started · updated
FirewallFalcon tool found to contain malicious backdoors
Security researchers at Flare have discovered that FirewallFalcon, a free open-source Linux server management tool, contains malicious components designed to hijack network traffic and grant developers control over installed systems. The tool is primarily marketed via Telegram to operators in emerging markets, such as Africa and the Middle East, who manage VPN, proxy, and SSH tunneling infrastructure to bypass mobile carrier restrictions.
The campaign specifically targets the DT Tunnel component, a legitimate Brazilian commercial tunneling platform. FirewallFalcon intercepts subscription validation requests intended for DT Tunnel and redirects them to an attacker-controlled IP address. To facilitate this Man-in-the-Middle attack, the software installs a custom root certificate and modifies the system's hosts file to make the malicious server appear trustworthy.
Researchers identified at least 650 live servers connected to the infrastructure. Earlier versions of the tool were found to be even more invasive, using obfuscated installation programs to collect server information and transmit it via Telegram, and in some cases, installing a universal SSH backdoor.