Arctic Wolf Observes Threat Campaign Targeting Palo Alto Networks Firewall Devices
ID: 8319ac03-e106-54ed-8e79-5577ac523a94
STIX ID: report--8319ac03-e106-54ed-8e79-5577ac523a94
Feed Name: Arctic Wolf
Date Published: 2024-11-22
Date Updated: 2026-07-25
Author: Julian Tuin, Stefan Hostetler, Jon Grimm, Aaron Diaz, and Trevor Daher
Arctic Wolf Labs observed a mass exploitation campaign targeting PAN-OS management interfaces that chained CVE-2024-0012 (authentication bypass) with CVE-2024-9474 (privilege escalation) to gain administrative and root access to Palo Alto firewall devices; actors downloaded payloads via curl/wget (notably Sliver C2 and UPX-packed Sliver payloads), deployed an obfuscated PHP webshell and XMRig coinminer, staged and exfiltrated firewall configuration and credential files, and left multiple IoCs and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
