CordScan is a custom telecommunications-focused network scanning and packet-capture utility associated with the China-linked intrusion cluster CL-STA-0969, which substantially overlaps activity tracked as Liminal Panda. It is designed for reconnaissance of mobile-core infrastructure, supporting TCP and ICMP scanning as well as telecom-specific GTP and SCTP protocol activity. CordScan can conduct Packet Data Protocol context scans against Serving GPRS Support Nodes and use mobile-subscriber and operator identifiers to identify subscribers and obtain subscriber metadata, including IMSI values and location-related information. Its use has been observed in long-term espionage-oriented compromises of telecommunications providers, particularly in Southeast and Southwest Asia during 2024. The utility reflects operator familiarity with mobile-network protocols and infrastructure and is used to support intelligence collection from telecom environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CordScan, a tool capable of scanning via TCP and ICMP as well as telecom-specific protocols like GTP and SCTP. CordScan can also perform Packet Data Protocol (PDP) context scans against Serving GPRS Support Nodes (SGSN), enabling the extraction of subscriber metadata and International Mobile Subscriber Identity (IMSI) numbers.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
CordScan can perform Packet Data Protocol (PDP) context scans against Serving GPRS Support Nodes (SGSN), enabling the extraction of subscriber metadata and International Mobile Subscriber Identity (IMSI) numbers.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used in telecom-focused espionage activity; described as capable of collecting location data from mobile devices and used alongside other remote-access tooling.
A network scanning and packet capture tool designed for telecom environments, extracting IMSI and operator data from SGSN nodes and logging results in .pcap files.
Custom network scanning and packet-capture utility used in telecom intrusions; described as capable of capturing common mobile telecom communication protocols (including SGSN) to support tracking/location-related collection.
Custom network scanning and packet-capture utility used in telecom intrusions; described as capable of capturing common mobile telecom communication protocols (including SGSN) to support tracking/location-related collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.