One Step Ahead in Cyber Hide-and-Seek: Automating Malicious Infrastructure Discovery With Graph Neural Networks
ID: e66bcc50-51c6-5b0b-8658-57f55a8d4928
STIX ID: report--e66bcc50-51c6-5b0b-8658-57f55a8d4928
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-01-14
Date Updated: 2026-04-28
Author: Nabeel Mohamed, Keerthiraj Nagaraj, Billy Melicher, Shehroze Farooqi, Alex Starov, Brady Stout and Robert Davis
Unit 42 describes an automated, GNN-driven approach to pivot from known indicators to discover extensive attacker infrastructure across three active campaigns: FIN7 spear-phishing distributing Aranuk/Carbanak, a global postal-service phishing network, and a web skimmer campaign exfiltrating payment data. The report maps thousands of domains and IPs, highlights shared hosting, certificates and phishing kits as pivot points, and publishes sample IOCs to enable proactive detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
