Threat Brief: Operation MidnightEclipse, Post-Exploitation Activity Related to CVE-2024-3400 (Updated May 20)
ID: 8ad6d5ac-ee65-54e4-9086-c35591ec0f49
STIX ID: report--8ad6d5ac-ee65-54e4-9086-c35591ec0f49
Feed Name: Palo Alto Networks Unit 42
Unit 42 and Palo Alto Networks describe active exploitation of CVE-2024-3400 — a critical (CVSS 10.0) command injection in PAN-OS affecting GlobalProtect-configured firewalls — observed in Operation MidnightEclipse. Attackers attempted to deploy a custom Python backdoor (UPSTYLE), resorted to a cron-based backdoor when installation failed, exfiltrated configuration files, and used remote bash retrieval commands; the brief includes IOCs, XQL hunting queries, and mitigation guidance including hotfixes and threat prevention signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
