Campaign comparison

Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) vs FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration

2026-07-09  ·  2026-06-09

Link signals

Strong link Shared procedure(s): exploit-escalation:try-newer-then-pivot — same operational playbook, regardless of tooling
Strong link Same procedure, different tooling — shared steps: exploit-escalation:try-newer-then-pivot, with no shared tools, payload, or infrastructure (likely the same operator after retooling, or a shared playbook)
Analytic Same stage(s) reached by different techniques: persistence, defense-evasion — same objective, different method
Commodity Shared ATT&CK technique(s): T1190 — commodity, many actors share these

Actor & objective

Actor unattributed vs z0r0 (suspected) different
Objective unknown (intent unproven) vs access-resale different

Kill chain

= same stage & technique   same stage, different technique   unique to one campaign

Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)

  1. shared step: 1. reconnaissance
    two visits to PAN-OS management interface hours apart
  2. shared step: 2. initial-access · T1190
    CVE-2024-0012 auth bypass + CVE-2024-9474 privesc chained in a single request
  3. unique step: 3. execution · T1059.004
    backtick injection executes bash dropper (in.js) fetching implant up.js
  4. divergent step: 4. persistence · T1543.002
    Sliver implant masquerades as /usr/bin/e3fsck; timestamp copied from /usr/sbin/e3fsck
  5. divergent step: 5. defense-evasion · T1027
    UPX-packed obfuscated custom Sliver; staging server blocks cloud/AWS/GCP/Azure/CF IP ranges
  6. unique step: 6. command-and-control · T1071.001
    HTTPS beacon to secpopper.world; fallback catalapnews.today; DNS C2 fallback
  7. unique step: 7. lateral-movement · T1021
    WireGuard tunnel + SOCKS proxy pivot into internal network

FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration

  1. shared step: 1. reconnaissance
    admin login probing (UA Research/1.0) + firmware version check via python-requests/2.34.2
  2. shared step: 2. initial-access · T1190
    CVE-2022-40684 auth bypass via Forwarded: for=127.0.0.1, after failed CVE-2024-21762 SSL-VPN heap-spray attempt
  3. divergent step: 3. persistence · T1136.001
    created 6 backdoor super_admin accounts (fortipwn_test, fw1/fw2/fw3, fw_api, fortipwn_admin)
  4. divergent step: 4. persistence · T1098.004
    planted SSH key on admin account (fingerprint withheld)
  5. divergent step: 5. defense-evasion · T1564
    set hidden:1 on admin account (invisible in management GUI)
  6. divergent step: 6. defense-evasion · T1556.006
    disabled two-factor authentication on admin account
  7. unique step: 7. exfiltration · T1552.001
    downloaded full FortiOS config backup x3 from two IPs (LDAP bind, VPN, SNMP creds)

Side by side

green = shared by both campaigns.

Attribute-by-attribute comparison of Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) and FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration. Values labelled "shared" appear in both campaigns.
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration
Procedures
shared: exploit-escalation:try-newer-then-pivothistory-suppression:HISTFILEmasquerade-as-system-binarytimestomp:touch-rshared: exploit-escalation:try-newer-then-pivotconfig-backup-exfilhidden-admin-persistence:hidden-flagmfa-disableredundant-backdoor-accountsssh-key-implanttrusthost-any:0.0.0.0/0
Toolmarks
bypass:watchTowr.js.mapmasquerade:/usr/bin/e3fsckaccount-naming:fortipwn_password-style:pentest (Test1234!/Pwn3d123!)
C2 protocol
https beacon /api/javascripts/bundles/route.js (procedurally generated) to secpopper.world; fallback catalapnews.today; DNS C2 fallback
Tooling
sliverupxwatchtowr-cve-2024-0012-bypasscustom-cve-2022-40684-exploitcve-2024-21762-modulepython-requests
Capabilities
Cobalt Strike BOF supportOS credential dumping (MakeToken/ImpersonateReq)SOCKS proxy pivotWireGuard tunnelinganti-forensics (timestomp, history wipe)MFA disableSSH key implantationconfig exfiltrationhidden-admin persistence
C2
catalapnews.todaysecpopper.world
Domains
catalapnews.todayfeng-shui.uasecpopper.world
CVEs
CVE-2024-0012CVE-2024-3400CVE-2024-9474CVE-2022-40684CVE-2024-21762
Products
PAN-OSFortiGate

← Compare a different pair