logo

Discovering Splinter: A First Look at a New Post-Exploitation Red Team Tool

ID: 1b11c71f-1b8e-508d-8ce1-0484cb3a088b

STIX ID: report--1b11c71f-1b8e-508d-8ce1-0484cb3a088b

Feed Name: Palo Alto Networks Unit 42

Threat Score
60/100

Date Published: 2024-09-19

Date Updated: 2026-04-28

Author: Dominik Reichel

...
...

This report details the discovery and technical analysis of Splinter, a Rust-based post-exploitation/red-team tool found on customer systems; it describes the implant's configuration format, capabilities (remote command execution, module injection, file transfer, cloud info gathering, self-delete), C2 URL paths, a sample SHA-256 indicator, and detection/mitigation guidance from Palo Alto Networks, while noting no attribution to a specific threat actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.