Recent cybersecurity investigations have uncovered a sophisticated technique employed by threat actors to evade detection during malware distribution.
Attackers are leveraging ephemeral port 60102, typically reserved for temporary communications, as a service port for covert malware transmission.
This approach bypasses traditional monitoring systems, which often focus on scanning standard service ports such as 80 or 443.
The attack begins with a successful password-guessing attempt, granting attackers access to a target system.
Once inside, the malicious actor executes commands to download malware from a remote server via HTTP using port 60102.
Tools like curl
, wget
, and direct TCP connections are employed to ensure the payload is retrieved, even if one method fails.
The server hosting the malwareidentified as an IP address based in Shanghai and owned by Tencent Cloud Computing Co., Ltd. has remained undetected by automated scanning tools like Shodan and GreyNoise due to its use of this nonstandard port.
The use of ephemeral ports for HTTP traffic poses significant challenges for cybersecurity professionals.
Automated scanners like Shodan typically scan a predefined list of ports, which does not include port 60102.
Similarly, GreyNoise relies on honeypots to detect malicious activity but may not capture attacks targeting specific systems.
According to ISC, this gap in detection allows threat actors to operate under the radar, using these ephemeral ports as temporary conduits for malware distribution.
Analysis of the attack revealed that the malicious server does not exhibit continuous malicious behavior but serves as a passive repository for malware files.
This intermittent activity further complicates identification and classification efforts.
Additionally, the use of nonstandard ports suggests that attackers have customized their infrastructure to evade conventional detection mechanisms.
To counter this emerging threat, organizations should implement robust security measures:
While these measures can mitigate current threats, the increasing use of ephemeral ports for malicious purposes underscores the need for continuous vigilance.
Cybersecurity professionals must adapt their strategies and leverage advanced tools to detect and respond to such sophisticated tactics effectively.
Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free
The Tails Project has urgently released Tails 6.14.2, addressing critical security vulnerabilities in the Linux kernel…
Check Point Research (CPR) has uncovered a new targeted phishing campaign employing GRAPELOADER, a sophisticated…
A sophisticated cyber espionage campaign leveraging the newly identified BRICKSTORM malware variants has targeted European…
A recent report by Cyble has shed light on the evolving tactics of hacktivist groups,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released nine new advisories detailing severe…
Email security solutions are critical for protecting organizations from the growing sophistication of cyber threats…