Campaign comparison
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) vs TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking
2026-07-09 · 2026-06-29
Link signals
Analytic
Same stage(s) reached by different techniques: reconnaissance, execution, defense-evasion, lateral-movement — same objective, different method
Commodity
Shared ATT&CK technique(s): T1027, T1190, T1543.002 — commodity, many actors share these
Actor & objective
Actor
unattributed
vs
unattributed
different
Objective
unknown (intent unproven)
vs
Credential harvesting + Monero cryptojacking via Docker API container escape, with Kubernetes cluster-wide propagation
different
Kill chain
= same stage & technique ≠ same stage, different technique • unique to one campaign
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)
-
divergent step: 1. reconnaissance
two visits to PAN-OS management interface hours apart
-
unique step: 2. initial-access
· T1190
CVE-2024-0012 auth bypass + CVE-2024-9474 privesc chained in a single request
-
divergent step: 3. execution
· T1059.004
backtick injection executes bash dropper (in.js) fetching implant up.js
-
shared step: 4. persistence
· T1543.002
Sliver implant masquerades as /usr/bin/e3fsck; timestamp copied from /usr/sbin/e3fsck
-
divergent step: 5. defense-evasion
· T1027
UPX-packed obfuscated custom Sliver; staging server blocks cloud/AWS/GCP/Azure/CF IP ranges
-
unique step: 6. command-and-control
· T1071.001
HTTPS beacon to secpopper.world; fallback catalapnews.today; DNS C2 fallback
-
divergent step: 7. lateral-movement
· T1021
WireGuard tunnel + SOCKS proxy pivot into internal network
TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking
-
divergent step: 1. reconnaissance
· T1190
Docker /version probe + /images/json enumeration on exposed daemon API
-
divergent step: 2. execution
· T1610
Four privileged containers created (Privileged:true, Binds /:/host:rw)
-
unique step: 3. privilege-escalation
· T1611
Escape to host via bind-mounted root; CVE-2026-31431 kernel LPE if not root
-
shared step: 4. persistence
· T1543.002
cgroup-fs.service systemd unit disguised as 'Control Group FS'; cron net-check; profile.d hijack; 41832@CAI SSH key
-
unique step: 5. credential-access
· T1552.005
Cloud metadata tokens (AWS/GCP/Azure/Alibaba/Tencent), SSH keys, K8s SA tokens, wallets, CI/CD tokens, AI tool configs -> POST :667
-
divergent step: 6. lateral-movement
· T1021.004
SSH worm via harvested keys + masscan; K8s kubectl apply DaemonSet attempt
-
unique step: 7. impact
· T1496
XMRig 6.22.2 Monero mining behind self-hosted stratum proxies -> MoneroOcean
-
divergent step: 8. defense-evasion
· T1562.001
Cloud monitoring-agent removal; Perfctl-style process hiding; iptables DROP 2375-2377
Side by side
green = shared by both campaigns.
| Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) | TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking |
|---|---|
| Procedures | |
| exploit-escalation:try-newer-then-pivothistory-suppression:HISTFILEmasquerade-as-system-binarytimestomp:touch-r | Five-method fetch fallback (bash /dev/tcp, busybox wget, curl, wget, python3 urllib; each x2)Live C2 rotation via sed patch of /opt/.cgroup-fs/miner.c on pre-compromised hosts |
| Toolmarks | |
| bypass:watchTowr.js.mapmasquerade:/usr/bin/e3fsck | Monero wallet 85BVSXMzxy74NTecwdiNbZZ83gxibFSszZhwCHBwcCCfW2xdrTWzMT14EgGihhQWC9fi3m5ZNfFAcaR4u5QYFP19ArnSAsKSSH key comment 41832@CAISource comment '# Pattern: 0cl/boatnet(ELLIO)+TeamTNT+PCPJack+RedTail+Perfctl+Kiss-a-dog'Source comment '# TeamPCP v21'XMRig CI/CD build path /home/buildbot/xmrig/ dated 2024-11-03 |
| C2 protocol | |
| https beacon /api/javascripts/bundles/route.js (procedurally generated) to secpopper.world; fallback catalapnews.today; DNS C2 fallback | HTTP dropper delivery (port 666); HTTP POST credential exfil (port 667); Monero stratum via self-hosted relay proxies (80/443/3333/8080) |
| Tooling | |
| sliverupxwatchtowr-cve-2024-0012-bypass | TeamPCP v21 toolkitXMRig 6.22.2masscan |
| Capabilities | |
| Cobalt Strike BOF supportOS credential dumping (MakeToken/ImpersonateReq)SOCKS proxy pivotWireGuard tunnelinganti-forensics (timestomp, history wipe) | 18-category credential harvest incl. cloud metadata + AI tool configsCloud security-agent removal; rival-miner termination; Docker port lockoutDocker API container escape (privileged + host bind mount)Four-layer host persistence (systemd + cron + profile.d + SSH key)Kubernetes config dump + DaemonSet propagation attemptSSH worm spreading via harvested keys + masscanSelf-hosted stratum proxy aggregation |
| C2 | |
| catalapnews.todaysecpopper.world | 31.56.48.17995.182.96.193 |
| ASNs | |
| — | AS20473AS37963AS56971 |
| Domains | |
| catalapnews.todayfeng-shui.uasecpopper.world | gulf.moneroocean.stream |
| CVEs | |
| CVE-2024-0012CVE-2024-3400CVE-2024-9474 | CVE-2026-31431 |
| Products | |
| PAN-OS | — |