logo

Zero-Day Exploitation of Unauthenticated Remote Code Execution Vulnerability in GlobalProtect (CVE-2024-3400)

ID: 9c315cb0-68c0-5e92-8e0c-f9c996a91d0b

STIX ID: report--9c315cb0-68c0-5e92-8e0c-f9c996a91d0b

Feed Name: Volexity Blog

Threat Score
95/100

Date Published: 2024-04-12

Date Updated: 2026-05-01

...
...

Volexity discovered active exploitation of a zero-day unauthenticated RCE in Palo Alto GlobalProtect (CVE-2024-3400) by a tracked actor UTA0218 that created reverse shells, installed a Python backdoor (UPSTYLE), established cron-based persistence, and rapidly moved laterally to exfiltrate firewall configurations, AD data (NTDS.DIT), DPAPI keys, and browser-stored credentials; the report provides technical analysis of the backdoor and post-exploitation scripts, infrastructure details, IoCs, and detection/response recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.