Campaign comparison

Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) vs TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking

2026-07-09  ·  2026-06-29

Link signals

Analytic Same stage(s) reached by different techniques: reconnaissance, execution, defense-evasion, lateral-movement — same objective, different method
Commodity Shared ATT&CK technique(s): T1027, T1190, T1543.002 — commodity, many actors share these

Actor & objective

Actor unattributed vs unattributed different
Objective unknown (intent unproven) vs Credential harvesting + Monero cryptojacking via Docker API container escape, with Kubernetes cluster-wide propagation different

Kill chain

= same stage & technique   same stage, different technique   unique to one campaign

Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474)

  1. divergent step: 1. reconnaissance
    two visits to PAN-OS management interface hours apart
  2. unique step: 2. initial-access · T1190
    CVE-2024-0012 auth bypass + CVE-2024-9474 privesc chained in a single request
  3. divergent step: 3. execution · T1059.004
    backtick injection executes bash dropper (in.js) fetching implant up.js
  4. shared step: 4. persistence · T1543.002
    Sliver implant masquerades as /usr/bin/e3fsck; timestamp copied from /usr/sbin/e3fsck
  5. divergent step: 5. defense-evasion · T1027
    UPX-packed obfuscated custom Sliver; staging server blocks cloud/AWS/GCP/Azure/CF IP ranges
  6. unique step: 6. command-and-control · T1071.001
    HTTPS beacon to secpopper.world; fallback catalapnews.today; DNS C2 fallback
  7. divergent step: 7. lateral-movement · T1021
    WireGuard tunnel + SOCKS proxy pivot into internal network

TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking

  1. divergent step: 1. reconnaissance · T1190
    Docker /version probe + /images/json enumeration on exposed daemon API
  2. divergent step: 2. execution · T1610
    Four privileged containers created (Privileged:true, Binds /:/host:rw)
  3. unique step: 3. privilege-escalation · T1611
    Escape to host via bind-mounted root; CVE-2026-31431 kernel LPE if not root
  4. shared step: 4. persistence · T1543.002
    cgroup-fs.service systemd unit disguised as 'Control Group FS'; cron net-check; profile.d hijack; 41832@CAI SSH key
  5. unique step: 5. credential-access · T1552.005
    Cloud metadata tokens (AWS/GCP/Azure/Alibaba/Tencent), SSH keys, K8s SA tokens, wallets, CI/CD tokens, AI tool configs -> POST :667
  6. divergent step: 6. lateral-movement · T1021.004
    SSH worm via harvested keys + masscan; K8s kubectl apply DaemonSet attempt
  7. unique step: 7. impact · T1496
    XMRig 6.22.2 Monero mining behind self-hosted stratum proxies -> MoneroOcean
  8. divergent step: 8. defense-evasion · T1562.001
    Cloud monitoring-agent removal; Perfctl-style process hiding; iptables DROP 2375-2377

Side by side

green = shared by both campaigns.

Attribute-by-attribute comparison of Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) and TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking. Values labelled "shared" appear in both campaigns.
Feng Shui: A Custom, Fully-Obfuscated Sliver Implant Deployed to a Palo Alto Firewall (CVE-2024-0012 + CVE-2024-9474) TeamPCP v21: Inside a 45-Second Docker Escape to Multi-Persistence Cryptojacking
Procedures
exploit-escalation:try-newer-then-pivothistory-suppression:HISTFILEmasquerade-as-system-binarytimestomp:touch-rFive-method fetch fallback (bash /dev/tcp, busybox wget, curl, wget, python3 urllib; each x2)Live C2 rotation via sed patch of /opt/.cgroup-fs/miner.c on pre-compromised hosts
Toolmarks
bypass:watchTowr.js.mapmasquerade:/usr/bin/e3fsckMonero wallet 85BVSXMzxy74NTecwdiNbZZ83gxibFSszZhwCHBwcCCfW2xdrTWzMT14EgGihhQWC9fi3m5ZNfFAcaR4u5QYFP19ArnSAsKSSH key comment 41832@CAISource comment '# Pattern: 0cl/boatnet(ELLIO)+TeamTNT+PCPJack+RedTail+Perfctl+Kiss-a-dog'Source comment '# TeamPCP v21'XMRig CI/CD build path /home/buildbot/xmrig/ dated 2024-11-03
C2 protocol
https beacon /api/javascripts/bundles/route.js (procedurally generated) to secpopper.world; fallback catalapnews.today; DNS C2 fallbackHTTP dropper delivery (port 666); HTTP POST credential exfil (port 667); Monero stratum via self-hosted relay proxies (80/443/3333/8080)
Tooling
sliverupxwatchtowr-cve-2024-0012-bypassTeamPCP v21 toolkitXMRig 6.22.2masscan
Capabilities
Cobalt Strike BOF supportOS credential dumping (MakeToken/ImpersonateReq)SOCKS proxy pivotWireGuard tunnelinganti-forensics (timestomp, history wipe)18-category credential harvest incl. cloud metadata + AI tool configsCloud security-agent removal; rival-miner termination; Docker port lockoutDocker API container escape (privileged + host bind mount)Four-layer host persistence (systemd + cron + profile.d + SSH key)Kubernetes config dump + DaemonSet propagation attemptSSH worm spreading via harvested keys + masscanSelf-hosted stratum proxy aggregation
C2
catalapnews.todaysecpopper.world31.56.48.17995.182.96.193
ASNs
AS20473AS37963AS56971
Domains
catalapnews.todayfeng-shui.uasecpopper.worldgulf.moneroocean.stream
CVEs
CVE-2024-0012CVE-2024-3400CVE-2024-9474CVE-2026-31431
Products
PAN-OS

← Compare a different pair