Campaign comparison
FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration vs TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking
2026-06-09 · 2026-06-29
Link signals
Analytic
Same stage(s) reached by different techniques: reconnaissance, persistence, defense-evasion — same objective, different method
Commodity
Shared ATT&CK technique(s): T1098.004, T1190, T1552.001 — commodity, many actors share these
Actor & objective
Actor
z0r0 (suspected)
vs
unattributed
different
Objective
access-resale
vs
Credential harvesting + Monero cryptojacking via Docker API container escape, with Kubernetes cluster-wide propagation
different
Kill chain
= same stage & technique ≠ same stage, different technique • unique to one campaign
FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration
-
divergent step: 1. reconnaissance
admin login probing (UA Research/1.0) + firmware version check via python-requests/2.34.2
-
unique step: 2. initial-access
· T1190
CVE-2022-40684 auth bypass via Forwarded: for=127.0.0.1, after failed CVE-2024-21762 SSL-VPN heap-spray attempt
-
divergent step: 3. persistence
· T1136.001
created 6 backdoor super_admin accounts (fortipwn_test, fw1/fw2/fw3, fw_api, fortipwn_admin)
-
divergent step: 4. persistence
· T1098.004
planted SSH key on admin account (fingerprint withheld)
-
divergent step: 5. defense-evasion
· T1564
set hidden:1 on admin account (invisible in management GUI)
-
divergent step: 6. defense-evasion
· T1556.006
disabled two-factor authentication on admin account
-
unique step: 7. exfiltration
· T1552.001
downloaded full FortiOS config backup x3 from two IPs (LDAP bind, VPN, SNMP creds)
TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking
-
divergent step: 1. reconnaissance
· T1190
Docker /version probe + /images/json enumeration on exposed daemon API
-
unique step: 2. execution
· T1610
Four privileged containers created (Privileged:true, Binds /:/host:rw)
-
unique step: 3. privilege-escalation
· T1611
Escape to host via bind-mounted root; CVE-2026-31431 kernel LPE if not root
-
divergent step: 4. persistence
· T1543.002
cgroup-fs.service systemd unit disguised as 'Control Group FS'; cron net-check; profile.d hijack; 41832@CAI SSH key
-
unique step: 5. credential-access
· T1552.005
Cloud metadata tokens (AWS/GCP/Azure/Alibaba/Tencent), SSH keys, K8s SA tokens, wallets, CI/CD tokens, AI tool configs -> POST :667
-
unique step: 6. lateral-movement
· T1021.004
SSH worm via harvested keys + masscan; K8s kubectl apply DaemonSet attempt
-
unique step: 7. impact
· T1496
XMRig 6.22.2 Monero mining behind self-hosted stratum proxies -> MoneroOcean
-
divergent step: 8. defense-evasion
· T1562.001
Cloud monitoring-agent removal; Perfctl-style process hiding; iptables DROP 2375-2377
Side by side
green = shared by both campaigns.
| FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration | TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking |
|---|---|
| Procedures | |
| config-backup-exfilexploit-escalation:try-newer-then-pivothidden-admin-persistence:hidden-flagmfa-disableredundant-backdoor-accountsssh-key-implanttrusthost-any:0.0.0.0/0 | Five-method fetch fallback (bash /dev/tcp, busybox wget, curl, wget, python3 urllib; each x2)Live C2 rotation via sed patch of /opt/.cgroup-fs/miner.c on pre-compromised hosts |
| Toolmarks | |
| account-naming:fortipwn_password-style:pentest (Test1234!/Pwn3d123!) | Monero wallet 85BVSXMzxy74NTecwdiNbZZ83gxibFSszZhwCHBwcCCfW2xdrTWzMT14EgGihhQWC9fi3m5ZNfFAcaR4u5QYFP19ArnSAsKSSH key comment 41832@CAISource comment '# Pattern: 0cl/boatnet(ELLIO)+TeamTNT+PCPJack+RedTail+Perfctl+Kiss-a-dog'Source comment '# TeamPCP v21'XMRig CI/CD build path /home/buildbot/xmrig/ dated 2024-11-03 |
| C2 protocol | |
| — | HTTP dropper delivery (port 666); HTTP POST credential exfil (port 667); Monero stratum via self-hosted relay proxies (80/443/3333/8080) |
| Tooling | |
| custom-cve-2022-40684-exploitcve-2024-21762-modulepython-requests | TeamPCP v21 toolkitXMRig 6.22.2masscan |
| Capabilities | |
| MFA disableSSH key implantationconfig exfiltrationhidden-admin persistence | 18-category credential harvest incl. cloud metadata + AI tool configsCloud security-agent removal; rival-miner termination; Docker port lockoutDocker API container escape (privileged + host bind mount)Four-layer host persistence (systemd + cron + profile.d + SSH key)Kubernetes config dump + DaemonSet propagation attemptSSH worm spreading via harvested keys + masscanSelf-hosted stratum proxy aggregation |
| C2 | |
| — | 31.56.48.17995.182.96.193 |
| ASNs | |
| — | AS20473AS37963AS56971 |
| Domains | |
| — | gulf.moneroocean.stream |
| CVEs | |
| CVE-2022-40684CVE-2024-21762 | CVE-2026-31431 |
| Products | |
| FortiGate | — |