Campaign comparison

FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration vs TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking

2026-06-09  ·  2026-06-29

Link signals

Analytic Same stage(s) reached by different techniques: reconnaissance, persistence, defense-evasion — same objective, different method
Commodity Shared ATT&CK technique(s): T1098.004, T1190, T1552.001 — commodity, many actors share these

Actor & objective

Actor z0r0 (suspected) vs unattributed different
Objective access-resale vs Credential harvesting + Monero cryptojacking via Docker API container escape, with Kubernetes cluster-wide propagation different

Kill chain

= same stage & technique   same stage, different technique   unique to one campaign

FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration

  1. divergent step: 1. reconnaissance
    admin login probing (UA Research/1.0) + firmware version check via python-requests/2.34.2
  2. unique step: 2. initial-access · T1190
    CVE-2022-40684 auth bypass via Forwarded: for=127.0.0.1, after failed CVE-2024-21762 SSL-VPN heap-spray attempt
  3. divergent step: 3. persistence · T1136.001
    created 6 backdoor super_admin accounts (fortipwn_test, fw1/fw2/fw3, fw_api, fortipwn_admin)
  4. divergent step: 4. persistence · T1098.004
    planted SSH key on admin account (fingerprint withheld)
  5. divergent step: 5. defense-evasion · T1564
    set hidden:1 on admin account (invisible in management GUI)
  6. divergent step: 6. defense-evasion · T1556.006
    disabled two-factor authentication on admin account
  7. unique step: 7. exfiltration · T1552.001
    downloaded full FortiOS config backup x3 from two IPs (LDAP bind, VPN, SNMP creds)

TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking

  1. divergent step: 1. reconnaissance · T1190
    Docker /version probe + /images/json enumeration on exposed daemon API
  2. unique step: 2. execution · T1610
    Four privileged containers created (Privileged:true, Binds /:/host:rw)
  3. unique step: 3. privilege-escalation · T1611
    Escape to host via bind-mounted root; CVE-2026-31431 kernel LPE if not root
  4. divergent step: 4. persistence · T1543.002
    cgroup-fs.service systemd unit disguised as 'Control Group FS'; cron net-check; profile.d hijack; 41832@CAI SSH key
  5. unique step: 5. credential-access · T1552.005
    Cloud metadata tokens (AWS/GCP/Azure/Alibaba/Tencent), SSH keys, K8s SA tokens, wallets, CI/CD tokens, AI tool configs -> POST :667
  6. unique step: 6. lateral-movement · T1021.004
    SSH worm via harvested keys + masscan; K8s kubectl apply DaemonSet attempt
  7. unique step: 7. impact · T1496
    XMRig 6.22.2 Monero mining behind self-hosted stratum proxies -> MoneroOcean
  8. divergent step: 8. defense-evasion · T1562.001
    Cloud monitoring-agent removal; Perfctl-style process hiding; iptables DROP 2375-2377

Side by side

green = shared by both campaigns.

Attribute-by-attribute comparison of FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration and TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking. Values labelled "shared" appear in both campaigns.
FortiGate Admin-Hijack Operator Plants Hidden Backdoors and Steals Full Device Configuration TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking
Procedures
config-backup-exfilexploit-escalation:try-newer-then-pivothidden-admin-persistence:hidden-flagmfa-disableredundant-backdoor-accountsssh-key-implanttrusthost-any:0.0.0.0/0Five-method fetch fallback (bash /dev/tcp, busybox wget, curl, wget, python3 urllib; each x2)Live C2 rotation via sed patch of /opt/.cgroup-fs/miner.c on pre-compromised hosts
Toolmarks
account-naming:fortipwn_password-style:pentest (Test1234!/Pwn3d123!)Monero wallet 85BVSXMzxy74NTecwdiNbZZ83gxibFSszZhwCHBwcCCfW2xdrTWzMT14EgGihhQWC9fi3m5ZNfFAcaR4u5QYFP19ArnSAsKSSH key comment 41832@CAISource comment '# Pattern: 0cl/boatnet(ELLIO)+TeamTNT+PCPJack+RedTail+Perfctl+Kiss-a-dog'Source comment '# TeamPCP v21'XMRig CI/CD build path /home/buildbot/xmrig/ dated 2024-11-03
C2 protocol
HTTP dropper delivery (port 666); HTTP POST credential exfil (port 667); Monero stratum via self-hosted relay proxies (80/443/3333/8080)
Tooling
custom-cve-2022-40684-exploitcve-2024-21762-modulepython-requestsTeamPCP v21 toolkitXMRig 6.22.2masscan
Capabilities
MFA disableSSH key implantationconfig exfiltrationhidden-admin persistence18-category credential harvest incl. cloud metadata + AI tool configsCloud security-agent removal; rival-miner termination; Docker port lockoutDocker API container escape (privileged + host bind mount)Four-layer host persistence (systemd + cron + profile.d + SSH key)Kubernetes config dump + DaemonSet propagation attemptSSH worm spreading via harvested keys + masscanSelf-hosted stratum proxy aggregation
C2
31.56.48.17995.182.96.193
ASNs
AS20473AS37963AS56971
Domains
gulf.moneroocean.stream
CVEs
CVE-2022-40684CVE-2024-21762CVE-2026-31431
Products
FortiGate

← Compare a different pair