Threat reportSupply ChainTL-2026-2987
LATAM supply chain attack: Sliver C2 reverse shells from DMZ web application to Active Directory, contained by Akamai ExAR
LATAM supply chain attack (TL-2026-2987) is a high-severity supply-chain compromise, first published 2026-10-06. It has no confirmed attribution, affects Unknown Web-facing DMZ application (unidentified), maps to 6 MITRE ATT&CK techniques (T1021.004, T1059.004, T1087.002), and is covered by 9 detection rules and 5 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 5Indicators of compromise
Key facts for TL-2026-2987
- Threat ID
- TL-2026-2987
- Severity
- HIGH
- Status
- RESOLVED
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- supply chain logistics
- Target regions
- Latin America
- Detection rules
- 9
- Indicators of compromise
- 5
Malware and tooling in LATAM supply chain attack
Malware and tooling: Sliver, Sliver - S0633, ftp - S0095, socat
How LATAM supply chain attack works
Akamai describes an intrusion in a Latin American environment, titled a supply chain attack, that began with a compromised web-facing DMZ application. The attacker opened BASH TCP-socket reverse shells to infrastructure associated with the Sliver C2 framework, enumerated Active Directory with `net ads search`, and moved laterally using a socat listener plus inbound FTP/SSH from malicious IPs and anomalous NTP traffic. Akamai ExAR correlated workload process telemetry, network flows, segmentation policy and threat intelligence to contain it.
Akamai Security Research (Dennis Birchard, João Dejavite; published 2026-10-06) documents an intrusion against a Latin American environment, labelled in the article title as a supply chain attack. The article extract available to us does not describe the supply-chain mechanism itself; the label comes from the title and from the victim environment being described as LATAM supply chain infrastructure. The incident dates are not disclosed.
Initial access: the adversary likely gained a foothold through a web-facing application in the DMZ. Evidence from the affected web server and internal FTP logs supported the conclusion that exposed web endpoints, including unrestricted file access via a web endpoint, were the likely route to remote code execution. No CVE is cited.
Command and control: from a Linux or OpenShift host the actor used BASH TCP socket redirection to establish interactive reverse shells to external infrastructure that threat intelligence associated with the Sliver C2 framework (an open-source, Golang, cross-platform C2 framework). The shells were persistent, reconnecting repeatedly.
Discovery and lateral movement: the adversary used `net ads search` to enumerate Active Directory users and identify potential high-value targets. A socat process listening on nonstandard ports and spawning interactive BASH sessions served as an additional backdoor/pivot. Workloads also saw inbound FTP and SSH connections from confirmed malicious IP addresses and anomalous inbound traffic to an NTP service. Affected systems spanned Linux workloads, OpenShift containers and Windows DMZ systems.
Response: Akamai ExAR correlated workload-level process telemetry, network flows, segmentation policy and threat intelligence, combined with human analyst investigation, to contain the intrusion. Akamai recommends positive security models for internet-facing workloads, restricting access to internal identity services and approved external destinations, controlling egress, deception techniques, and closing infrastructure coverage gaps.
Caveats: the article provides no IP addresses, domains, hashes, ports or file names, no threat-actor attribution and no CVSS. Severity is an analyst assessment, not stated by the source. Indicators recorded below are behavioral and tool-level only.
MITRE ATT&CK techniques used in TL-2026-2987
Lateral Movement
T1021.004 Remote Services: SSH
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell
Discovery
T1087.002 Account Discovery: Domain Account
Command and Control
T1095 Non-Application Layer Protocol; T1571 Non-Standard Port
Initial Access
Affected products and versions in LATAM supply chain attack
- Unknown — Web-facing DMZ application (unidentified)
- Red Hat — OpenShift containers (affected workloads)
- Linux / Windows — Linux workloads and Windows DMZ systems (affected hosts)
Remediation for LATAM supply chain attack
Immediate actions
- Hunt Linux, OpenShift and Windows DMZ workloads for outbound BASH TCP-socket (/dev/tcp) reverse shells and repeated reconnect loops
- Hunt for socat processes listening on nonstandard ports and spawning interactive BASH sessions
- Alert on `net ads search` executed from DMZ or web-tier workloads
- Block and investigate inbound FTP/SSH from untrusted IPs and anomalous inbound NTP to DMZ services
Workarounds
- Remove or restrict unrestricted file access via exposed web endpoints
- Apply microsegmentation between the DMZ, OpenShift and Active Directory zones
Longer-term hardening
- Apply a positive security model to internet-facing workloads (permit only required flows)
- Restrict DMZ access to internal identity services (Active Directory) to required systems only
- Control egress to approved external destinations only
- Deploy deception techniques and close infrastructure coverage gaps in workload telemetry
- Combine automated correlation of process telemetry and network flows with human analyst investigation
Timeline of LATAM supply chain attack
- Akamai Security Research published 'How Akamai ExAR Contained a LATAM Supply Chain Attack'.
- Akamai ExAR correlated workload process telemetry, network flows, segmentation policy and threat intelligence, with human analyst investigation, to contain the intrusion (date undisclosed).
- socat process listening on nonstandard ports spawned interactive BASH sessions; inbound FTP and SSH from confirmed malicious IPs and anomalous inbound NTP traffic observed (stage date undisclosed).
- Adversary ran `net ads search` to enumerate Active Directory users and identify high-value targets (stage date undisclosed).
- BASH TCP socket redirection from a Linux or OpenShift host established interactive reverse shells to external infrastructure associated with the Sliver C2 framework (stage date undisclosed).
- Adversary likely gained initial access through a web-facing DMZ application; web server and internal FTP logs point to exposed web endpoints (unrestricted file access) as the route to remote code execution. Incident dates not disclosed; stage order follows Akamai's narrative and is dated to the publication day.
Sources cited for LATAM supply chain attack
- How Akamai ExAR Contained a LATAM Supply Chain Attack (Dennis Birchard, João Dejavite)
- MITRE ATT&CK: Sliver (S0633)
- MITRE ATT&CK: T1190 Exploit Public-Facing Application
- MITRE ATT&CK: T1059.004 Unix Shell
- MITRE ATT&CK: T1087.002 Domain Account
- Sliver Case Study: Assessing Common Offensive Security Tools (Team Cymru)
- Sliver C2 Leveraged by Many Threat Actors (Cybereason)
Detection coverage for TL-2026-2987
As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2987 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.