RedTail Crypto-Mining Malware Exploiting Palo Alto Networks Firewall Vulnerability
ID: b2d5a803-a465-52b2-b337-7fb4286725ab
STIX ID: report--b2d5a803-a465-52b2-b337-7fb4286725ab
Feed Name: The Hacker News
Akamai researchers report that RedTail, a cryptocurrency-mining malware family, has added exploitation of a critical Palo Alto PAN-OS RCE (CVE-2024-3400, CVSS 10.0) to its infection chain; successful exploitation fetches a shell script that deploys an XMRig-based miner. The malware also leverages multiple other CVEs across routers, VPNs, and web frameworks, includes new anti-analysis and persistence techniques, and appears to use private mining pools — behaviors indicative of a well-resourced, possibly nation-state-linked operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
