logo

Silent Skimmer Gets Loud (Again)

ID: aa69fab8-e932-56c4-8f8a-d1e1d68331eb

STIX ID: report--aa69fab8-e932-56c4-8f8a-d1e1d68331eb

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2024-11-07

Date Updated: 2026-04-28

Author: Veronika Senderovych, Chema Garcia and Zack Fink

...
...

Unit 42 observed a resurgence of the Silent Skimmer campaign in May 2024 where adversaries exploited one-day Telerik UI vulnerabilities to compromise web servers, install web shells and reverse shells, escalate privileges with GodPotato, and use loaders (RingQ) and Cobalt Strike to dump payment data; the attackers used a PyInstaller-compiled Python binary to query and exfiltrate payment records. The report provides detailed TTP analysis (including mixed-mode .NET assembly evasion and reverse-proxy tunneling), a long list of IOCs (hashes, IPs, domains, URLs), XQL detection queries, and mitigation recommendations including patching and defensive products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.