Arctic Wolf Observes Threat Campaign Targeting Palo Alto Networks Firewall Devices
ID: 6cfc66b3-e165-550e-b42b-04538a231fb9
STIX ID: report--6cfc66b3-e165-550e-b42b-04538a231fb9
Feed Name: Arctic Wolf Blog
Threat Score
Arctic Wolf Labs observed multiple intrusions exploiting PAN-OS vulnerabilities CVE-2024-0012 and CVE-2024-9474 on Palo Alto firewall devices, enabling attackers to inject commands via the username field, download and persist payloads (Sliver C2, XMRig, obfuscated PHP webshells), exfiltrate firewall configs and credentials, and perform timestomping and history clearing; the report provides IoCs, ATT&CK mappings, detections, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
