logo

An Investigation Into Years of Undetected Operations Targeting High-Value Sectors

ID: 39d998e2-29d2-572c-b27a-c4fd2b0be6d1

STIX ID: report--39d998e2-29d2-572c-b27a-c4fd2b0be6d1

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2026-03-06

Date Updated: 2026-04-28

Author: Tom Fakterman

...
...

Since at least 2020 Unit 42 has tracked CL-UNK-1068, a Chinese‑language threat cluster targeting critical sectors across South, Southeast and East Asia; the report details a multi‑platform espionage toolkit (web shells like GodZilla/AntSword, DLL side‑loading using Python binaries, custom ScanPortPlus scanner, custom FRP tunneling with unique tokens/passwords, Xnote backdoor), credential‑theft and exfiltration methods, exploitation of PwnKit (CVE‑2021‑4034) and CVE‑2023‑34048, and provides comprehensive IOCs (hashes, IPs) and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.