Free Linux VPN Tool Turns Out to Be a Hidden Backdoor for Hackers

12.08.2026 4 minutes Author: Cyber Witcher

FirewallFalcon Manager, a free open-source tool promoted as a convenient way to manage Linux servers and VPNs, is actually hiding a sophisticated attack. Once installed, the software can give attackers full control over a user’s infrastructure while secretly redirecting network traffic.

FirewallFalcon Manager is being actively promoted through Telegram among VPN sellers and operators of so-called “free internet” services, which help users bypass restrictions imposed by mobile carriers. Such services are particularly widespread in the Middle East and Africa.

At first glance, the software does not appear particularly suspicious. It is presented as a free, open-source tool for managing Linux servers, VPN services, proxies, and network configurations.

However, Flare cybersecurity researcher Assaf Morag, who uncovered the scheme, found that a far more dangerous mechanism is hiding behind the polished GitHub repository and functional shell menus. According to Morag, it is a “multi-layered, well-hidden, and sophisticated attack” that effectively leads users to hand attackers full control over their own infrastructure.

FirewallFalcon falls into what could be described as a “gray area” of software. The tool is designed to manage SSH/VPN tunneling servers and is distributed within communities where VPN services and tools for bypassing network restrictions are sold.

Researchers found that communications related to FirewallFalcon most commonly used a mix of English and Arabic.

“It sits in a gray area between legitimate tunneling tools and infrastructure that is often used to bypass restrictions, and sometimes in cybercriminal operations,” Morag explained.

Tools like these can be used for entirely legitimate purposes. At the same time, cybercriminals can use them to conceal their real IP addresses or make malicious activity more difficult to trace.

Researchers believe the way FirewallFalcon is distributed suggests that at least 50% of its installations may have been used to conceal malicious activity and bypass security controls. This creates an unusual trap: a tool that hackers may use to hide their own activity can itself attack the people who install it.

FirewallFalcon’s functionality is not merely for show. Its open-source code genuinely allows users to manage Nginx, HAProxy, V2Ray/XRay, DNS tunneling, SSL certificates, and Linux user accounts. The fact that the software actually works as advertised helps make it appear trustworthy.

Morag discovered the campaign after one of his own honeypot servers was compromised and used to deploy FirewallFalcon.

“Behind the polished GitHub repository and feature-rich shell menus lies a multi-layered, well-disguised, and sophisticated attack,” the researcher warned.

The most serious threat appears when the DT Tunnel component is installed. This is where FirewallFalcon gains the ability to intercept network connections.

DTunnel is a legitimate Brazilian commercial VPN and tunneling service. Under normal circumstances, its software checks whether a customer’s subscription is valid by connecting to the proxy.dtunnel.com.br server.

FirewallFalcon interferes with this process and silently redirects those requests to a server controlled by the attacker.

To prevent the substitution from triggering obvious security warnings, the malicious tool installs a forged certificate, causing the computer to trust the attacker-controlled infrastructure.

At the same time, traffic that should be sent to the legitimate DTunnel server is redirected to the attacker’s server. From the user’s perspective, everything may appear to continue working normally.

Together, these mechanisms allow the attacker to quietly position themselves between the user and DTunnel’s servers. Morag describes this as a classic man-in-the-middle attack, in which an attacker intercepts and controls the connection between two parties.

The campaign has already grown beyond a handful of isolated infections. Researchers found FirewallFalcon being promoted in two Telegram groups with thousands of members combined. They also identified at least 650 active servers linked to the broader infrastructure behind the operation.

The FirewallFalcon case shows that software supply chain attacks are not limited to large and popular open-source projects. Similar schemes are also spreading through underground and “gray” markets, where users often install tools with root access without reviewing their code or even performing basic security checks.

In this case, the attacker did more than simply disguise malware as a useful application. They created a genuinely functional product that solves real problems for its target audience and is distributed for free to build trust.

As researchers point out, the software works, has a polished interface, and offers a real set of features. That is precisely what makes this type of scheme particularly dangerous, as users may have no reason to suspect for a long time that they have effectively installed a backdoor alongside a useful tool.

FirewallFalcon Manager demonstrates just how convincingly a malicious tool can disguise itself as a legitimate open-source product. Real functionality, free distribution, and active promotion through Telegram helped the software reach hundreds of servers, while its hidden mechanisms allow attackers to intercept traffic and gain control over other people’s infrastructure.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.