logo

Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices

ID: 65bf0bf0-06ae-55f7-850d-2a28edb6c48f

STIX ID: report--65bf0bf0-06ae-55f7-850d-2a28edb6c48f

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2024-05-15

Date Updated: 2026-05-01

...
...

Volexity reports discovery and investigation of active exploitation of CVE-2024-3400 targeting Palo Alto Networks GlobalProtect, observed initially from a China-linked actor (UTA0218) and later by other actors after proof-of-concept publication; the post details log- and memory-based detection methods, example malicious log entries and artifacts (including binaries like /tmp/vpn_prot and cron-based persistence), network monitoring guidance, and remediation recommendations such as applying patches and threat prevention signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.