logo

Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant

ID: 29900d69-1711-5f49-a1e4-65884a3b1bd9

STIX ID: report--29900d69-1711-5f49-a1e4-65884a3b1bd9

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-09-02

Date Updated: 2026-04-28

Author: Mark Lim and Tom Marsden

...
...

Unit 42 describes an active WikiLoader (WailingCrab) campaign that uses SEO poisoning to serve spoofed GlobalProtect installers which sideload malicious DLLs, decrypt and inject shellcode, establish persistence, and communicate with C2 infrastructure (including MQTT brokers and compromised WordPress sites). The report details delivery and execution steps, anti-analysis and evasion techniques (DLL sideloading, encrypted shellcode, hashed VM checks, fake error dialogs), provides numerous IOCs (delivery URLs, C2 URLs, SHA-256 hashes), and supplies XQL hunting queries and mitigations for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.