Campaign comparison
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) vs Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE
2026-07-09 · 2026-06-03
Link signals
Strong link
Shared procedure(s): history-suppression:HISTFILE — same operational playbook, regardless of tooling
Strong link
Same procedure, different tooling — shared steps: history-suppression:HISTFILE, with no shared tools, payload, or infrastructure (likely the same operator after retooling, or a shared playbook)
Analytic
Same stage(s) reached by different techniques: execution, persistence — same objective, different method
Commodity
Shared ATT&CK technique(s): T1027, T1190 — commodity, many actors share these
Actor & objective
Actor
unattributed
vs
unattributed
different
Objective
unknown (intent unproven)
vs
data-exfiltration
different
Kill chain
= same stage & technique ≠ same stage, different technique • unique to one campaign
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)
-
unique step: 1. reconnaissance
two visits to PAN-OS management interface hours apart
-
shared step: 2. initial-access
· T1190
CVE-2024-0012 auth bypass + CVE-2024-9474 privesc chained in a single request
-
divergent step: 3. execution
· T1059.004
backtick injection executes bash dropper (in.js) fetching implant up.js
-
divergent step: 4. persistence
· T1543.002
Sliver implant masquerades as /usr/bin/e3fsck; timestamp copied from /usr/sbin/e3fsck
-
shared step: 5. defense-evasion
· T1027
UPX-packed obfuscated custom Sliver; staging server blocks cloud/AWS/GCP/Azure/CF IP ranges
-
unique step: 6. command-and-control
· T1071.001
HTTPS beacon to secpopper.world; fallback catalapnews.today; DNS C2 fallback
-
unique step: 7. lateral-movement
· T1021
WireGuard tunnel + SOCKS proxy pivot into internal network
Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE
-
shared step: 1. initial-access
· T1190
unauth RCE via Langflow code-eval endpoint
-
divergent step: 2. execution
· T1059.006
python one-liner stages the Go loader
-
shared step: 3. defense-evasion
· T1027
garble-obfuscated symbols, GoReSym-resistant
-
divergent step: 4. persistence
· T1543
multi-init systemd + cron + shell rc
-
unique step: 5. exfiltration
· T1041
Alibaba OSS SDK upload over TLS
Side by side
green = shared by both campaigns.
| Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) | Polydrop: Dissecting a Four-Stage Implant Chain Delivered via Langflow RCE |
|---|---|
| Procedures | |
| shared: history-suppression:HISTFILEexploit-escalation:try-newer-then-pivotmasquerade-as-system-binarytimestomp:touch-r | shared: history-suppression:HISTFILEarch-sweep:uname-m->arch-tagged-urlfileless:memfd+fexecveruntime-tasking:no-targeting-in-binary |
| Toolmarks | |
| bypass:watchTowr.js.mapmasquerade:/usr/bin/e3fsck | buildenv:/home/vbccsbpacker:garble-no-literals |
| C2 protocol | |
| https beacon /api/javascripts/bundles/route.js (procedurally generated) to secpopper.world; fallback catalapnews.today; DNS C2 fallback | tcp+single-byte-xor; url-grammar ?h=&p=&t=tcp&a={l64|l32|a64|a32}&stage=true |
| Tooling | |
| sliverupxwatchtowr-cve-2024-0012-bypass | alibaba-oss-sdkgarblememfd-loader |
| Capabilities | |
| Cobalt Strike BOF supportOS credential dumping (MakeToken/ImpersonateReq)SOCKS proxy pivotWireGuard tunnelinganti-forensics (timestomp, history wipe) | fileless-loadermemfd-execmulti-init-persistencesocks5-tunnel |
| C2 | |
| catalapnews.todaysecpopper.world | 149.104.29.201 |
| ASNs | |
| — | AS139659 |
| Domains | |
| catalapnews.todayfeng-shui.uasecpopper.world | — |
| CVEs | |
| CVE-2024-0012CVE-2024-3400CVE-2024-9474 | CVE-2025-3248 |
| Products | |
| PAN-OS | Langflow |
| Sectors | |
| — | ai-ml-tooling |
| Geographies | |
| — | global |