logo

Threat Brief: Operation MidnightEclipse, Post-Exploitation Activity Related to CVE-2024-3400 (Updated May 20)

ID: 8ad6d5ac-ee65-54e4-9086-c35591ec0f49

STIX ID: report--8ad6d5ac-ee65-54e4-9086-c35591ec0f49

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 and Palo Alto Networks describe active exploitation of CVE-2024-3400 — a critical (CVSS 10.0) command injection in PAN-OS affecting GlobalProtect-configured firewalls — observed in Operation MidnightEclipse. Attackers attempted to deploy a custom Python backdoor (UPSTYLE), resorted to a cron-based backdoor when installation failed, exfiltrated configuration files, and used remote bash retrieval commands; the brief includes IOCs, XQL hunting queries, and mitigation guidance including hotfixes and threat prevention signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.