CheckMesh: Hidden Threats in Your FW
2024-07-09 • Hackers Eye •
HackersEye describes an intrusion against an Israeli enterprise where an attacker used admin access to a Check Point firewall, moved from the GAIA web interface to SSH, and installed a malicious MeshAgent based ELF implant. The implant disguised itself as a legitimate process, gave the attacker encrypted C2 and persistence on the firewall Linux system, and let the actor operate as root. The attacker then used the firewall foothold for credential theft, password spraying or brute force activity, port forwarding, and RDP tunneling into internal systems. HackersEye says the TTPs resemble Cisco Talos reporting on LilacSquid, but the excerpt frames the attribution as similarity based rather than definitive.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | MeshAgent_Config | 2024-07-09 | 2024-07-09 |
| YARA | MeshAgent_ELF | 2024-07-09 | 2024-07-09 |
| HASH | 1134af27bea8518c62444a56f4bd4bc… | 2024-07-09 | 2024-07-09 |
| HASH | 3840acb15880f6cb0a77347d4a3893c… | 2024-07-09 | 2024-07-09 |
| HASH | 277e376f8e521b5127d45da965a5a43d | 2024-07-09 | 2024-07-09 |
| HASH | b1b15e09ea98228203e110456d51432… | 2024-07-09 | 2024-07-09 |
| DOMAIN | gupdate.net | 2024-07-09 | 2024-07-09 |
| DOMAIN | api.gupdate.net | 2024-07-09 | 2024-07-09 |
| IPv4 | 51.16.51.81 | 2024-07-09 | 2024-07-09 |
| IPv4 | 78.141.238.182 | 2024-07-09 | 2024-07-09 |