It Was Not Me! Malware-Initiated Vulnerability Scanning Is on the Rise
ID: bb913e13-1a8c-5db4-9872-37b9c457251a
STIX ID: report--bb913e13-1a8c-5db4-9872-37b9c457251a
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-04-08
Date Updated: 2026-04-28
Author: Beliz Kaleli, Fang Liu, Peng Peng, Alex Starov, Joey Allen and Stefan Springer
Unit 42 describes a growing trend of malware-initiated scanning attacks in which infected hosts (notably Mirai variants) are instructed by C2 to scan and exploit widely used vulnerabilities—such as MOVEit CVE-2023-34362, Zyxel RCE, and multiple Ivanti CVEs—resulting in millions of scan requests and major spikes of tens of thousands of unique targets; the report provides telemetry, case studies, IoCs (IPs, URLs, a SHA256), and mitigation recommendations using Palo Alto Networks products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
