Campaign comparison

Bulletproof-Hosting Tradecraft: Two-Hour DGA Certificates, Role-Separated Nodes, and Brand-Impersonation TLS vs Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)

2026-09-30  ·  2026-07-09

Link signals

Analytic Same stage(s) reached by different techniques: defense-evasion — same objective, different method
Commodity Shared ATT&CK technique(s): T1036.005, T1071.001 — commodity, many actors share these

Actor & objective

Actor unattributed vs unattributed different
Objective unknown (intent unproven) vs unknown (intent unproven) same

Kill chain

= same stage & technique   ≠ same stage, different technique   • unique to one campaign

Bulletproof-Hosting Tradecraft: Two-Hour DGA Certificates, Role-Separated Nodes, and Brand-Impersonation TLS

  1. divergent step: 1. defense-evasion · T1036.005
    fake Windows-update payload filenames (MSI + PE) via self-signed HTTPS
  2. divergent step: 2. defense-evasion · T1587.003
    Apple brand-impersonation TLS cert (issuer label copies Apple Public EV Server RSA CA; absent from CT logs, not issued through Apple's normal channel - self-signed vs. stolen-key signature unconfirmed) on relay + AkamaiGHost header
  3. shared step: 3. command-and-control · T1071.001
    HTTPS payload delivery across a 3-node role-separated bulletproof-hosting cluster (dropper/relay/C2 separation)

Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)

  1. unique step: 1. reconnaissance
    two visits to PAN-OS management interface hours apart
  2. unique step: 2. initial-access · T1190
    CVE-2024-0012 auth bypass + CVE-2024-9474 privesc chained in a single request
  3. unique step: 3. execution · T1059.004
    backtick injection executes bash dropper (in.js) fetching implant up.js
  4. unique step: 4. persistence · T1543.002
    Sliver implant masquerades as /usr/bin/e3fsck; timestamp copied from /usr/sbin/e3fsck
  5. divergent step: 5. defense-evasion · T1027
    UPX-packed obfuscated custom Sliver; staging server blocks cloud/AWS/GCP/Azure/CF IP ranges
  6. shared step: 6. command-and-control · T1071.001
    HTTPS beacon to secpopper.world; fallback catalapnews.today; DNS C2 fallback
  7. unique step: 7. lateral-movement · T1021
    WireGuard tunnel + SOCKS proxy pivot into internal network

Side by side

green = shared by both campaigns.

Attribute-by-attribute comparison of Bulletproof-Hosting Tradecraft: Two-Hour DGA Certificates, Role-Separated Nodes, and Brand-Impersonation TLS and Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474). Values labelled "shared" appear in both campaigns.
Bulletproof-Hosting Tradecraft: Two-Hour DGA Certificates, Role-Separated Nodes, and Brand-Impersonation TLS Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)
Procedures
cert-rotation:2h-dgafake-update-social-engineeringmulti-node-role-separationexploit-escalation:try-newer-then-pivothistory-suppression:HISTFILEmasquerade-as-system-binarytimestomp:touch-r
Toolmarks
brand-impersonation:Apple-CN-labelserver-header:AkamaiGHostbypass:watchTowr.js.mapmasquerade:/usr/bin/e3fsck
C2 protocol
https; DGA-named certificates with a two-hour validity window (issuer authenticity unconfirmed)https beacon /api/javascripts/bundles/route.js (procedurally generated) to secpopper.world; fallback catalapnews.today; DNS C2 fallback
Tooling
dga-cert-rotationfake-update-droppersliverupxwatchtowr-cve-2024-0012-bypass
Capabilities
Apple brand-impersonation TLS (certificate not issued through Apple's normal channel; self-signed vs. stolen-key signature unconfirmed)TLS certificates with a two-hour validity window on the C2 nodemulti-node functional separation (dropper/relay/C2)Cobalt Strike BOF supportOS credential dumping (MakeToken/ImpersonateReq)SOCKS proxy pivotWireGuard tunnelinganti-forensics (timestomp, history wipe)
C2
—catalapnews.todaysecpopper.world
Domains
—catalapnews.todayfeng-shui.uasecpopper.world
CVEs
—CVE-2024-0012CVE-2024-3400CVE-2024-9474
Products
Microsoft WindowsPAN-OS

← Compare a different pair