FirewallFalcon Manager presents itself as a free, open-source tool for managing Linux servers, VPN services and proxy infrastructure. Researchers now warn that the software hides a backdoor that can give attackers extensive control over systems where it is installed.
The tool has been promoted through Telegram channels to VPN resellers and so-called Free Internet operators. These services often help users bypass mobile data restrictions, particularly across parts of the Middle East and Africa.
Although the software provides working management features, its hidden components can expose operators to serious security risks.
Tool targets VPN and tunnel operators
FirewallFalcon Manager offers features that resemble legitimate server administration software. Its public code can manage services such as Nginx, HAProxy, DNS tunnelling, SSL certificates and Linux user accounts.
That functional design helps the tool appear trustworthy. However, researchers found that it contains a sophisticated attack chain beneath its polished menus and public repository.
The campaign appears to focus on people who operate or resell SSH and VPN tunnelling services. These tools can support legitimate connectivity needs, but criminals can also use them to hide traffic or evade detection.
Researchers described this market as a grey area. Operators may install tools with elevated permissions while doing little or no code review, making them attractive targets for supply-chain attacks.
Hidden changes can redirect traffic
The most serious risk appears when an operator installs the tool’s DTunnel-related component. Researchers said the malicious software can redirect network requests that should reach a legitimate subscription-validation server.
It does this by adding a fraudulent certificate and changing where traffic is sent. These actions can place the attacker between the victim’s system and the intended service.
As a result, the attacker may be able to intercept connections without the operator noticing. The malicious changes can also provide a route to root-level control of the affected infrastructure.
This is particularly dangerous for organisations or resellers that manage multiple servers. A compromise at the administration layer could give an attacker access to a wider network of users and services.
Telegram promotion helped the operation spread
Researchers found FirewallFalcon Manager promoted in two Telegram groups with thousands of members. They also identified more than 650 live servers connected to the broader operation.
The campaign shows that supply-chain threats do not only affect popular software projects. Attackers can also target smaller and less visible communities where trust, convenience and free access encourage rapid adoption.
A tool does not become safe simply because it has a public code repository or useful features. Operators should verify who maintains a project, review privileged installation scripts and monitor configuration changes after deployment.
Conclusion
FirewallFalcon Manager demonstrates how a convincing open-source tool can conceal a serious backdoor. VPN operators and server administrators should avoid installing unverified tools with root privileges and review their systems for unexpected certificates, traffic changes and unauthorised configuration files.


0 responses to “FirewallFalcon Manager Hides Backdoor in Free VPN Tool”