Arctic Wolf Observes Threat Campaign Targeting Palo Alto Networks Firewall Devices
ID: 5147a6ab-c1ae-5d13-b086-ceb3cc8de750
STIX ID: report--5147a6ab-c1ae-5d13-b086-ceb3cc8de750
Feed Name: Arctic Wolf
Date Published: 2024-11-22
Date Updated: 2026-07-25
Author: Julian Tuin, Stefan Hostetler, Jon Grimm, Aaron Diaz, and Trevor Daher
Arctic Wolf Labs observed rapid mass exploitation of two PAN-OS vulnerabilities (CVE-2024-0012 and CVE-2024-9474) following public technical disclosures; attackers chained an authentication bypass and a privilege escalation to achieve remote code execution on Palo Alto firewall devices, resulting in command injection, exfiltration of configuration and credential files, deployment of Sliver C2 frameworks and PHP webshells, and installation of XMRig coinminers. The report provides exploitation log samples, lists observed IoCs (IP addresses, URLs, a SHA256 hash), maps TTPs to ATT&CK techniques, and outlines detection and remediation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
