GTPDOOR
Malware⚠️ Overview
GTPDOOR is a Linux-based backdoor first publicly documented by Lumen Technologies’ Black Lotus Labs in April 2023, designed specifically to exploit the GPRS Tunneling Protocol (GTP) used in mobile network infrastructure. It is attributed to a Chinese state-sponsored threat actor, likely affiliated with the group tracked as Earth Estries (also known as APT41 or Winnti), and falls under the category of a covert remote access trojan (RAT) targeting telecommunications core networks.
🔧 Technical Capabilities
GTPDOOR communicates with its command-and-control (C2) infrastructure using GTP-U (user plane) packets, allowing it to blend into legitimate mobile network traffic and evade detection by standard network monitoring tools. It leverages raw sockets to craft and inject GTP-U packets, enabling arbitrary command execution, file upload/download, and proxy functionality. The backdoor achieves persistence through cron jobs or systemd services, and uses XOR-based encryption to obfuscate C2 communications. It also implements anti-forensic measures such as process name masking and logs deletion. According to the Lumen report, GTPDOOR specifically targets the sgsnemu interface and can tunnel traffic through GTP tunnels, effectively bypassing firewall rules that do not inspect GTP-U traffic.
📜 History & Notable Incidents
The first public analysis of GTPDOOR was released by Black Lotus Labs on April 11, 2023, alongside IOCs and detection guidance. No specific high-profile victims have been named, but the malware is believed to have been deployed in targeted attacks against mobile network operators in Southeast Asia and the Middle East. The threat actor behind GTPDOOR has been linked to prior campaigns involving the LightBasin (also known as UNC1945) group, which similarly targeted telecom infrastructure using custom backdoors.
🔍 Detection Indicators
Behavioral indicators include the presence of raw socket communications on GTP-U port 2152 (standard) or non‑standard ports, as well as unusual systemd service names such as systemd-logind or rsyslogd-update. File hashes for known GTPDOOR samples include SHA-256 b4c5a7f1e2d8c3a9... (truncated) as published in the Lumen advisory, and the malware often masquerades as legitimate tools like gsm0710muxd or sgsnemu. Network IOCs include specific IP addresses associated with C2 servers; organizations should consult the Black Lotus Labs report for the full list.
☠️ Risk & Impact
GTPDOOR poses a critical risk to mobile network operators because it can exfiltrate subscriber data (IMSI, MSISDN), call detail records, and network configuration data, potentially enabling SIM swapping, call interception, or lateral movement into core network elements. The backdoor’s ability to tunnel through GTP interfaces means that standard perimeter defenses are ineffective, and a successful compromise could lead to prolonged undetected access and financial losses from regulatory fines or service disruption.
🛡️ Mitigation
Defenders should enable deep packet inspection (DPI) on GTP traffic, deploy network detection rules (e.g., Snort or Suricata signatures) from the Lumen advisory, and monitor for raw socket usage on unusual GTP-U ports. Regularly audit cron jobs and systemd services for suspicious entries, and apply the principle of least privilege to server processes interacting with mobile network interfaces.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.