1. X
  2. Unit 42
Log inSign up
Unit 42
3,024 posts
Image
user avatar
Unit 42
@Unit42_Intel
The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
unit42.paloaltonetworks.com
Joined December 2015
81
Following
69.9K
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    Unit 42
    @Unit42_Intel
    15h
    We analyzed an AI enabled hacking campaign by a Chinese-speaking threat actor. The adversary targeted infrastructure across seven vulnerabilities, combining autonomous AI driven enumeration with manual exploitation. Read our analysis: bit.ly/4xg1bP2
    Image
    2.9K
  • user avatar
    Unit 42
    @Unit42_Intel
    Jul 29
    15-plus risky Chrome productivity extensions bundle an SDK that turns a browser into a covert web-crawling proxy. No mention of crawling in CWS description but a limited disclosure as an opt-in popup after installation. Details at: bit.ly/4gZw3hK
    Screenshot of code in a text editor highlighting JavaScript functions. Annotations point to a URL being set for crawling and the injection of a hidden iFrame for crawling.
    This image shows a user interface with a "Terms of Service" agreement. It includes a checkbox option and a "Manage settings" button. Text highlights concerns about vague bandwidth sharing terms and deceptive opt-in form design. An example extension overview from the Chrome Web Store is shown, lacking information about the proxy service.
    Image
    Image
    5.5K
  • user avatar
    Unit 42
    @Unit42_Intel
    Jul 24
    Four evasion techniques deliver stealthy device code phishing: blob URLs evade network analyzers, custom CAPTCHA gates block URL scanners, SaaS multi-step flows bypass domain reputation checks, plus source-code evasion. Details at bit.ly/4wZQGPs
    The image shows a screenshot of a fake Microsoft document verification page. It includes a section for entering a verification code and button options for copying the code or signing in with code. On the right, there are code snippets labeled "Runtime decryption" and "Blob URL phishing delivery" related to the document.
    A screenshot displays a phishing attempt involving fake notifications. On the left, a message mimics "Ray Allen Manufacturing" with an encouragement to "VIEW PDF ONLINE," adding false legitimacy. On the right, there's a spoofed Microsoft sign-in request page asking for a device code and verification.
    A comparison image showing two CAPTCHA systems used in a phishing campaign. The custom build and fake reCAPCHA add legitimacy.
    The image shows a comparison between two HTML code examples, highlighting how Cyrillic characters can resemble Latin characters to evade source-code detection. The left example uses Cyrillic characters in the title and body of a webpage template, while the right example uses random characters. The examples show how this technique can affect scanners for brands.
    10K
  • user avatar
    Unit 42
    @Unit42_Intel
    Jul 24
    New #Rhadamanthys #infostealer campaign seen following Global Law Enforcement infrastructure takedown. Attackers impersonated the RingCentral site by using web pages illegally copied from the publicly-available legitimate RingCentral download site. More: bit.ly/3T8zxEV
    The image is a flowchart titled "Rhadamanthys Infection & Execution Tree." It outlines steps of a cyber infection process for Rhadamanthys malware.
    Fake RingCentral download page. The image features a call to action for downloading the RingCentral app for free, highlighting communication features. Buttons are available for downloading on Mac and Windows. A laptop displays a RingCentral interface, with a coffee cup and notebook nearby.
    This image shows a computer screen displaying a cybersecurity analysis tool. It includes a flowchart illustrating the execution path of "RingCentral.exe" and a concurrent Rhadamanthys payload. The interface lists details like actions, timing, and file paths, focusing on a DLL sideloading technique. Notable paths include a Krita.exe file. Red text highlights the evasion strategy.
    6.2K
  • user avatar
    Unit 42
    @Unit42_Intel
    Jul 23
    RubyGems cryptojacking campaign: 113-plus malicious RubyGems found delivering XMRig miners via trojanized libraries, using delayed persistence and direct launchers. Details at bit.ly/4frpVwd
    Screenshot of a programming script related to a crypto mining operation.
    Screenshot of a code editor showing HTML code with highlighted URL to a YouTube video.
    A computer screen displays lines of code and configuration details, including a URL to a GitHub repository and various network settings.
    This image shows a snippet of code for a Ruby gem specification.
    8.9K
  • See @Unit42_Intel's full profile

    Sign up
    Log in
Advertisement
Advertisement