Skip to content
  Threat research

The 4307 Mirage

How one port anomaly exposed a much larger infrastructure.

After two actively exploited TrueConf vulnerabilities put TCP port 4307 in the spotlight, Attaxion researchers examined existing traffic telemetry to see what else was hiding behind the signal.

What the investigation uncovered

A large IPTV distribution ecosystem connected to the initial traffic signal
Related Android TV applications sharing infrastructure and a common codebase
Malware signals, reverse-tunneling infrastructure, and live-video services
Research window
June–August 2026
Data sources
Traffic, passive DNS & APK analysis
Researcher
Max Beatty

Download the full report

Get the complete investigation, evidence, methodology, and observables.

 
Key findings

One anomaly. Millions of observations.

What started as an unusual concentration of traffic on port 4307 quickly expanded into a much broader infrastructure investigation.

29.5%

One host stood out

A single IP appeared in 29.5% of the collected sample records involving TCP port 4307.

12.9M

Traffic records revealed

Pivoting on that host uncovered 12.9 million sampled traffic records across roughly 80 days.

162,908

Distinct source IPs

Nearly all were associated with consumer broadband or mobile networks.

3

Related Android apps

Verified CATMO, CATMOLIVE and VODTV samples shared a codebase, with several AV engines flagging them as Trojan-Proxy.

Why it matters

The anomaly was only the starting point.

The full investigation connects unusual port activity with a wider infrastructure footprint, large-scale source activity, and related Android applications — showing how a single observable can lead to a much broader threat picture.