Network Security

FirewallFalcon tool found hijacking network traffic

As reported by Cyber Insider, a free Linux server management tool called FirewallFalcon has been discovered secretly hijacking network traffic, giving its developer unauthorized control over installed systems. This tool, primarily promoted to VPN resellers and operators of "free internet" services, combines legitimate functions with malicious components, according to Flare researchers.

Researchers identified that FirewallFalcon Manager secretly redirects traffic, weakens server security, and in older versions, installs a universal SSH backdoor. The campaign was uncovered by Flare cybersecurity researcher Assaf Morag after a honeypot server was compromised and used to deploy FirewallFalcon. The tool is advertised as an open-source solution for managing VPN, proxy, and SSH tunneling infrastructure, targeting operators in emerging markets.

A critical component, DT Tunnel, is modified to redirect traffic to an IP address controlled by the FirewallFalcon operator. This is achieved by adding a custom root certificate and altering the /etc/hosts file, creating a man-in-the-middle position. Earlier versions were more aggressive, collecting server information and creating privileged SSH accounts. Flare highlighted how such software supply chain attacks can infiltrate underground ecosystems, urging administrators to be cautious of tools that modify system settings and communicate with external servers.

Source: Cyber Insider

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds