Threat reportSupply ChainTL-2026-2987

LATAM supply chain attack: Sliver C2 reverse shells from DMZ web application to Active Directory, contained by Akamai ExAR

highRESOLVED

LATAM supply chain attack (TL-2026-2987) is a high-severity supply-chain compromise, first published 2026-10-06. It has no confirmed attribution, affects Unknown Web-facing DMZ application (unidentified), maps to 6 MITRE ATT&CK techniques (T1021.004, T1059.004, T1087.002), and is covered by 9 detection rules and 5 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
5Indicators of compromise

Key facts for TL-2026-2987

Threat ID
TL-2026-2987
Severity
HIGH
Status
RESOLVED
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
supply chain logistics
Target regions
Latin America
Detection rules
9
Indicators of compromise
5

Malware and tooling in LATAM supply chain attack

Malware and tooling: Sliver, Sliver - S0633, ftp - S0095, socat

How LATAM supply chain attack works

Akamai describes an intrusion in a Latin American environment, titled a supply chain attack, that began with a compromised web-facing DMZ application. The attacker opened BASH TCP-socket reverse shells to infrastructure associated with the Sliver C2 framework, enumerated Active Directory with `net ads search`, and moved laterally using a socat listener plus inbound FTP/SSH from malicious IPs and anomalous NTP traffic. Akamai ExAR correlated workload process telemetry, network flows, segmentation policy and threat intelligence to contain it.

Akamai Security Research (Dennis Birchard, João Dejavite; published 2026-10-06) documents an intrusion against a Latin American environment, labelled in the article title as a supply chain attack. The article extract available to us does not describe the supply-chain mechanism itself; the label comes from the title and from the victim environment being described as LATAM supply chain infrastructure. The incident dates are not disclosed.

Initial access: the adversary likely gained a foothold through a web-facing application in the DMZ. Evidence from the affected web server and internal FTP logs supported the conclusion that exposed web endpoints, including unrestricted file access via a web endpoint, were the likely route to remote code execution. No CVE is cited.

Command and control: from a Linux or OpenShift host the actor used BASH TCP socket redirection to establish interactive reverse shells to external infrastructure that threat intelligence associated with the Sliver C2 framework (an open-source, Golang, cross-platform C2 framework). The shells were persistent, reconnecting repeatedly.

Discovery and lateral movement: the adversary used `net ads search` to enumerate Active Directory users and identify potential high-value targets. A socat process listening on nonstandard ports and spawning interactive BASH sessions served as an additional backdoor/pivot. Workloads also saw inbound FTP and SSH connections from confirmed malicious IP addresses and anomalous inbound traffic to an NTP service. Affected systems spanned Linux workloads, OpenShift containers and Windows DMZ systems.

Response: Akamai ExAR correlated workload-level process telemetry, network flows, segmentation policy and threat intelligence, combined with human analyst investigation, to contain the intrusion. Akamai recommends positive security models for internet-facing workloads, restricting access to internal identity services and approved external destinations, controlling egress, deception techniques, and closing infrastructure coverage gaps.

Caveats: the article provides no IP addresses, domains, hashes, ports or file names, no threat-actor attribution and no CVSS. Severity is an analyst assessment, not stated by the source. Indicators recorded below are behavioral and tool-level only.

MITRE ATT&CK techniques used in TL-2026-2987

Lateral Movement

T1021.004 Remote Services: SSH

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell

Discovery

T1087.002 Account Discovery: Domain Account

Command and Control

T1095 Non-Application Layer Protocol; T1571 Non-Standard Port

Initial Access

T1190 Exploit Public-Facing Application

Affected products and versions in LATAM supply chain attack

  • Unknown — Web-facing DMZ application (unidentified)
  • Red Hat — OpenShift containers (affected workloads)
  • Linux / Windows — Linux workloads and Windows DMZ systems (affected hosts)

Remediation for LATAM supply chain attack

Immediate actions

  • Hunt Linux, OpenShift and Windows DMZ workloads for outbound BASH TCP-socket (/dev/tcp) reverse shells and repeated reconnect loops
  • Hunt for socat processes listening on nonstandard ports and spawning interactive BASH sessions
  • Alert on `net ads search` executed from DMZ or web-tier workloads
  • Block and investigate inbound FTP/SSH from untrusted IPs and anomalous inbound NTP to DMZ services

Workarounds

  • Remove or restrict unrestricted file access via exposed web endpoints
  • Apply microsegmentation between the DMZ, OpenShift and Active Directory zones

Longer-term hardening

  • Apply a positive security model to internet-facing workloads (permit only required flows)
  • Restrict DMZ access to internal identity services (Active Directory) to required systems only
  • Control egress to approved external destinations only
  • Deploy deception techniques and close infrastructure coverage gaps in workload telemetry
  • Combine automated correlation of process telemetry and network flows with human analyst investigation

Timeline of LATAM supply chain attack

  • Akamai Security Research published 'How Akamai ExAR Contained a LATAM Supply Chain Attack'.
  • Akamai ExAR correlated workload process telemetry, network flows, segmentation policy and threat intelligence, with human analyst investigation, to contain the intrusion (date undisclosed).
  • socat process listening on nonstandard ports spawned interactive BASH sessions; inbound FTP and SSH from confirmed malicious IPs and anomalous inbound NTP traffic observed (stage date undisclosed).
  • Adversary ran `net ads search` to enumerate Active Directory users and identify high-value targets (stage date undisclosed).
  • BASH TCP socket redirection from a Linux or OpenShift host established interactive reverse shells to external infrastructure associated with the Sliver C2 framework (stage date undisclosed).
  • Adversary likely gained initial access through a web-facing DMZ application; web server and internal FTP logs point to exposed web endpoints (unrestricted file access) as the route to remote code execution. Incident dates not disclosed; stage order follows Akamai's narrative and is dated to the publication day.

Sources cited for LATAM supply chain attack

Detection coverage for TL-2026-2987

As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2987 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
5 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats