How Akamai ExAR Contained a LATAM Supply Chain Attack

Источник: Akamai

How Akamai ExAR Contained a LATAM Supply Chain Attack

Source: Akamai

Learn how Akamai ExAR helped contain a complex supply chain intrusion targeting Linux, OpenShift, and Windows DMZ workloads in Latin America.

•Updated: October 6, 2026

October 06, 2026

  • Observed attack sequence C2 establishment Internal reconnaissance Additional backdoor activity
  • C2 establishment
  • Internal reconnaissance
  • Additional backdoor activity
  • How ExAR connected the signals A structured incident summary communicates early findings and recommendations to the customer
  • A structured incident summary communicates early findings and recommendations to the customer
  • How deception could add protection
  • How microsegmentation reduces risk
  • Building a proactive defense model
  • Recommendations for security leaders

Key takeaways

Akamai Guardicore Segmentation’s Exposure Analysis and Response (ExAR) detected and investigated a multistage intrusion affecting supply chain infrastructure in Latin America (LATAM). The complex intrusion was targeting Linux, OpenShift, and Windows DMZ workloads before significant operational disruption occurred.

By correlating workload-level process telemetry, network flows, and threat intelligence, ExAR's AI threat investigator — combined with human security analysts — connected disparate attack signals and rapidly attributed command and control (C2) infrastructure to the Sliver framework.

Integrating AI-driven threat correlation, human expert analysis, strict policy enforcement, and deception technologies (decoys and lures) provides high-fidelity early detection and effectively constrains attacker progression.

Akamai ExAR detected and investigated a multistage intrusion affecting supply chain infrastructure in LATAM. By correlating workload, process, network, and threat intelligence signals, ExAR helped the customer contain the incident before it developed into a broader operational security event.

Our investigation identified suspicious activity across Linux and OpenShift workloads, Windows systems in the DMZ, and network services. Observed behaviors included outbound C2 traffic, Active Directory enumeration, a separate socat listener, and inbound connections from malicious external infrastructure.

ExAR connected these signals within the context of the customer's segmentation policies. This context helped analysts assess which communications were expected, which paths were permitted, and where the activity deviated from the intended network design.

Within ExAR, our AI threat investigator accelerated initial correlation and reporting. Human analysts then expanded the investigation, examined the affected web server, identified evidence supporting the likely initial access vector, and enriched the C2 infrastructure with threat intelligence.

This incident illustrates how microsegmentation combined with threat intelligence can constrain attack paths when appropriate policies are enforced. Guardicore deception technology was not deployed in this environment, but it could provide an additional high-fidelity detection layer if an attacker interacted with a decoy or lure.

Observed attack sequence

Our investigation found evidence that an adversary likely gained initial access through a web-facing application in the DMZ. Evidence from the affected web server and internal FTP logs supported the conclusion that exposed web endpoints were the likely route to remote code execution. After gaining access, the adversary progressed through several operational phases, including:

  • C2 establishment

C2 establishment

  • Internal reconnaissance

Internal reconnaissance

  • Additional backdoor activity

Additional backdoor activity

C2 establishment

The threat actor used BASH TCP socket redirection from a Linux or OpenShift host to establish interactive reverse shells with external infrastructure associated with the Sliver C2 framework. A continuous reconnection loop attempted to restore connectivity after session interruptions.

Internal reconnaissance

Operating under a standard service account, the adversary used `net ads search` to enumerate Active Directory users and identify potential high-value targets.

Additional backdoor activity

On a separate host, analysts observed a socat process listening on nonstandard ports and spawning interactive BASH sessions. This provided an additional access mechanism independent of the primary C2 channel, although persistence across reboots or service restarts was not established.

Analysts also observed inbound FTP and SSH connections originating from confirmed malicious IP addresses, as well as anomalous inbound traffic targeting an NTP service. These findings broadened the investigation beyond the initially compromised host (Figure 1).

How ExAR connected the signals

In retrospect, the attack sequence appears linear: compromise a web application, establish C2, conduct reconnaissance, and attempt to expand access. During the incident, however, the evidence appeared as separate signals across different infrastructure types:

  • Suspicious outbound connections from a Linux or OpenShift workload

Suspicious outbound connections from a Linux or OpenShift workload

  • A socat listener on another host

A socat listener on another host

  • Malicious inbound connections to Windows DMZ systems

Malicious inbound connections to Windows DMZ systems

  • Anomalous NTP traffic

Anomalous NTP traffic

  • Unrestricted file access via a web endpoint

Unrestricted file access via a web endpoint

In this environment, existing endpoint coverage did not extend to every investigated surface, while network-only telemetry would not have provided the same process and user context.

ExAR correlated workload-level process telemetry, network flows, segmentation policy context, and threat intelligence. This allowed analysts to connect activity across the affected systems without relying solely on post-processing across separate data sources.

A structured incident summary communicates early findings and recommendations to the customer

The AI threat investigator organized the initial signals into a structured incident summary, helping the team communicate early findings and recommended actions to the customer while the investigation continued.

ExAR analysts then examined the suspicious web server, identified unrestricted file access and internal FTP logs that supported the likely initial access vector, and, through threat intelligence enrichment, associated the external infrastructure with Sliver C2.

The customer later confirmed that the detection and investigation by ExAR analysts were instrumental in containing an incident that could have caused significant operational disruption across its LATAM supply chain infrastructure.

How deception could add protection

Deception techniques were not deployed in this environment at the time of the incident but can add investigatory value to security operations or InfoSec teams. ExAR's behavioral detection, AI threat investigator, and human analysts identified and investigated the attack. This section describes how deception could have provided an additional layer of detection during reconnaissance and lateral movement.

After gaining execution on a host, an attacker commonly searches for credentials, services, systems, and trust relationships that could support privilege escalation or lateral movement. Deception introduces decoys and lures that can reveal this activity when an attacker interacts with them.

Unlike detections based only on known signatures or statistical anomalies, deception creates assets that legitimate users and applications should not need to access. Interaction with those assets can therefore produce a high-fidelity signal for investigation.

  • Decoy assets and synthetic credentials: Deception can place fake services, files, systems, and credentials alongside legitimate resources.

Decoy assets and synthetic credentials: Deception can place fake services, files, systems, and credentials alongside legitimate resources.

  • High-fidelity alerts: Port scanning, queries directed at a decoy identity service, or the use of a baited credential can generate an alert when the activity reaches a deployed decoy or lure.

High-fidelity alerts: Port scanning, queries directed at a decoy identity service, or the use of a baited credential can generate an alert when the activity reaches a deployed decoy or lure.

  • Controlled observation: If an attacker interacts with a decoy environment, security teams can observe tactics, techniques, and procedures while reducing exposure to production assets.

Controlled observation: If an attacker interacts with a decoy environment, security teams can observe tactics, techniques, and procedures while reducing exposure to production assets.

In this incident, deception techniques could have generated an additional alert context if the Active Directory enumeration or related discovery activity interacted with a deployed decoy or lure. The outcome would have depended on the placement and configuration of the deception assets.

How microsegmentation reduces risk

Attackers often use “living off the land” (LoTL) tools such as `net ads search` to identify users, systems, and potential paths toward sensitive identity infrastructure. In a flat or loosely segmented environment, a compromised internet-facing workload may have more access to internal services than its business function requires.

Akamai Guardicore Segmentation enforces granular communication policies around workloads and endpoints via positive security models. AI-assisted analysis can help teams understand observed activity and develop policy recommendations, while the segmentation policy provides the enforcement control plane.

  • Restrict identity access: Linux and OpenShift workloads in the DMZ can be limited to required operational endpoints. When policy does not authorize access to domain controllers or other identity services, those connections can be blocked.

Restrict identity access: Linux and OpenShift workloads in the DMZ can be limited to required operational endpoints. When policy does not authorize access to domain controllers or other identity services, those connections can be blocked.

  • Control egress: Outbound policies can block unauthorized connections to external C2 infrastructure, including reverse-shell traffic, when the destination, port, or communication path is not permitted.

Control egress: Outbound policies can block unauthorized connections to external C2 infrastructure, including reverse-shell traffic, when the destination, port, or communication path is not permitted.

  • Contain east-west movement: Explicit policies between DMZ tiers and internal zones limit a compromised workload to permitted communication paths. In this incident, segmentation context also helped analysts assess which lateral movement routes were technically available and which were blocked by policy.

Contain east-west movement: Explicit policies between DMZ tiers and internal zones limit a compromised workload to permitted communication paths. In this incident, segmentation context also helped analysts assess which lateral movement routes were technically available and which were blocked by policy.

Building a proactive defense model

This incident shows the value of combining detection with network policy context. ExAR correlated signals across Linux and OpenShift workloads, Windows DMZ systems, LoTL tools, and network services into a single incident narrative.

Microsegmentation helped define and constrain permitted attack paths. Deception, if deployed and engaged by the adversary, could have added another high-fidelity signal during reconnaissance or lateral movement.

Recommendations for security leaders

To prevent similar attacks and build a proactive defense, security leaders should focus on improving visibility, limiting lateral movement, and speeding up response times. The following strategic actions will help strengthen your security stance across all environments:

  • Identify coverage gaps across workloads, endpoints, network communications, and legacy infrastructure. In this environment, ExAR provided workload and process context on attack surfaces where existing endpoint coverage was limited.

Identify coverage gaps across workloads, endpoints, network communications, and legacy infrastructure. In this environment, ExAR provided workload and process context on attack surfaces where existing endpoint coverage was limited.

  • Employ positive security for ringfencing internet-facing application workloads. Only permit required access to internal identity services and approved external destinations.

Employ positive security for ringfencing internet-facing application workloads. Only permit required access to internal identity services and approved external destinations.

  • Use deception techniques as an additional detection layer. Properly placed decoys and lures can generate high-fidelity alerts when adversaries interact with them.

Use deception techniques as an additional detection layer. Properly placed decoys and lures can generate high-fidelity alerts when adversaries interact with them.

  • Combine AI-assisted correlation with human investigation. AI can accelerate triage and synthesis, while experienced analysts validate evidence, investigate context, and guide containment decisions.

Combine AI-assisted correlation with human investigation. AI can accelerate triage and synthesis, while experienced analysts validate evidence, investigate context, and guide containment decisions.

About the Author(s)

Dennis Birchard

Dennis Birchard is a cybersecurity and business development leader with more than 20 years of experience helping large enterprises manage cyber risk. His work focuses on security architecture (cloud and on-prem), Zero Trust enforcement, pre- and post-merger integration where operational complexity, regulatory pressure, and real-world threats collide. Dennis brings a practitioner’s perspective to strategy, translating architectural rigor into controls that hold up during M&A, regulatory scrutiny, and active threat scenarios.

João Dejavite

João Dejavite is a cybersecurity professional specializing in threat hunting, security operations, penetration testing, threat intelligence, and incident investigation. He focuses on identifying sophisticated threats, analyzing attacker behavior and infrastructure, and turning security telemetry and intelligence into actionable insights. With extensive hands-on experience in enterprise security environments, João is passionate about proactive threat detection, security research, and helping organizations strengthen their security posture.

Tags

These findings suggest an active ecosystem capable of supporting multiple monetization and attack strategies simultaneously.

Research

When Productivity Extensions Become Attack Platforms

Our research uncovered a campaign of 32 malicious browser extensions that uses remote configs to spy on 9,800+ users and hijack browsing activity.

This campaign took a different approach. Instead of impersonating products, it impersonated credibility.

Security Research

Crypto Scam Extensions Masquerade as High-Profile Investors

Learn how threat actors use crypto scam extensions that impersonate high-profile investors to steal wallets via evasive split-behavior phishing infrastructure.

Sharing vital threat intelligence allows the broader security community to stay one step ahead of emerging threats.

Research

Akamai Joins Athena Coalition to Shield Users from New Vulnerabilities

Akamai joins Chainguard’s Athena Coalition, verifying that Akamai App & API Protector customers are automatically shielded from newly disclosed vulnerabilities.

What this article says

Something is unclear? Ask about the article — I will explain in plain words.

Do not want to dig deeper? We will sort it out for you.