Security researcher HaxRob has discovered a new Linux backdoor that is currently used to spy on telco networks.
The malware is named GTPDOOR after its use of the GPRS Tunnelling Protocol (GTP) to disguise command-and-control communications.
HaxRob believes the malware may be linked to LightBasin, a cyber-espionage group with a long history of telco espionage.
https://doubleagent.net/telecommunications/backdoor/gtp/2024/02/27/GTPDOOR-COVERT-TELCO-BACKDOOR