# LATAM supply chain attack: Sliver C2 reverse shells from DMZ web application to Active Directory, contained by Akamai ExAR

> Akamai describes an intrusion in a Latin American environment, titled a supply chain attack, that began with a compromised web-facing DMZ application. The attacker opened BASH TCP-socket reverse shells to infrastructure associated with the Sliver C2 framework, enumerated Active Directory with `net ads search`, and moved laterally using a socat listener plus inbound FTP/SSH from malicious IPs and anomalous NTP traffic. Akamai ExAR correlated workload process telemetry, network flows, segmentation policy and threat intelligence to contain it.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2987
- **ID:** TL-2026-2987
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** RESOLVED
- **Detections:** 9 · **IOCs:** 5 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Akamai Security Research (Dennis Birchard, João Dejavite; published 2026-10-06) documents an intrusion against a Latin American environment, labelled in the article title as a supply chain attack. The article extract available to us does not describe the supply-chain mechanism itself; the label comes from the title and from the victim environment being described as LATAM supply chain infrastructure. The incident dates are not disclosed.

Initial access: the adversary likely gained a foothold through a web-facing application in the DMZ. Evidence from the affected web server and internal FTP logs supported the conclusion that exposed web endpoints, including unrestricted file access via a web endpoint, were the likely route to remote code execution. No CVE is cited.

Command and control: from a Linux or OpenShift host the actor used BASH TCP socket redirection to establish interactive reverse shells to external infrastructure that threat intelligence associated with the Sliver C2 framework (an open-source, Golang, cross-platform C2 framework). The shells were persistent, reconnecting repeatedly.

Discovery and lateral movement: the adversary used `net ads search` to enumerate Active Directory users and identify potential high-value targets. A socat process listening on nonstandard ports and spawning interactive BASH sessions served as an additional backdoor/pivot. Workloads also saw inbound FTP and SSH connections from confirmed malicious IP addresses and anomalous inbound traffic to an NTP service. Affected systems spanned Linux workloads, OpenShift containers and Windows DMZ systems.

Response: Akamai ExAR correlated workload-level process telemetry, network flows, segmentation policy and threat intelligence, combined with human analyst investigation, to contain the intrusion. Akamai recommends positive security models for internet-facing workloads, restricting access to internal identity services and approved external destinations, controlling egress, deception techniques, and closing infrastructure coverage gaps.

Caveats: the article provides no IP addresses, domains, hashes, ports or file names, no threat-actor attribution and no CVSS. Severity is an analyst assessment, not stated by the source. Indicators recorded below are behavioral and tool-level only.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1087.002 Account Discovery: Domain Account
- T1021.004 Remote Services: SSH
- T1095 Non-Application Layer Protocol
- T1571 Non-Standard Port

## Sources

- [How Akamai ExAR Contained a LATAM Supply Chain Attack (Dennis Birchard, João Dejavite)](https://www.akamai.com/blog/security-research/2026/oct/how-akamai-exar-contained-latam-supply-chain-attack)
- [MITRE ATT&CK: Sliver (S0633)](https://attack.mitre.org/software/S0633/)
- [MITRE ATT&CK: T1190 Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190/)
- [MITRE ATT&CK: T1059.004 Unix Shell](https://attack.mitre.org/techniques/T1059/004/)
- [MITRE ATT&CK: T1087.002 Domain Account](https://attack.mitre.org/techniques/T1087/002/)
- [Sliver Case Study: Assessing Common Offensive Security Tools (Team Cymru)](https://www.team-cymru.com/post/sliver-case-study-assessing-common-offensive-security-tools)
- [Sliver C2 Leveraged by Many Threat Actors (Cybereason)](https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2987
