MESSAGETAP is a Linux ELF infostealer used to intercept and collect SMS traffic from telecommunications infrastructure, specifically servers operating as Short Message Service Centers (SMSCs). It has been associated with the Winnti group, also tracked as APT41/Barium, and has been used against telecom operators to support targeted surveillance.
The malware monitors network traffic on compromised SMSC servers using libpcap, parses protocol layers, and extracts SMS message content along with routing metadata. It supports selective collection rather than indiscriminate theft: configuration data is used to define targeting criteria such as phone numbers, IMSI values, and keywords. Messages matching those criteria are stored locally in CSV format for later theft. MESSAGETAP also reads XOR-decoded configuration files and deletes those files from disk after loading them into memory, indicating basic defense-evasion and anti-forensics behavior.
Operationally, MESSAGETAP begins monitoring all network connections to and from the victim server after loading its targeting data. Its placement on telecom messaging infrastructure makes it notable as a surveillance-oriented Linux malware family focused on SMS interception rather than conventional endpoint theft. Reported victims include telecommunications environments, and the malware is notable for demonstrating mature APT interest in Linux-based carrier infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MESSAGETAP - Infostealer discovered by FireEye on a telecommunications company’s Linux servers. These servers operate as a Short Message Service Center (SMSC), which routed SMS messages to recipients. The malware was designed to steal SMS traffic and it was also tied to the Winnti group.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer deployed on Linux SMSC servers to steal SMS traffic; tied to the Winnti group.
Malware that XOR-decodes file contents after checking for specific files.
Backdoor malware that deletes configuration files after loading into memory.
Linux malware used to selectively intercept SMS messages from telecom operator infrastructure, reportedly deployed on SMS gateway systems for surveillance operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.