logo

Fake Palo Alto GlobalProtect used as lure to backdoor enterprises

ID: 4f8a9e27-3eb3-5354-bc22-2a9cd476559a

STIX ID: report--4f8a9e27-3eb3-5354-bc22-2a9cd476559a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-08-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Targeted Fake GlobalProtect Malware Campaign:** Researchers at Trend Micro uncovered a targeted campaign against Middle Eastern organizations where attackers distribute a fake Palo Alto GlobalProtect installer that runs stealthily, checks for sandboxes, profiles victims, and communicates with freshly registered C2 domains (e.g., containing "sharjahconnect") using AES-encrypted traffic and Interactsh beacons; it supports remote PowerShell execution and file upload/download, enabling further lateral movement and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.