Monday, April 28, 2025
Homecyber securityThreat Actors Using Ephemeral Port 60102 for Covert Malware Communications

Threat Actors Using Ephemeral Port 60102 for Covert Malware Communications

Published on

SIEM as a Service

Follow Us on Google News

Recent cybersecurity investigations have uncovered a sophisticated technique employed by threat actors to evade detection during malware distribution.

Attackers are leveraging ephemeral port 60102, typically reserved for temporary communications, as a service port for covert malware transmission.

This approach bypasses traditional monitoring systems, which often focus on scanning standard service ports such as 80 or 443.

- Advertisement - Google News

Unconventional Port Usage in Malware Distribution

The attack begins with a successful password-guessing attempt, granting attackers access to a target system.

Once inside, the malicious actor executes commands to download malware from a remote server via HTTP using port 60102.

Tools like curl, wget, and direct TCP connections are employed to ensure the payload is retrieved, even if one method fails.

The server hosting the malwareidentified as an IP address based in Shanghai and owned by Tencent Cloud Computing Co., Ltd. has remained undetected by automated scanning tools like Shodan and GreyNoise due to its use of this nonstandard port.

Covert Malware Communications
Excerpt from cowrie JSON log detailing successful password guessing attack from source IP 8.133.192.98.

Challenges in Detection and Mitigation

The use of ephemeral ports for HTTP traffic poses significant challenges for cybersecurity professionals.

Automated scanners like Shodan typically scan a predefined list of ports, which does not include port 60102.

Snapshot of HTTP service responses on nonstandard ports. Sourced from Shodan query for IP 220.180.76.126

Similarly, GreyNoise relies on honeypots to detect malicious activity but may not capture attacks targeting specific systems.

According to ISC, this gap in detection allows threat actors to operate under the radar, using these ephemeral ports as temporary conduits for malware distribution.

Analysis of the attack revealed that the malicious server does not exhibit continuous malicious behavior but serves as a passive repository for malware files.

This intermittent activity further complicates identification and classification efforts.

Additionally, the use of nonstandard ports suggests that attackers have customized their infrastructure to evade conventional detection mechanisms.

To counter this emerging threat, organizations should implement robust security measures:

  • Restrict Network Traffic: Limit inbound and outbound connections to authorized addresses and block HTTP traffic over unconventional ports like 60102.
  • Enhance Credential Security: Enforce strong password policies, remove unused accounts, and disable root login via SSH to mitigate brute force attacks.
  • Monitor Anomalous Connections: Use intrusion detection systems (IDS) or intrusion prevention systems (IPS) to flag unusual protocol-port pairings. Tools like Censys’s Universal Internet DataSet can aid in identifying nonstandard port usage.
  • File Download Monitoring: Track file downloads from untrusted sources and inspect encrypted traffic where possible.

While these measures can mitigate current threats, the increasing use of ephemeral ports for malicious purposes underscores the need for continuous vigilance.

Cybersecurity professionals must adapt their strategies and leverage advanced tools to detect and respond to such sophisticated tactics effectively.

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...

Fog Ransomware Reveals Active Directory Exploitation Tools and Scripts

Cybersecurity researchers from The DFIR Report’s Threat Intel Group uncovered an open directory hosted...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

RansomHub Ransomware Deploys Malware to Breach Corporate Networks

The eSentire’s Threat Response Unit (TRU) in early March 2025, a sophisticated cyberattack leveraging...

19 APT Hackers Target Asia-based Company Servers Using Exploited Vulnerabilities and Spear Phishing Email

The NSFOCUS Fuying Laboratory’s global threat hunting system identified 19 sophisticated Advanced Persistent Threat...

FBI Reports ₹1.38 Lakh Crore Loss in 2024, a 33% Surge from 2023

The FBI’s Internet Crime Complaint Center (IC3) has reported a record-breaking loss of $16.6...