logo

Arctic Wolf Observes Threat Campaign Targeting Palo Alto Networks Firewall Devices

ID: 8319ac03-e106-54ed-8e79-5577ac523a94

STIX ID: report--8319ac03-e106-54ed-8e79-5577ac523a94

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2024-11-22

Date Updated: 2026-07-25

Author: Julian Tuin, Stefan Hostetler, Jon Grimm, Aaron Diaz, and Trevor Daher

...
...

Arctic Wolf Labs observed a mass exploitation campaign targeting PAN-OS management interfaces that chained CVE-2024-0012 (authentication bypass) with CVE-2024-9474 (privilege escalation) to gain administrative and root access to Palo Alto firewall devices; actors downloaded payloads via curl/wget (notably Sliver C2 and UPX-packed Sliver payloads), deployed an obfuscated PHP webshell and XMRig coinminer, staged and exfiltrated firewall configuration and credential files, and left multiple IoCs and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.