CVE-2024-3400 Activity
ID: 40210ca1-8e2e-5cb0-a939-97b255569ddd
STIX ID: report--40210ca1-8e2e-5cb0-a939-97b255569ddd
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes the Upstyle backdoor suspected to be used in a PAN-OS zero-day firewall exploit: a three-layer malicious implant that achieves persistence by installing code in a Python .pth file, launches only under specific process conditions, and uses encoded commands embedded in SSLVPN error logs to execute and exfiltrate output (temporarily stored in a CSS file) while restoring timestamps and cleaning logs to minimize detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
