GTPDoor is a Linux backdoor tailored to telecommunications roaming infrastructure. It listens for GTP-C signaling traffic and tunnels command-and-control communications through the protocol, allowing covert beaconing and remote command execution in environments adjacent to GPRS Roaming eXchange networks. It has been associated with activity targeting telecommunications infrastructure, including systems supporting mobile roaming and packet-data services. GTPDoor can masquerade as legitimate system processes to reduce detection. It has been linked to the nation-state-associated CL-STA-0969 intrusion cluster, which overlaps with Liminal Panda and has tooling associations with LightBasin/UNC1945. The implant is assessed as requiring prior compromise of a carrier or roaming-partner environment before deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Security researcher “HaxRob” discovered a new Linux-based malware named “GTPDOOR”... likely a tool, belonging to the ‘LightBasin’ threat group (UNC1945), that is deployed for intelligence-collection operations targeting telecommunications company globally.
GTPDoor: A Linux implant that uses GTP-C signaling (UDP port 2123) to tunnel C2 traffic within telecom networks, supporting beaconing and remote code execution. It bypasses traditional detection tools due to its use of telecom-specific protocols.
“GTPDOOR —served as a persistent command-distribution layer, enabling covert communications and exfiltration through roaming interfaces.”
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tooling/abuse referenced in a telecom-focused cyber-espionage campaign to enable access/exfiltration via GTP-related mechanisms.
A custom backdoor used to provide persistent command-and-control and data exfiltration over telecom roaming interfaces by abusing GTP-related pathways.
A Linux implant that tunnels C2 traffic using GTP-C signaling, supports beaconing and remote code execution, and evades detection by leveraging telecom-specific protocols.
Linux telecom implant that tunnels C2 over GTP-C signaling (UDP/2123) to bypass traditional controls; supports beaconing and remote code execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.