Campaign comparison
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) vs FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration
2026-07-09 · 2026-06-09
Link signals
Strong link
Shared procedure(s): exploit-escalation:try-newer-then-pivot — same operational playbook, regardless of tooling
Strong link
Same procedure, different tooling — shared steps: exploit-escalation:try-newer-then-pivot, with no shared tools, payload, or infrastructure (likely the same operator after retooling, or a shared playbook)
Analytic
Same stage(s) reached by different techniques: persistence, defense-evasion — same objective, different method
Commodity
Shared ATT&CK technique(s): T1190 — commodity, many actors share these
Actor & objective
Actor
unattributed
vs
z0r0 (suspected)
different
Objective
unknown (intent unproven)
vs
access-resale
different
Kill chain
= same stage & technique ≠ same stage, different technique • unique to one campaign
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)
-
shared step: 1. reconnaissance
two visits to PAN-OS management interface hours apart
-
shared step: 2. initial-access
· T1190
CVE-2024-0012 auth bypass + CVE-2024-9474 privesc chained in a single request
-
unique step: 3. execution
· T1059.004
backtick injection executes bash dropper (in.js) fetching implant up.js
-
divergent step: 4. persistence
· T1543.002
Sliver implant masquerades as /usr/bin/e3fsck; timestamp copied from /usr/sbin/e3fsck
-
divergent step: 5. defense-evasion
· T1027
UPX-packed obfuscated custom Sliver; staging server blocks cloud/AWS/GCP/Azure/CF IP ranges
-
unique step: 6. command-and-control
· T1071.001
HTTPS beacon to secpopper.world; fallback catalapnews.today; DNS C2 fallback
-
unique step: 7. lateral-movement
· T1021
WireGuard tunnel + SOCKS proxy pivot into internal network
FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration
-
shared step: 1. reconnaissance
admin login probing (UA Research/1.0) + firmware version check via python-requests/2.34.2
-
shared step: 2. initial-access
· T1190
CVE-2022-40684 auth bypass via Forwarded: for=127.0.0.1, after failed CVE-2024-21762 SSL-VPN heap-spray attempt
-
divergent step: 3. persistence
· T1136.001
created 6 backdoor super_admin accounts (fortipwn_test, fw1/fw2/fw3, fw_api, fortipwn_admin)
-
divergent step: 4. persistence
· T1098.004
planted SSH key on admin account (fingerprint withheld)
-
divergent step: 5. defense-evasion
· T1564
set hidden:1 on admin account (invisible in management GUI)
-
divergent step: 6. defense-evasion
· T1556.006
disabled two-factor authentication on admin account
-
unique step: 7. exfiltration
· T1552.001
downloaded full FortiOS config backup x3 from two IPs (LDAP bind, VPN, SNMP creds)
Side by side
green = shared by both campaigns.
| Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) | FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration |
|---|---|
| Procedures | |
| shared: exploit-escalation:try-newer-then-pivothistory-suppression:HISTFILEmasquerade-as-system-binarytimestomp:touch-r | shared: exploit-escalation:try-newer-then-pivotconfig-backup-exfilhidden-admin-persistence:hidden-flagmfa-disableredundant-backdoor-accountsssh-key-implanttrusthost-any:0.0.0.0/0 |
| Toolmarks | |
| bypass:watchTowr.js.mapmasquerade:/usr/bin/e3fsck | account-naming:fortipwn_password-style:pentest (Test1234!/Pwn3d123!) |
| C2 protocol | |
| https beacon /api/javascripts/bundles/route.js (procedurally generated) to secpopper.world; fallback catalapnews.today; DNS C2 fallback | — |
| Tooling | |
| sliverupxwatchtowr-cve-2024-0012-bypass | custom-cve-2022-40684-exploitcve-2024-21762-modulepython-requests |
| Capabilities | |
| Cobalt Strike BOF supportOS credential dumping (MakeToken/ImpersonateReq)SOCKS proxy pivotWireGuard tunnelinganti-forensics (timestomp, history wipe) | MFA disableSSH key implantationconfig exfiltrationhidden-admin persistence |
| C2 | |
| catalapnews.todaysecpopper.world | — |
| Domains | |
| catalapnews.todayfeng-shui.uasecpopper.world | — |
| CVEs | |
| CVE-2024-0012CVE-2024-3400CVE-2024-9474 | CVE-2022-40684CVE-2024-21762 |
| Products | |
| PAN-OS | FortiGate |