GTPDOOR – A novel backdoor tailored for covert access over the roaming exchange
doubleagent.net
doubleagent.net
1. https://malpedia.caad.fkie.fraunhofer.de/actor/lightbasin 2. https://malpedia.caad.fkie.fraunhofer.de/actor/mustang_panda
This is interesting - the attribution for this actor has remained elusive for quite some time due to their consistent operational security.
Could you elaborate on how you came to this attribution? And to what confidence?
LightBasin is a group that is highly experienced in telecommunications that is able to identify specific hardware from vendors and probably has the same gear sitting in a lab to test on. They are focused on COMINT collection and exploitation. There has been no evidence of them doing initial access work (establishing a foothold within specific networks), so they are likely being given access and then using their domain knowledge to pivot between different telcom providers on shared networks.
Mustang Panda on the other hand focuses on initial access to organizations and then stealing credentials, intellectual property, and most importantly internal documentation. You can start to see how these two groups would work hand-in-hand.
Based on victimology I believe the two to be within an organizational structure where information passes from one to the other. It is impossible to definitively state one way or the other without having information from within the Chinese government.
If you want further info, my email is in my profile.
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/operati...
If it's the former, then it seems very un-stealthy. Like, if the GTP packets are making their way back to e.g. China Unicom, it's going to be hard to deny they were in on the operation. Which, maybe they don't care, but it seems like they're risking blacklisting.
The threat actor maintains a presence on the roaming exchange through compromising "at least 13 telecommunication companies".
> If it's the former, then it seems very un-stealthy
In this article there is one example where the outbound connectivity to the Internet was via a "SGSN emulator in a loop, attempting to connect to a set of nine pairs of International Mobile Subscriber Identity (IMSI) and Mobile Subscriber Integrated Services Digital Network (MSISDN) numbers."
In this example, the transit traffic before egress to the Internet would appear to be legitimate subscriber traffic - user payload encapsulated in a PDP context / GTP tunnel to another telco's GGSN / packet gateway.
> Which, maybe they don't care, but it seems like they're risking blacklisting.
By compromising so many telcos, there are many points of redundancy for persistence on the roaming exchange. This threat actor has remained on telco networks for many years undetected - their techniques are apparently are quite effective.
[1] https://www.crowdstrike.com/blog/an-analysis-of-lightbasin-t...
The diagram in the article is succinct but only a small part of complex full 3GPP architecture[1][2]. I kind of suspect it had probably been easy enough to chalk such traffic up to "a buggy implementation they're using over there" for a while.
1: https://yatebts.com/documentation/concepts/lte-concepts/
2: https://github.com/nickel0/3GPP-Overall-Architecture/blob/ma...
The counterintelligence that would give you should be far more valuable.
This is really advanced stuff and when it comes to infiltrating telco communications, it’s usually done at the highest levels of state actors to listen in or tap connections of countries and their president’s communications.
Also, the equipment is extremely expensive and getting access to it to craft exploits offline is costly. Exploiting it in the wild has its own risks.