Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors LIMINAL PANDA

Also known as: UNC6384, CL-STA-0969, the LightBasin activity cluster

Description

LIMINAL PANDA, also referred to as UNC6384, CL-STA-0969 or LightBasin, has been active since at least 2019 targeting telecommunications operators worldwide. The adversary exploits commonly‑used credentials such as "huawei" and gains SSH access to external DNS servers within GPRS networks, allowing lateral movement across partner infrastructures. Once inside, the actors deploy a suite of custom tools—including PingPong backdoor, TinyShell command‐and‐control binary, SIGTRANslator for signalling protocol manipulation, CordScan for network scanning, and the sgsnemu2 GSM‑SGSN emulator—to harvest subscriber information and call metadata. Their methodology relies on sophisticated operational security. They modify legitimate system binaries (e.g., an iptables wrapper) to obscure firewall rule changes, alter init scripts (/etc/rc.d/init.d/) for persistence, and schedule execution windows of 30 minutes between 02:15‑02:45 UTC to minimise detection. The actor also chains SOCKS5 proxies via ProxyChains, often hosted on commercial VPS providers such as Vultr, to pivot internally and disguise C2 traffic. In addition to custom tools, they abuse publicly available utilities (Nexus, PowerShell scripts) and exploit multiple CVEs—including CVE‑2016‑5195, CVE‑2021‑4034 and CVE‑2021‑3156—for initial access or privilege escalation. While primarily focused on telecommunications assets for signals intelligence, LIMINAL PANDA’s tactics exhibit a generalist approach that could extend to enterprises sharing vendor relationships with telecom operators. Their campaigns are characterised by stealth, persistence, and an emphasis on exfiltrating large volumes of network traffic rather than financial gain.

Goals & Targeting

Targeted Sectors

Telecommunications
Government
Defense
Financial services
Non profit
Education
Energy
Critical infrastructure
Aerospace
Pharmaceutical
Maritime
Media
Think tank
Information technology
Healthcare
Gaming
Legal services
Hospitality
Aviation
Transportation

Targeted Countries / Regions

CN
US
RU
KP
JP
IL
BR
AU
VN
IN
CA
GB
DE
UA
KR
TW
BY

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 days ago

Executive Summary

LIMINAL PANDA is a China‑linked APT that specialises in infiltrating global telecommunications networks for SIGINT collection. The group utilizes weak passwords, custom backdoors and telecom‑specific emulation tools to spread laterally and exfiltrate subscriber data while remaining under the radar. Their operations demonstrate high technical sophistication with an emphasis on persistence, covert C2 and exploitation of known CVEs.

Goals & Targeting

The actor's strategic goal is to acquire signals intelligence from telecommunications payloads, including subscriber data, call metadata and other mission‑critical information. By leveraging weak passwords and exploitable vulnerabilities they infiltrate partner networks, pivot through trusted relationships (telecom vendors, cloud services) and establish multiple layers of persistence and command‑and‑control. Their targeting profile spans nearly every global telecom operator and is extended to any organisation that shares interfaces or contractual obligations with affected carriers.

Enhanced Description

Key Capabilities

  • Targeted telecommunications organisations globally
  • Compromised Linux‐based systems primarily
  • Interacted with Windows when required
  • Custom backdoors such as PingPong and TinyShell
  • Emulated signalling protocols using SIGTRANslator and sgsnemu2 SGSN emulator
  • Lateral spread through telecom architectures (eDNS servers, GPRS networks)
  • OPSEC via tampering legitimate binaries and hiding firewall rules with an iptables wrapper
  • Multi‑layered Remote Access Mechanisms using custom backdoors and proxy chains
  • Persistence by modifying SysVinit/init.d scripts
  • Scheduled time‑bound execution windows (02:15‑02:45 UTC daily)
  • Capability to fingerprint telecom hardware and build architecture‑specific binaries
  • Exploitation of known CVEs for initial access or privilege escalation

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Persistence
Defense Evasion
Discovery
Lateral Movement
Command And Control

ATT&CK Techniques

T1110.001
T1021.004
T1546
T1027.002
T1059.003
T1046
T1071
T1090
T1053.005
T1068
T1560.001
T1003
T1014
T1114
T1071.004
T1542.003
T1204.002
T1566.002
T1566.001
T1040
T1091
T1045
T1505.003
T1552.004
T1059
T1070
T1584.005
T1102
T1598.002
T1041
T1547.001
T1199
T1090.003
T1059.004
T1078
T1571
T1486
T1203
T1070.004
T1065
T1533

Software / Tooling

PingPong backdoor
TinyShell
SIGTRANslator
CordScan
sgsnemu2 SGSN emulator
ProxyChains
iptables wrapper binary
Custom PowerShell scripts
Cobalt Strike (used by adversary)

Campaigns & Victims

LIMINAL PANDA’s activities exhibit a disciplined, long‑term campaign model rather than opportunistic intrusions. The actor has repeatedly compromised major telecom operators in South Asia and Africa, using trusted vendor connections to expand their reach. Their infrastructure leverages commercial cloud hosts (e.g., Vultr) to host C2 nodes and employs chained proxies to obfuscate traffic. Operations tend to occur during off‑peak hours, with daily execution windows tied to specific UTC times. Victim sectors extend beyond telecoms to any organisation connected through shared services or partnerships, especially those providing critical communication infrastructure.

IOC Patterns

  • Weak password spraying (e.g., 'huawei')
  • SSH access to external DNS servers in GPRS networks
  • Execution of a custom backdoor binary /usr/bin/pingg
  • Modification of init scripts (/etc/rc.d/init.d/) for persistence
  • Deployment of an iptables wrapper binary with SHA256 97d4c9b5...
  • Proxy configuration files specifying chained SOCKS5 proxies
  • C2 server hosted on Vultr IP ranges
  • Scheduled script execution between 02:15‑02:45 UTC daily

Recommended Actions

  • Enforce MFA and strong password policies for telecom services, especially SSH to external DNS servers.
  • Implement host‑based intrusion detection that flags unexpected binary tampering (e.g., iptables wrappers) and monitors changes in system init scripts.
  • Apply network segmentation to isolate eDNS components from internal networks and restrict unnecessary protocols such as GTP or external DNS traffic.
  • Deploy endpoint protection capable of detecting custom backdoors like PingPong and TinyShell, including file integrity monitoring for /usr/bin and /etc directories.
  • Enable comprehensive logging on C2 channels and set alerts for unusual tunneling activity involving ProxyChains, SOCKS5 proxies or commercial VPS endpoints.
  • Conduct regular audits of CVE‑2021‑3156, CVE‑2021‑4034 and other critical kernel vulnerabilities in Linux systems used within telecom infrastructure.
  • Review and tighten trust relationships with third‑party vendors to reduce lateral movement vectors.
  • Schedule periodic checks for scheduled tasks/scripts that may run during known execution windows (02:15‑02:45 UTC).

Suggested Tags

Telecommunications Sector
China-linked Threat Actor
Lateral Movement via Telecom Infrastructure
Custom Backdoor
Credential Stuffing – Password Spraying
Defense Evasion – Binary Tampering
Command And Control – Custom Protocol
Persistence Mechanism – Init Scripts
iptables Manipulation
Public Proxy Tools used for C2
Liminal Panda
SGSN Emulation
CordScan
ProxyChains
Vultr IP
CVE Exploitation
Signals Intelligence
External DNS Compromise

Confidence Assessment

The available information provides a coherent picture of LIMINAL PANDA’s tactics, techniques and procedures focused on telecommunications networks, but it is largely derived from a single public report and supplementary observations. While the core capabilities are well‑documented, details such as exact campaign chronology, full toolchain spectrum, and broader victim reach remain incomplete. Further intelligence would refine operational timelines, supply chain influences and potential expansion into other sectors.

ATT&CK Techniques

Discovery
1 technique
Exfiltration
1 technique
Reconnaissance
1 technique
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 3 IPv4 Address 9 SHA-256 Hash 8

References

  1. apt.etda.or.th — Cited by web research for: the LightBasin activity cluster
  2. www.picussecurity.com — Cited by web research for: T1071.001
  3. learn.microsoft.com — Cited by web research for: Winnti
  4. www.crowdstrike.com — Cited by web research for: ProxyChains
  5. unit42.paloaltonetworks.com — Cited by web research for: GTPDOOR
  6. www.crowdstrike.com — Cited by web research for: Defense

Intel Summary

50

Techniques

48

Tools

0

Campaigns

39

IOCs

0

Observed Data

15

Tactics

Tags

APT
Data Exfiltration
espionage
telecommunications
SIGINT
Telecommunications Sector
China-linked Threat Actor
Lateral Movement via Telecom Infrastructure
Custom Backdoor
Credential Stuffing – Password Spraying
Defense Evasion – Binary Tampering
Command And Control – Custom Protocol
Persistence Mechanism – Init Scripts
iptables Manipulation
Public Proxy Tools used for C2
Liminal Panda
SGSN Emulation
CordScan
ProxyChains
Vultr IP
CVE Exploitation
Signals Intelligence
External DNS Compromise

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.