216.73.216.233

Threat Campaign Targeting Palo Alto Networks Firewall Devices Observed

· Published 25/11/2024 16:01 · Modified 25/11/2024 17:28

Export JSON

Essential information

Published
25/11/2024 16:01
Modified
25/11/2024 17:28
Tags
2024-11-25 CVE-2024-0012 CVE-2024-9474 data exfiltration palo alto networks sliver c2 vulnerability exploitation webshells xmrig
Related entities
14 observables, 10 techniques (mitre), 2 malware

Description

Arctic Wolf has identified multiple intrusions across various industries involving Palo Alto Network firewall devices. The attacks likely exploit recently disclosed PAN-OS vulnerabilities and for initial access. Affected devices downloaded payloads including the framework and coinminer binaries. Threat actors injected malicious commands into firewall login attempts, deployed PHP , exfiltrated sensitive configuration files and credentials, and in some cases installed cryptocurrency miners. The campaign demonstrates rapid exploitation of newly disclosed vulnerabilities in perimeter devices. Defenders are advised to implement robust external monitoring, restrict management interfaces, and patch vulnerable systems promptly.

External references