Campaign comparison
Bulletproof-Hosting Tradecraft: Two-Hour DGA Certificates, Role-Separated Nodes, and Brand-Impersonation TLS vs Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)
2026-09-30 · 2026-07-09
Link signals
Analytic
Same stage(s) reached by different techniques: defense-evasion — same objective, different method
Commodity
Shared ATT&CK technique(s): T1036.005, T1071.001 — commodity, many actors share these
Actor & objective
Actor
unattributed
vs
unattributed
different
Objective
unknown (intent unproven)
vs
unknown (intent unproven)
same
Kill chain
= same stage & technique ≠ same stage, different technique • unique to one campaign
Bulletproof-Hosting Tradecraft: Two-Hour DGA Certificates, Role-Separated Nodes, and Brand-Impersonation TLS
-
divergent step: 1. defense-evasion
· T1036.005
fake Windows-update payload filenames (MSI + PE) via self-signed HTTPS
-
divergent step: 2. defense-evasion
· T1587.003
Apple brand-impersonation TLS cert (issuer label copies Apple Public EV Server RSA CA; absent from CT logs, not issued through Apple's normal channel - self-signed vs. stolen-key signature unconfirmed) on relay + AkamaiGHost header
-
shared step: 3. command-and-control
· T1071.001
HTTPS payload delivery across a 3-node role-separated bulletproof-hosting cluster (dropper/relay/C2 separation)
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)
-
unique step: 1. reconnaissance
two visits to PAN-OS management interface hours apart
-
unique step: 2. initial-access
· T1190
CVE-2024-0012 auth bypass + CVE-2024-9474 privesc chained in a single request
-
unique step: 3. execution
· T1059.004
backtick injection executes bash dropper (in.js) fetching implant up.js
-
unique step: 4. persistence
· T1543.002
Sliver implant masquerades as /usr/bin/e3fsck; timestamp copied from /usr/sbin/e3fsck
-
divergent step: 5. defense-evasion
· T1027
UPX-packed obfuscated custom Sliver; staging server blocks cloud/AWS/GCP/Azure/CF IP ranges
-
shared step: 6. command-and-control
· T1071.001
HTTPS beacon to secpopper.world; fallback catalapnews.today; DNS C2 fallback
-
unique step: 7. lateral-movement
· T1021
WireGuard tunnel + SOCKS proxy pivot into internal network
Side by side
green = shared by both campaigns.
| Bulletproof-Hosting Tradecraft: Two-Hour DGA Certificates, Role-Separated Nodes, and Brand-Impersonation TLS | Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) |
|---|---|
| Procedures | |
| cert-rotation:2h-dgafake-update-social-engineeringmulti-node-role-separation | exploit-escalation:try-newer-then-pivothistory-suppression:HISTFILEmasquerade-as-system-binarytimestomp:touch-r |
| Toolmarks | |
| brand-impersonation:Apple-CN-labelserver-header:AkamaiGHost | bypass:watchTowr.js.mapmasquerade:/usr/bin/e3fsck |
| C2 protocol | |
| https; DGA-named certificates with a two-hour validity window (issuer authenticity unconfirmed) | https beacon /api/javascripts/bundles/route.js (procedurally generated) to secpopper.world; fallback catalapnews.today; DNS C2 fallback |
| Tooling | |
| dga-cert-rotationfake-update-dropper | sliverupxwatchtowr-cve-2024-0012-bypass |
| Capabilities | |
| Apple brand-impersonation TLS (certificate not issued through Apple's normal channel; self-signed vs. stolen-key signature unconfirmed)TLS certificates with a two-hour validity window on the C2 nodemulti-node functional separation (dropper/relay/C2) | Cobalt Strike BOF supportOS credential dumping (MakeToken/ImpersonateReq)SOCKS proxy pivotWireGuard tunnelinganti-forensics (timestomp, history wipe) |
| C2 | |
| — | catalapnews.todaysecpopper.world |
| Domains | |
| — | catalapnews.todayfeng-shui.uasecpopper.world |
| CVEs | |
| — | CVE-2024-0012CVE-2024-3400CVE-2024-9474 |
| Products | |
| Microsoft Windows | PAN-OS |