Hackers Deploy Python Backdoor in Palo Alto Zero-Day Attack
ID: bf701148-829e-5548-8528-ffac373ec84f
STIX ID: report--bf701148-829e-5548-8528-ffac373ec84f
Feed Name: The Hacker News
**Operation MidnightEclipse (CVE-2024-3400)**: A critical PAN-OS command-injection zero-day (CVSS 10.0) has been exploited in the wild to install a Python backdoor (tracked as UPSTYLE) on GlobalProtect-enabled Palo Alto firewalls; the attacker (UTA0218) creates cron jobs that fetch and execute commands, uses forged requests to embed commands in legitimate log/web files, and rapidly restores file contents to minimize traces while stealing DPAPI keys, NTDS.DIT, and credentials for lateral movement and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
