Rare malware used to target telcos across three continents
A rare piece of malware has been observed targeting telecommunications providers across three continents.
Cybersecurity researchers from SentinelOne recently discovered a novel malware, dubbed LuaDream, on infrastructure belonging to telcos in the Middle East, Western Europe, and the South Asian subcontinent.
What makes this malware unique is that it leverages a just-in-time (JIT) compiler for the Lua programming language, dubbed LuaJIT. Lua is not exactly a popular choice among hackers, with malware written in this language only observed three times in the past ten years, The Hacker News reports. That includes Flame, Animal Farm (AKA SNOWGLOBE), and Project Sauron.
Advanced threat actors
LuaDream is a modular, multi-protocol backdoor, containing 13 core and 21 support components, the researchers further explained. Its main goal is to steal system and user information and run additional plugins – including command execution.
Considering the victim organizations, the endpoints on which the malware had been found, the rare choice of programming language, and the type of data LuaDream looks to exfiltrate, the researchers speculate that the work is a “well-executed, maintained, and actively developed project of a considerable scale.” The attackers, who are unknown at the time, have gone to considerable lengths to stay out of sight, it was said.
The malware was detected in August 2023, but the source code references a June 2022 date, leading the researchers to believe the malware was being prepared for more than a year.
When it comes to the identity of the attackers, while inconclusive, some evidence points to Chinese actors. A separate SentinelOne report discusses “strategic” Chinese intrusions in Africa, some of which were against telecommunications providers. These were part of activity clusters named Backdoor Diplomacy, Earth Estries, and Operation Tainted Love. The latter – Operation Tainted Love – allegedly shares the same threat actor with LuaDream activity.
“Targeted intrusions by the BackdoorDiplomacy APT and the threat group orchestrating Operation Tainted Love indicate a level intention directed at supporting [China in its efforts to] shape policies and narratives aligned with its geostrategic ambitions, establishing itself as a pivotal and defining force in Africa’s digital evolution,” security researcher Tom Hegel said.
More from TechRadar Pro
A rare piece of malware has been observed targeting telecommunications providers across three continents. Cybersecurity researchers from SentinelOne recently discovered a novel malware, dubbed LuaDream, on infrastructure belonging to telcos in the Middle East, Western Europe, and the South Asian subcontinent. What makes this malware unique is that it leverages…
Recent Posts
- UK will ban social media for children under 16
- Under-16 social media ban announced by UK government
- Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting
- Bose, Apple, Sonos & Sennheiser: 6 EOFY headphone deals I’d actually recommend as an audio-gear expert
- Is using a VPN legal in the USA, Canada and Mexico? What World Cup travelers need to know
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023