Log inSign up
Unit 42
2,994 posts
Image
user avatar
Unit 42
@Unit42_Intel
The latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
unit42.paloaltonetworks.com
Joined December 2015
81
Following
69.2K
Followers
  • user avatar
    Unit 42
    @Unit42_Intel
    May 15, 2024
    2024-05-14 (Tuesday): #DarkGate activity. HTML file asks victim to paste script into a run window. Indicators available at bit.ly/4bjvMAC #TimelyThreatIntel #Unit42ThreatIntel #Wireshark #InfectionTraffic
    unknown source --> HTML file --> victim runs CMD script from HMTL file --> downloads & runs HTA file --> retrieves & runs PowerShell script --> Retrieves & runs Autoitv3 package for DarkGate --> DarkGate C2
    Browser window. HTML file. Victim pastes script into run window and runs it. Arrows point to each step in the process.
    Screenshots of Startup folder, Properties folder, ProgramData folder. DarkGate persistent on the infected host. Arrows point to each step.
    Infection traffic filtered in Wireshark. From top to bottom: Returned HTA file. Returned PowerShell script. Returned ZIP archive of AutoIt3 package for DarkGate. DarkGate C2 traffic.
    558K
  • user avatar
    Unit 42
    @Unit42_Intel
    Mar 14, 2025
    We have tested CVE-2025-24813. Under specific circumstances, an exploit sent to a vulnerable Apache web server running outdated Tomcat software could lead to remote code execution. We used a 2-step method that resulted in a successful attempt. Details at bit.ly/426Njtp
    Screenshot of a collage of windows in Wireshark explaining the exploit of CVE-2015-2483 on a vulnerable web server running Tomcat. It includes two steps illustrated with HTTP code examples: the first step shows an HTTP PUT request to send a malicious session file, and the second step shows an HTTP GET request with a customized cookie to deserialize the session file.
    A screenshot of the Apache Tomcat web server status page displaying various server details including version numbers for Tomcat and Java, memory pool statistics, and other server information. This is highlighted in a red box and indicated by an arrow. The Apache web server has an outdated version of Tomcat as well as Java.
    A screenshot of a computer terminal with a red arrow pointing to a file named "pan_is_here." The file is located in the `/tmp` directory of a server named `server1.wiresharkworkshop.online`. The terminal displays file permissions and ownership details for the files in the directory. Exploit allowed us to write a file with root permissions in the Apache web server's TMP directory.
    Screenshot of Wireshark HTTP stream windows. The first shows Step 1: HTTP PUT request to send malicious session file. Also tested this method on a vulnerable Apache web server with Tomcat running locally on a macOS system to open macOS calculator. Step 2 on the second HTTP stream window shows the HTTP GET request with a customized cookie.
    29K
  • user avatar
    Unit 42
    @Unit42_Intel
    Jul 19, 2025
    We are observing active global exploitation of critical Microsoft SharePoint vulns CVE-2025-49704 and CVE-2025-49706. Orgs worldwide are being targeted. Patch immediately. The exploits are real, in-the-wild and pose a serious threat. IoCs we've seen: bit.ly/4kQZS2e
    Image
    69K
  • user avatar
    Unit 42
    @Unit42_Intel
    Feb 9, 2021
    Today, we exposed "BendyBear," one of the most sophisticated, well-engineered and difficult-to-detect samples of shellcode employed by an APT, says the Unit 42 researcher who analyzed it. bit.ly/3aH1ABi
    Image
  • user avatar
    Unit 42
    @Unit42_Intel
    Feb 13, 2020
    🦈 Good news everyone! 🦈 @malware_traffic is back with another great #Wireshark tutorial - this one covers a recent infection with the information stealer Qakbot (aka Qbot).
    Image
    Wireshark Tutorial: Examining Qakbot Infections
    From unit42.paloaltonetworks.com
  • user avatar
    Unit 42
    @Unit42_Intel
    Nov 1, 2024
    Acting as digital detectives, we uncovered the sale of a bypass tool on underground forums. This investigation began when a bad actor tried to test an EDR bypass tool. Read what we learned from there: bit.ly/4eb8nlh
    Representation of malware displayed over a computer screen
    72K
  • user avatar
    Unit 42
    @Unit42_Intel
    Dec 7, 2023
    2023-12-07 (Thursday) - PDF file found on VirusTotal led to #DarkGate infection - Windows shortcut retrieved DarkGate install script from DNS TXT record - activity may have started as early as 2023-11-27 - IOCs available at bit.ly/47DoyFH #TimelyThreatIntel #Wireshark
    Screenshot of Adobe Acrobat. Red open button goes to URL indicated by arrow. Next, file downloads from OneDrive. Arrow points to zip file Passport2021023_90223.pdf.zip.
    Screenshot of PDF in Properties pane. Windows shortcut retrieved DNS text record, saved as taste.cmd and ran it.
    Wireshark screenshot. UPD stream. DNS record returned DarkGate install script.
    Wireshark screenshot. From top to bottom. HTTPS link to download initial ZIP. DNS text record returned install script. Install script retrieved decoy PDF and DarkGate files indicated in black box. DarkGate C2 traffic.
    42K
  • user avatar
    Unit 42
    @Unit42_Intel
    Oct 1, 2021
    Love our Wireshark Tutorials? We've just released five free Wireshark Workshop videos from @malware_traffic bit.ly/3CZQPqb
    Image
  • user avatar
    Unit 42
    @Unit42_Intel
    Apr 1, 2021
    In our latest Wireshark tutorial, we demonstrate how to prepare the environment, obtain a decryption key and use it to decrypt RDP traffic. bit.ly/3rCESAz
    Image
  • user avatar
    Unit 42
    @Unit42_Intel
    Oct 12, 2023
    2023-10-12 (Thursday): The latest example of #DarkGate malware distributed through Microsoft Teams. Attacker poses as target organization's CEO and sends victim a Teams invite. Message contains password-protected zip archive. IOCs available at bit.ly/3rY1hi1
    2023-10-12 (Thursday) DarkGate from Teams message. Teams chat invite & message > password-protected zip archive from Teams chat > extracted Windows shortcut > PowerShell commands from shortcut > HTTP traffic for Autolt3.exe and au3 file > Autolt3.exe runs .au3 file > HTTP traffic for encoded binary > encoded binary converted to DarkGate EXE > DarkGate HTTP C2 traffic
    Message that redacted email was added to group chat with warning they are outside of the org. Option to delete chat or accept. Message that includes attached zip file. Extracted file contents in Window zip preview pane.
    Wireshark traffic. DarkGate C2. Returned encoded binary. Returned .au3 file. Returned copy of autoit3.exe.
    Shortcut in Startup folder under Windows Start menu. Properties pane for dbhhfbh. Used for persistent DarkGate infection. Filepath of target file is in red.
    47K
  • user avatar
    Unit 42
    @Unit42_Intel
    Aug 29, 2024
    2024-08-28 (Wednesday): More #Lumma #Stealer (#LummaStealer) from pages instructing potential victims to copy/paste #PowerShell script in a Run window. Recent examples of these human captcha style pages available at bit.ly/4cJk0zq #Unit42ThreatIntel #TimelyThreatIntel
    A web page displaying a CAPTCHA verification interface with the message "Verify You Are Human" and a button labeled "I'm not a robot", which includes a checkbox and a stylized human hand cursor clicking on it.
    Image showing a computer screen with multiple open windows, including a browser window displaying a CAPTCHA verification, a PowerShell window with a script, and a translated segment providing instructions on pressing Windows + R keys. The taskbar shows various application icons.
    Fake human CAPTCHA page and file downloads indicated by red arrow. Screen capture of Wireshark interface showing network traffic log entries with timestamps, IP addresses, ports, and host names. The background is green with text in white and red. Lumma Stealer C2 indicated by red arrow.
    73K
  • user avatar
    Unit 42
    @Unit42_Intel
    Jan 17, 2023
    2023-01-16 (Monday) - Google ad led to fake software site sending malware. Post-infection activity for #Gozi (#ISFB/#Ursnif) and #RedlineStealer. Seeing this for different software searches. Indicators for an infection from a fake 7-Zip page available at bit.ly/3iQe8OH
    2023-01-16 (Monday): Malware from fake software sites: Google ad > fake 7-zip site > downloaded installer file > HTTPS traffic for 7-zip and various files > GPG-encrypted files decrypted to malware > 7-Zip installed with malware > follow-up activity: Redline Stealer, Gozi (ISFB/Ursnif), possible GongShell-related traffic, possible follow-up malware
    Red arrow points to the google ad
    Red arrows show the download options, followed by the Windows defender message that pops up after deciding to keep the file
    Wireshark pcap showing Google Ad, Fake 7-Zip page, MSI file download, traffic caused by MSI file, redline exe, redline C2, Gozi (ISFB/Ursnif) traffic, and unknown traffic, possible Cobalt Strike
    51K
  • user avatar
    Unit 42
    @Unit42_Intel
    Feb 8, 2023
    2023-02-07 (Tuesday): Among the wave of #Qakbot malspam, we found an email with a #OneNote attachment pushing probable #Matanbuchus malware. IoCs from an infection run available at bit.ly/3I7jGOF
    2023-02-07 (Tuesday): Probably Matanbuchus Activity: thread-hijacked email > attached OneNote file > embedded .cmd script file > HTTPS traffic for installer DLL > installer DLL runs > registry update & scheduled task created > HTTPS traffic for base64 text > base64 text converted to Matanbuchus DLL > HTTPS C2 traffic for Matanbuchus > scheduled task renews DLL every 13 minutes
    red arrows indicate OneNote attachment that leads to installer DLL for probable Matanbuchus. Red and black text shows the contents of in.cmd
    Scheduled task created by the installer DLL, recreates probable Matanbuchus DLL every 13 minutes, task runs PowerShell script from registry, script saved as base64 text, decoded script is shown. After running/loading, this DLL is changed to a decoy file
    Wireshark pcap showing traffic for installer DLL, initial traffic for base64 text to create Matanbuchus DLL, the point where Matanbuchus C2 traffic starts, and the traffic showing how the Matanbuchus DLL is recreated every 13 minutes
    63K
  • user avatar
    Unit 42
    @Unit42_Intel
    Jan 31, 2023
    2023-01-31 (Tuesday) - #Qakbot (#Qbot) returns after one month hiatus, now using OneNote (.one) files as initial lure. Saw #CobaltStrike on 104.237.219[.]36 using ciruvowuto[.]com as the domain. Also saw VNC traffic from this infection. IoCs available at bit.ly/3DqSszS
    2023-01-31 (Wednesday): Qakbot (Qbot) BB12 & Obama234 distribution tags: BB12 email > link for zip > downloaded zip > extracted OneNote file > embedded .hta file > traffic for Qakbot DLL > infection made persistent > Qakbot C2 traffic > post-infection activity - Cobalt Strike, VNC traffic. An obama 234 email with an attached OneNote file also leads to an embedded .hta file, and then a similar flow from there.
    Wireshark pcap shows Zip-ed OneNote file, DLL for Qakbot and Qakbot C2 traffic
    Wireshark pcap shows Qakbot C2 traffic and Cobalt Strike traffic
    VNC traffic from Qakbot-infected host
    42K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement