Press ESC to close

Arctic Wolf Observes Threat Campaign Targeting Palo Alto Networks Firewall Devices

AspectDetails
Threat ActorsUnknown cybercriminals exploiting CVE-2024-0012 and CVE-2024-9474 vulnerabilities.
Campaign OverviewExploitation of vulnerabilities in Palo Alto Networks firewalls to deploy malicious payloads, including Sliver C2 and coinminers.
Target Regions (Or Victims)Various industries affected globally.
MethodologyExploited vulnerabilities, downloaded malicious payloads over HTTP, and collected sensitive data.
Product TargetedPalo Alto Networks firewall devices running PAN-OS software.
Malware ReferenceSliver C2 framework, XMRig coinminer.
Tools Usedwget, curl, tar, cat, touch, PHP webshells.
Vulnerabilities ExploitedCVE-2024-0012 (admin access) and CVE-2024-9474 (privilege escalation) in PAN-OS.
TTPsInitial Access (T1190), Privilege Escalation (T1068), Credential Access (T1003.008), Defense Evasion (T1027, T1070).
AttributionNot yet attributed to specific threat actor groups.
RecommendationsMonitor firewall logs for unusual username activity.
SourceHendryadrian

Read full article: https://www.hendryadrian.com/arctic-wolf-observes-threat-campaign-targeting-palo-alto-networks-firewall-devices-arctic-wolf/

Disclaimer: The above summary has been generated by an AI language model

Leave a Reply

Your email address will not be published. Required fields are marked *