled) to the actor's infrastructure, hosted across a mix of commodity VPS providers (Contabo, DigitalOcean, IONOS, Hetzner, OVH, Linode), hyperscalers (AWS, Oracle Cloud, Alibaba, Azure, GCP) and gray/boutique hosts, with automated provisioning patterns visible in subdomain naming (vps-*, ns-*, tun-*) under the actor-controlled dynamic-DNS domains manager.firewallfalcon.qzz.io (current) and firewallfalcon.thefirewoods.org (legacy), both backed by a hardcoded, abused deSEC.io API token. Geographically the affected server population concentrates in Egypt, Morocco, Saudi Arabia, and Algeria, with secondary clusters in Iraq, Tunisia, Turkey, and Sub-Saharan Africa (Ghana, Tanzania, Kenya, Senegal, Ivory Coast), plus smaller South Asian, European, and South American footprints. The underlying business model exploits mobile-carrier zero-rating programs (Meta/Facebook FreeBasics and carrier 'social' data packages from Telecom Egypt, Mobily, Zain, and Ooredoo): resellers use SNI manipulation to disguise general internet traffic as zero-rated traffic, and FirewallFalcon Manager (and a related shared-access endpoint, zfalcon.quantumz.co.uk, using default credentials falcon/falcon and distributed via the HTTP Custom Android app) supplies the tunneling infrastructure for this fraud.

Flare discovered the campaign after one of its own VPS honeypots was compromised and repurposed to run the toolkit; the disproportionate engineering effort behind a 'free' tool for an anonymous underground audience prompted deeper analysis (GitHub commit/binary forensics, Ghidra disassembly, Telegram linguistic/activity analysis, DNS reconnaissance, and TLS certificate comparison) that surfaced the layered backdoors. Linguistic and operational analysis of the actor's Telegram activity (admin handle 'FirewallFalcon,' 135 of 949 group messages between Nov 2025-Mar 2026) points to Egyptian origin with Saudi/Gulf influence, though this is an inferred stylistic assessment, not a confirmed identity; a PayPal donation address associated with the project contains the name 'Mahmoud.' The actor demonstrates multi-language development skill (Go, Rust/tokio, C++/Asio) and deep Linux administration knowledge (PAM, systemd, iptables, SSH hardening internals), used here to *weaken* rather than harden target systems. Net effect: every server on which the DT Tunnel option is enabled hands the operator root-equivalent persistent access, a trusted MitM position over that server's proxied traffic, and by extension exposure for the (potentially hundreds of thousands of) end-user devices that route through these gray-market VPN/proxy services.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1608 Stage Capabilities
- T1583 Acquire Infrastructure
- T1136 Create Account
- T1078 Valid Accounts
- T1556 Modify Authentication Process
- T1553 Subvert Trust Controls
- T1685 Disable or Modify Tools
- T1090 Proxy
- T1557 Adversary-in-the-Middle
- T1082 System Information Discovery

## Sources

- [FirewallFalcon Manager: Supply-Chain Backdoors in Underground VPN Infrastructure](https://flare.io/learn/resources/blog/firewallfalcon-manager-supply-chain-backdoor)
- [github.com/firewallfalcons/FirewallFalcon-Manager — malicious repository cited by Flare (returns 404 / taken down as of this research)](https://github.com/firewallfalcons/FirewallFalcon-Manager)
- [t.me/firewallfalcons — FirewallFalcon's Telegram distribution/support channel (~800 members, ~949 messages Nov 2025-Mar 2026)](https://t.me/firewallfalcons)
- [DTunnel — legitimate Brazilian proxy/tunneling service impersonated by the /etc/hosts MitM redirect](https://dtunnel.com.br/)
- [deSEC.io — free dynamic-DNS API service abused via a hardcoded token to auto-provision attacker subdomains](https://desec.io/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1947
