logo

Arctic Wolf Observes Threat Campaign Targeting Palo Alto Networks Firewall Devices

ID: 5147a6ab-c1ae-5d13-b086-ceb3cc8de750

STIX ID: report--5147a6ab-c1ae-5d13-b086-ceb3cc8de750

Feed Name: Arctic Wolf

Threat Score
78/100

Date Published: 2024-11-22

Date Updated: 2026-07-25

Author: Julian Tuin, Stefan Hostetler, Jon Grimm, Aaron Diaz, and Trevor Daher

...
...

Arctic Wolf Labs observed rapid mass exploitation of two PAN-OS vulnerabilities (CVE-2024-0012 and CVE-2024-9474) following public technical disclosures; attackers chained an authentication bypass and a privilege escalation to achieve remote code execution on Palo Alto firewall devices, resulting in command injection, exfiltration of configuration and credential files, deployment of Sliver C2 frameworks and PHP webshells, and installation of XMRig coinminers. The report provides exploitation log samples, lists observed IoCs (IP addresses, URLs, a SHA256 hash), maps TTPs to ATT&CK techniques, and outlines detection and remediation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.