[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Project AK47: Uncovering a Link to the SharePoint Vulnerability Attacks

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 13 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex Xpanse icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Xpanse](https://unit42.paloaltonetworks.com/product-category/cortex-xpanse/ "Cortex Xpanse")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Hiroaki Hara](https://unit42.paloaltonetworks.com/author/hiroaki-hara/)
  * [Mark Lim](https://unit42.paloaltonetworks.com/author/mark-lim/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 5, 2025

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/)
  * [CL-CRI-1040](https://unit42.paloaltonetworks.com/tag/cl-cri-1040/)
  * [CVE-2025-49704](https://unit42.paloaltonetworks.com/tag/cve-2025-49704/)
  * [CVE-2025-49706](https://unit42.paloaltonetworks.com/tag/cve-2025-49706/)
  * [CVE-2025-53770](https://unit42.paloaltonetworks.com/tag/cve-2025-53770/)
  * [CVE-2025-53771](https://unit42.paloaltonetworks.com/tag/cve-2025-53771/)
  * [LockBit](https://unit42.paloaltonetworks.com/tag/lockbit/)
  * [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/)
  * [SharePoint](https://unit42.paloaltonetworks.com/tag/sharepoint/)
  * [Storm-2603](https://unit42.paloaltonetworks.com/tag/storm-2603/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ak47-activity-linked-to-sharepoint-vulnerabilities/?pdf=download&lg=en&_wpnonce=7052973960 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ak47-activity-linked-to-sharepoint-vulnerabilities/?pdf=print&lg=en&_wpnonce=7052973960 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Project%20AK47:%20Uncovering%20a%20Link%20to%20the%20SharePoint%20Vulnerability%20Attacks&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fak47-activity-linked-to-sharepoint-vulnerabilities%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fak47-activity-linked-to-sharepoint-vulnerabilities%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fak47-activity-linked-to-sharepoint-vulnerabilities%2F&title=Project%20AK47:%20Uncovering%20a%20Link%20to%20the%20SharePoint%20Vulnerability%20Attacks "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fak47-activity-linked-to-sharepoint-vulnerabilities%2F&text=Project%20AK47:%20Uncovering%20a%20Link%20to%20the%20SharePoint%20Vulnerability%20Attacks "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fak47-activity-linked-to-sharepoint-vulnerabilities%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Project%20AK47:%20Uncovering%20a%20Link%20to%20the%20SharePoint%20Vulnerability%20Attacks%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fak47-activity-linked-to-sharepoint-vulnerabilities%2F "Share in Mastodon")

## Executive Summary

Unit 42 observed notable overlaps between Microsoft's reporting on ToolShell activity (an exploit chain affecting SharePoint vulnerabilities) and activity that we have been separately tracking. The activity, which we track as CL-CRI-1040, caught our attention by deploying a tool set that we call Project AK47, which includes a backdoor, ransomware and loaders.

[Microsoft's report](https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/) named a suspected China-based threat actor, Storm-2603. Based on our analysis of host- and network-based artifacts, we assess with high confidence that Storm-2603 is related to the activity cluster that we track as CL-CRI-1040. We initially noted this in our [threat brief covering exploitation of recent SharePoint vulnerabilities](https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/), and here further expand on our observations. (See Table 1 in the body of this article for clarification of the connection.)

Our key findings are:

* CL-CRI-1040 is a cluster of financially motivated activity involving the ToolShell exploit chain
* CL-CRI-1040 involves a custom tool set called Project AK47
* Project AK47 includes:
  * A backdoor nicknamed AK47C2 that supports multiple protocols
  * Ransomware nicknamed AK47/X2ANYLOCK
  * Loaders abusing DLL side-loading
* CL-CRI-1040 was formerly identified as activity from a LockBit 3.0 affiliate and has recently been linked to a double-extortion site operating under the name Warlock Client

This threat research article includes both findings we can [confidently attribute](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/) to CL-CRI-1040 and observations that remain at lower levels of certainty.

Palo Alto Networks customers are better protected from the threats discussed in this article through:

* [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire)
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security)
* [Next-Generation Firewall](https://docs.paloaltonetworks.com/ngfw) with the [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration)
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM)

For more information about protection against the ToolShell exploit chain, please see our [threat brief on active exploitation of recent SharePoint vulnerabilities](https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/).

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

|----------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Related Unit 42 Topics** | [**Ransomware**](https://unit42.paloaltonetworks.com/category/ransomware)**,** [**CVE-2025-49704**](https://unit42.paloaltonetworks.com/tag/cve-2025-49704/)**,** [**CVE-2025-49706**](https://unit42.paloaltonetworks.com/tag/cve-2025-49706/)**,** [**CVE-2025-53770**](https://unit42.paloaltonetworks.com/tag/cve-2025-53770/)**,** [**CVE-2025-53771**](https://unit42.paloaltonetworks.com/tag/cve-2025-53771/)**,** [**SharePoint**](https://unit42.paloaltonetworks.com/tag/sharepoint/) |

## CL-CRI-1040

CL-CRI-1040 has been active since at least March 2025. Based on overlaps in host- and network-based artifacts from the [Microsoft report](https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/), we have high confidence that the CL-CRI-1040 activity cluster represents the same threat actor nicknamed Storm-2603, that Microsoft observed exploiting recent vulnerabilities in SharePoint through the ToolShell exploit chain. The recent SharePoint vulnerabilities are designated [CVE-2025-49704](https://nvd.nist.gov/vuln/detail/CVE-2025-49704), ​​[CVE-2025-49706](https://nvd.nist.gov/vuln/detail/CVE-2025-49706), [CVE-2025-53770](https://nvd.nist.gov/vuln/detail/CVE-2025-53770) and [CVE-2025-53771](https://nvd.nist.gov/vuln/detail/CVE-2025-53771).

Microsoft assessed Storm-2603 as a China-based threat actor, as of late July, but we do not have enough direct evidence to [confidently attribute](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/) CL-CRI-1040 to any nation-state or cybercriminal entity. Prior to the SharePoint ToolShell exploitation campaign, however, we had already observed malicious activity from this cluster using a tool set we call Project AK47.

We have also observed in CL-CRI-1040 deployment of an [IIS backdoor](https://github.com/WBGlIl/IIS_backdoor) that a Chinese-speaking community commonly misuses, which might be a potential connection to the Chinese nexus.

Retrospective investigation of CL-CRI-1040 revealed several pieces of evidence to support our assessment of this activity cluster as financially motivated. We confirmed that CL-CRI-1040 was formerly associated with a LockBit 3.0-affiliate and has recently been operating a double-extortion data leak site known as Warlock Client Leaked Data Show. However, considering that CL-CRI-1040 activity appeared alongside espionage-motivated actors in Microsoft's report, we cannot entirely rule out the possibility of nation-state motivation or cooperation between threat actors.

While we further describe the connections throughout this article, Figure 1 below illustrates an overview of the overlaps between Storm-2603 and CL-CRI-1040. Table 1 details how this discussion relates to the Microsoft report.
![Diagram illustrating the attribution of cyber tools and malware. Labels show connections between different threat groups like Linen Typhoon, Violet Typhoon, and their relationships with entities like Storm-2603 and CL-CRI-1040 to ransomware and SharePoint vulnerabilities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-73902-149927-1.png) Figure 1. An overview of indicators of compromise (IoC) overlaps between Storm-2603 and CL-CRI-1040.

|---------------------|-------------------|----------------------------------------------------------------------|-------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Research Origin** | **Cluster/Group** | **Activity**                                                         | **Tools**                                                                                       | **Significance**                                                                                                                                                             |
| Unit 42             | CL-CRI-1040       | Financially motivated activity involving the ToolShell exploit chain | Project AK47: backdoor, ransomware, loaders                                                     | Based on our analysis of host and network-based artifacts, we assess with high confidence that Storm-2603 is identical to the activity cluster that we track as CL-CRI-1040. |
| Microsoft           | Storm-2603        | Exploiting SharePoint vulnerabilities to deploy ransomware           | Microsoft "has observed this threat actor deploying Warlock and Lockbit ransomware in the past" | Based on our analysis of host and network-based artifacts, we assess with high confidence that Storm-2603 is identical to the activity cluster that we track as CL-CRI-1040. |

Table 1. Microsoft's report covers the activity of several threat actors. In this article, we detail our observations of CL-CRI-1040, which we assess with high confidence represents the activity of the same threat actor as Storm-2603.

## Project AK47

Project AK47 is a collection of malware used in CL-CRI-1040 that has likely been under development since at least March 2025. Project AK47 consists of several sub-projects, including the following:

* A multi-protocol supporting backdoor named AK47C2
* Custom ransomware named AK47 ransomware (also known as X2ANYLOCK)
* A set of other supporting tools

We named this tool set based on its common PDB (Program Database) filepath names, as shown below in Figure 2.
![Screenshot of four computer file paths in a list highlighting the ak47c2 portion of each patch.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-79174-149927-2.png) Figure 2. Examples of PDB filepaths of Project AK47.

According to the PDB filepath, Project AK47 can be divided into two main sub-projects:

* AK47C2
  * This sub-project contains tools named dnsclient and httpclient
* AK47
  * This sub-project contains tools named writenull, encrypt, 7zdllhijacked and dll\_hijacked, shown in Figure 3 below

![Diagram titled "Project AK47" showing two branches. The first branch, labeled "AK47C2," includes details of a DNS-based backdoor and an HTTP-based backdoor. The second branch, labeled "AK47," lists a prototype of AK47/XANLYLOCK ransomware, an encrypt tool, and a loader of AK47/XANLYLOCK ransomware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-83003-149927-3.png) Figure 3. The structure of Project AK47.

### AK47C2

AK47C2 is designed as a multi-protocol supporting backdoor. The protocols supported include DNS and HTTP, referred to as dnsclient and httpclient respectively, based on their PDBs. These two backdoor instances share the following functionality:

* Commands
* Command and control (C2) communication request and response format
* Encryption algorithm
* XOR key

The capability of these backdoors is straightforward, supporting the following features:

* Setting sleep duration
* Executing an arbitrary command

According to IoCs shared by Microsoft, attackers deployed both the dnsclient and httpclient components of AK47C2 as payloads for the ToolShell exploits.

#### Dnsclient

The dnsclient has been under development since at least early March 2025. The current variant uses DNS to communicate with the C2 server, as its PDB name indicates.

* C:\\Users\\Administrator\\Desktop\\work\\tools\\ak47c2\\dnsclinet-c\\dnsclient\\x64\\Release\\dnsclient.pdb

The method of C2 communication varies depending on the date of the sample. An early stage of dnsclient that we have called [version 202503](https://www.virustotal.com/gui/file/ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b) was packed using UPX. [Version 202503](https://www.virustotal.com/gui/file/ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b) was likely a test build because it contains several verbose error messages and uses a private IP address as its DNS server, as noted in the code snippet shown below in Figure 4.
![Image displaying a segment of computer code in a programming language, featuring function calls. The code includes conditional checks and error log messages related to memory allocation and DNS server IP validation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-86520-149927-4.png) Figure 4. Code snippet from version 2025-03 of dnsclient showing a private IP address of 10.7.66\[.\]10 as its DNS server.

[Version 202503](https://www.virustotal.com/gui/file/ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b) of dnsclient communicates with the C2 server by XOR-encoding JSON data, converting it into a hexadecimal string and then sending it as a subdomain of the hard-coded server at update.updatemicfosoft\[.\]com. The XOR key (VHBD@H) is hard-coded in the binary and is shared among other AK47C2 samples.

Figure 5 below illustrates the encoding algorithm to generate subdomains on the initial C2 check-in to receive a backdoor command.
![Illustration demonstrating the process of DNS exfiltration using randomized characters and the XOR operation, concluding with a conversion to hexadecimal and alignment with DNS subdomain mask length.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-90990-149927-5.png) Figure 5. The encoding algorithm of the dnsclient version 202503.

The response of the C2 server is contained in a DNS TXT record encoded by the same algorithm. The decoded response uses the following format in JSON:  
{"cmd": "\<COMMANDS\_TO\_EXECUTE\>", "cmd\_id": "\<COMMAND\_ID\>"}

|---|----------------------------------------------------------------|
| 1 | {"cmd": "\<COMMANDS\_TO\_EXECUTE\>", "cmd\_id": "\<COMMAND\_ID\>"} |

[Version 202503](https://www.virustotal.com/gui/file/ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b) of dnsclient supports multiple arbitrary command execution but does not support sleep duration management. The command execution result is sent in the following JSON format encoded with the same algorithm:  
{"cmd": "\<COMMANDS\_TO\_EXECUTE\>", "cmd\_id": "\<COMMAND\_ID\>", "type": "result", "fqdn": "\<HOSTNAME\>", "result": "\<EXECUTION\_OUTPUT\>"}

|---|--------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | {"cmd": "\<COMMANDS\_TO\_EXECUTE\>", "cmd\_id": "\<COMMAND\_ID\>", "type": "result", "fqdn": "\<HOSTNAME\>", "result": "\<EXECUTION\_OUTPUT\>"} |

However, this implementation might generate a subdomain longer than the maximum length of a DNS query (255 bytes). To avoid this, dnsclient fragments the request data and sends it in multiple queries. It prepends s to the domain name in the DNS query to indicate the query represents fragmented data.

In early April 2025, the developer updated the protocol of the dnsclient to simplify and support more reliability, which we have named [version 202504](https://www.virustotal.com/gui/file/1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192). In this version, the initial request to receive a backdoor command during C2 check-in generates a slightly different DNS subdomain, as shown below in Figure 6. The notable changes are that it doesn't use JSON anymore and prepends 1 to a random five-character session key to tell the C2 server that it is a task request.
![Image showing a diagram explaining a process to generate a unique subdomain using random characters, XOR operations, hostname, and conversion to hexadecimal.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-95436-149927-6.png) Figure 6. The encoding algorithm of dnsclient version 202504.

The TXT record in the DNS response is also encoded by the same algorithm, but the decoded data differs from the [version 202503](https://www.virustotal.com/gui/file/ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b) of dnsclient as follows:  
\<COMMAND\_TO\_EXECUTE\>::\<SESSION\_KEY\>

|---|-----------------------------------------|
| 1 | \<COMMAND\_TO\_EXECUTE\>::\<SESSION\_KEY\> |

[Version 202504](https://www.virustotal.com/gui/file/1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192) of dnsclient verifies the session key on the client side and performs a backdoor routine based on the received command. On the response request, similar to [version 202503](https://www.virustotal.com/gui/file/ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b), version 202504 fragments the execution results if the encoded data is too long and prepends s to the random session key. To finalize the message, it prepends 2 to the first substring session key and a to the second substring session key.

#### Httpclient

The httpclient has been under development since at least late March 2025 and supports HTTP communication with the C2 server, as its PDB name indicates.

* C:\\Users\\Administrator\\Desktop\\work\\tools\\ak47c2\\httpclient-cpp\\x64\\Release\\httpclient-cpp.pdb

The encoding algorithm and XOR key are the same ones used in dnsclient [version 202503](https://www.virustotal.com/gui/file/ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b), because httpclient also uses JSON to send and receive messages. The original message of the C2 check-in appears as follows:  
{"cmd": "", "cmd\_id": "", "type": "task", "fqdn": "\<HOSTNAME\>"}

|---|-------------------------------------------------------------------|
| 1 | {"cmd": "", "cmd\_id": "", "type": "task", "fqdn": "\<HOSTNAME\>"} |

The encoded hexadecimal string is stored in the HTTP body and sent to the C2 server using the POST method. The httpclient uses curl for network communication, as noted in the curl options (CURLOPT) shown in the code snippet in Figure 7 below.
![A screenshot of computer code in an editor, displaying functions and commands primarily related to the curl library for handling internet protocols. Text is in shades of blue, green, and grey.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-98861-149927-7.png) Figure 7. Code snippet of httpclient indicating the use of curl to communicate over HTTP.

### AK47 Ransomware (Aka X2ANYLOCK Ransomware)

While analyzing AK47C2, we found an interesting PDB, indicating possible ransomware as a sub-project of Project AK47:

* C:\\Users\\Administrator\\Desktop\\work\\tools\\ai\\ak47\\cpp\\encrypt\\encrypt\\x64\\Release\\encrypt.pdb

The use of encrypt in the PDB filepath name was not a coincidence, and our investigation revealed a ransomware written in C++ that we dubbed AK47 ransomware. However, due to the .x2anylock file extension added to encrypted files, this malware is publicly referred to as X2ANYLOCK ransomware. Although we found several reports of victims and auto-generated pages related to this ransomware, at the time of writing we had seen no technical analysis on AK47/X2ANYLOCK ransomware.

The [earliest version of AK47 ransomware](https://www.virustotal.com/gui/file/4147a1c7084357463b35071eab6f4525a94476b40336ebbf8a4e54eb9b51917f) was observed in early April 2025, which has a slightly different PDB, using writenull instead of encrypt in the file path name:

* C:\\Users\\Administrator\\Desktop\\work\\tools\\ai\\ak47\\writenull\\x64\\Release\\writenull.pdb

This PDB didn't implement file encryption capability, but only implemented ransom note creation. The associated sample was likely a prototype of AK47 ransomware.

Based on its compilation time, a sample of the [fully implemented AK47 ransomware](https://www.virustotal.com/gui/file/79bef5da8af21f97e8d4e609389c28e0646ef81a6944e329330c716e19f33c73) might have been compiled a few days after the likely prototype. The capabilities of this ransomware are typical of other ransomware families. AK47 ransomware can perform the following actions:

* Terminating several applications
* Enumerating all possible logical drives and network shares
* Encrypting specific types of files using a combination of AES and RSA, while excluding specified directories and files
* Dropping ransom notes (How to decrypt my data.txt or How to decrypt my data.log)

To potentially evade detection, the ransomware checks the Data Modified timestamp of [specific objects](#post-149927-_zcwu38eh3ceu). If the timestamp is on or after June 6, 2026, the ransomware terminates itself, as the code snippet in Figure 8 below shows.
![A screenshot displaying a segment of computer code in a text editor, including file paths, system time function, and conditional statements. The code involves file operations and system time checks in a programming environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-104498-149927-8.png) Figure 8. Code snippet of AK47 ransomware showing the timestamp check routine.

The ransom note is embedded in the AK47 ransomware binary without encryption or encoding. Figure 9 below shows an example of the ransom note. The decrypt ID differs with each binary, but the Tox ID to communicate with the threat actor is the same across all AK47 ransomware variants.
![The image shows text providing contact information, listing both a QTox ID and an Email Support address, with email hosted at Proton.me. The decryption ID is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-108482-149927-9.png) Figure 9. Example of a ransom note generated by AK47 ransomware.

#### Is This Warlock Ransomware?

According to the [Microsoft report](https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/), Storm-2603 has previously deployed ransomware named Warlock. However, since we have not found any common indicators between AK47/X2ANYLOCK ransomware from CL-CRI-1040 and Warlock ransomware from Microsoft's article, we cannot conclusively determine the relationship between these two ransomware families.

### Loaders

In addition to the AK47C2 backdoor and AK47/X2ANYLOCK ransomware, we found other sub-projects that support executing the payload via DLL side-loading, as the following PDB shows.

* C:\\Users\\Administrator\\Desktop\\work\\tools\\ai\\ak47\\cpp\\dll\_hijacked\\dll\_hijacked\\x64\\Release\\dllhijacked.pdb
* C:\\Users\\Administrator\\Desktop\\work\\tools\\ai\\ak47\\cpp\\7zdllhijacked\\7zdllhijacked\\x64\\Release\\My7zdllhijacked.pdb

These loaders are designed to be loaded via a legitimate executable (7z.exe in this case) and invoke the entrypoint of the AK47 ransomware DLL, as shown below in Figure 10.
![Screenshot of a computer screen displaying a list of function names and memory addresses, highlighting "GetModuleProp" and "DllEntryPoint," with the first marked as the main entry point of the malicious routine and the latter marked as the main entry.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-112177-149927-10.png) Figure 10. Entrypoint of AK47 ransomware.

### Other Tools

During our investigation, we encountered a [RAR archive](https://www.virustotal.com/gui/file/035998b724044d20d583fffa393907c7fef11ad8b93b4d423ad8cb8e53f248b7) named Evidencia.rar containing the following:

* A copy of the AK47C2 dnsclient
* AK47 ransomware
* Several hacking tools

While the source is unknown, the directory structure (Evidencia.rar\\Directorio\_Public) and included files indicate this RAR archive is possibly a package of the Public directory from a victim machine. If so, the hacking tools in this archive may be part of the arsenal for CL-CRI-1040. Table 2 below shows notable files from Evidencia.rar.

|-----------------------|------------------------------------------------------------------|-----------------------------------|
| **Filename**          | **SHA256 Hash**                                                  | **File Description**              |
| nxc.exe               | 0f4b0d65468fe3e5c8fb4bb07ed75d4762e722a60136e377bdad7ef06d9d7c22 | PyPyKatz                          |
| SharpHostInfo.x64.exe | d6da885c90a5d1fb88d0a3f0b5d9817a82d5772d5510a0773c80ca581ce2486d | SharpHostInfo                     |
| 7z.exe                | e7a7cd756dfeacbdc8caa0d431f9192cb10d62da119b138fca65276ff4ab6958 | A legitimate executable           |
| 7z.dll                | abb0fa128d3a75e69b59fe0391c1158eb84a799ddb0abc55d2d6be3511ef0ea1 | Loader for AK47 ransomware        |
| masscan\_1.3.0.exe     | 5cc047a9c5bb2aa6a9581942b9d2d185815aefea06296c8195ca2f18f2680b3e | masscan                           |
| sd.exe                | f01675f9ca00da067bdb1812bf829f09ccf5658b87d3326d6fddd773df352574 | SharpAdidnsdump                   |
| PsExec64.exe          | edfae1a69522f87b12c6dac3225d930e4848832e3c551ee1e7d31736bf4525ef | PsExec                            |
| PsExec.exe            | 078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b | PsExec                            |
| ip.exe                | f185c91e62ca38494d7f125492058028028769a86ed169bd2fb051e43fd9fb70 | A CSV file                        |
| clink\_x86.exe         | 011b31d7e12a2403507a71deb33335d0e81f626d08ff68575a298edac45df4cb | A legitimate executable           |
| bbb.msi               | 3b013d5aec75bf8aab2423d0f56605c3860a8fbd4f343089a9a8813b15ecc550 | LockBit 3.0 ransomware dropper    |
| clink\_dll\_x86.dll     | dbf5ee8d232ebce4cd25c0574d3a1ab3aa7c9caf9709047a6790e94d810377de | Loader for LockBit 3.0 ransomware |

Table 2. Notable files from the Evidencia.rar archive.

Of note, the LockBit 3.0 ransomware files in Table 2 are important evidence for our attribution.

## Retrospective Investigation

Our investigation of CL-CRI-1040 attacks revealed evidence of previous ransomware activities, including LockBit 3.0 and Warlock Client ransomware. This evidence led us to assess with high confidence that CL-CRI-1040 is financially motivated. Figure 11 provides an overview of the activities we've attributed to CL-CRI-1040.
![Diagram illustrating the LockBit 3.0 ransomware's use by CL-CRI-1040 and Storm-2603. It shows connections and interactions, such as 'use' and 'grant access', between various elements and entities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-115572-149927-11.png) Figure 11. An overview of the activities we attribute to CL-CRI-1040.

### Alleged LockBit 3.0 Affiliate

During our investigation on the Tox ID (3DCE1C43491FC92EA7010322040B254FDD2731001C2DDC2B9E819F0C946BDC3CD251FA3B694A) from the AK47 ransomware note, we discovered a [database dump file](https://www.virustotal.com/gui/file/4781ec443bb563c0c7b59462d5c25b4d1cfd4ad8a8a9f15aaf1381d4f677c434/detection) associated with LockBit 3.0 ransomware.

In May 2025, an unknown actor compromised LockBit 3.0 infrastructure and leaked a database dump of the ransomware's operations. This leaked dump file contains:

* Negotiation messages
* Bitcoin wallet addresses
* Affiliated user information
* Operational details

In this LockBit 3.0 dump file a username wlteaml has the same Tox ID as used in the AK47 ransomware note. The username wlteaml was registered as a LockBit 3.0 user on April 22, 2025, as shown in Figure 12.
![Screenshot of computer code displayed in a text editor with a black background and white text. The code includes functions and variable declarations written in Python. A Tox ID is highlighted in red on the second line.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-119207-149927-12.png) Figure 12. Same Tox ID in the LockBit dumped database.

The database indicates that the wlteaml is the last user registered as a LockBit 3.0 affiliate before the data leak. We believe the letters in the username wlteaml might stand for **w**ar**l**ock **team L**ockBit and indicate a tie to Warlock Client ransomware.

Let's revisit the LockBit 3.0 ransomware files contained in the above-mentioned RAR archive ([Evidencia.rar](https://www.virustotal.com/gui/file/035998b724044d20d583fffa393907c7fef11ad8b93b4d423ad8cb8e53f248b7)).

Bbb.msi is a malicious installer that works as a dropper of LockBit 3.0 ransomware loader. This MSI file drops two components:

* clink\_x86.exe -- This is a legitimate application misused to sideload the latter malicious DLL.
* clink\_dll\_x86.dll -- This DLL is completely different from any other sub-projects of Project AK47. It performs several known anti-analysis and anti-debugging techniques, decrypts a shellcode and runs it within a legitimate DLL (d3dl1.dll) by using the DLL hollowing technique.

The final payload executed by the in-memory shellcode is explicitly LockBit 3.0. Figure 13 shows the disassembled code of a unique entrypoint from the Lockbit 3.0 ransomware sample. This code invokes ransomware behavior, associated functions and meaningless Windows API calls, as ​​[an analysis report on LockBit 3.0](https://www.txone.com/blog/malware-analysis-lockbit-3-0/) previously described.
![A screenshot showing a portion of code in a programming environment, with numerous "call" statements invoking functions. The top section with a red background is the ransomeware behavior functions. The section below it with the green background shows meaningless Windows API calls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/word-image-122410-149927-13.png) Figure 13. Disassembled code snippet from the LockBit 3.0 ransomware sample entrypoint.

The timeline for this sample is unusual, because the first submission date of this sample to VirusTotal was April 16, 2025, but the associated wlteaml user registration on the LockBit 3.0 portal was April 22, 2025. While we cannot yet explain this timeline gap, the inclusion of the LockBit 3.0 instance in the same archive as Project AK47 components does not seem to be a mere coincidence.

### Warlock Client Leaked Data Show

The AK47 ransomware Tox ID shows another link to the Warlock ransomware group, which emerged in June 2025. The ransomware's leak site on the dark web is named Warlock Client Leaked Data Show, and it displays the same Tox ID as AK47 ransomware for negotiation with its victims.

While the website is inaccessible as of late July, we confirmed the same Tox ID from [a publicly available screenshot](https://www.ransomlook.io/screenshots/warlock-elqfbcx5nofwtqfookqml7ltx2g6q6tmddys6e25vgu3al2meim6cbqdonion.png). However, we haven't yet observed any actual ransomware used by the threat actor behind this leak site. Therefore, we lack any evidence to determine whether the AK47 ransomware has been used by the Warlock ransomware group.

On the other hand, Microsoft mentioned that Storm-2603 has previously deployed Warlock ransomware. However, since the report shares no indicators of Warlock ransomware binaries, we cannot confirm if the Warlock mentioned by Microsoft is identical to that used by the Warlock Client Leaked Data Show.

## Conclusion

Our analysis reveals overlaps between recent ToolShell exploit activity and the activity of a cluster that we track as CL-CRI-1040. This article also covers the Project AK47 tool set in detail and describes the considerations behind our attribution. This information reveals a continuously evolving threat and a complex situation behind the attacks.

### Palo Alto Networks Protection and Mitigation

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* The[Advanced WildFire](https://docs.paloaltonetworks.com/wildfire) machine-learning models and analysis techniques have been reviewed and updated in light of the indicators shared in this research.
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) identify known domains and URLs associated with this activity as malicious.
* [Next-Generation Firewall](https://docs.paloaltonetworks.com/ngfw) with the [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration) security subscription can help block the attacks with best practices via the following Threat Prevention signature [87037](https://threatvault.paloaltonetworks.com/?query=87037).
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) combine several layers of protection to prevent both known and unknown malware from causing harm to endpoints, including those mentioned in this article.
* [Cortex Xpanse](https://docs-cortex.paloaltonetworks.com/p/XPANSE) has the ability to identify exposed SharePoint devices on the public internet and escalate these findings to defenders. Customers may also opt into Xpanse Attack Surface Testing, which allows customers to initiate an external vulnerability scan for CVE-2025-53770 across their exposed SharePoint servers.

For more information about protection against the ToolShell exploit chain, please see our [threat brief on active exploitation of recent SharePoint vulnerabilities](https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/).

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 00080005045107

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

|------------------------------------------------------------------|-------------------------|
| **SHA256 Hash**                                                  | **Malware Description** |
| ceec1a2df81905f68c7ebe986e378fec0805aebdc13de09a4033be48ba66da8b | AK47C2: dnsclient       |
| 24480dbe306597da1ba393b6e30d542673066f98826cc07ac4b9033137f37dbf | AK47C2: httpclient      |
| 1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192 | AK47C2: dnsclient       |
| 257fed1516ae5fe1b63eae55389e8464f47172154297496e6f4ef13c19a26505 | AK47C2: dnsclient       |
| b5a78616f709859a0d9f830d28ff2f9dbbb2387df1753739407917e96dadf6b0 | AK47C2: dnsclient       |
| c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94 | AK47C2: dnsclient       |
| 4147a1c7084357463b35071eab6f4525a94476b40336ebbf8a4e54eb9b51917f | AK47 Ransomware         |
| 79bef5da8af21f97e8d4e609389c28e0646ef81a6944e329330c716e19f33c73 | AK47 Ransomware         |
| 55a246576af6f6212c26ef78be5dd8f83e78dd45aea97bb505d8cee1aeef6f17 | AK47 Ransomware         |
| a919844f8f5e6655fd465be0cc0223946807dd324fcfe4ee93e9f0e6d607061e | AK47 Ransomware         |
| f711b14efb7792033b7ac954ebcfaec8141eb0abafef9c17e769ff96e8fecdf3 | AK47 Ransomware         |
| 1d85b18034dc6c2e9d1f7c982a39ca0d4209eb6c48ace89014924eae6532e6bc | Loader                  |
| 7e9632ab1898c47c46d68b66c3a987a0e28052f3b59d51c16a8e8bb11e386ce8 | Loader                  |
| 7c31d43b30bda3a891f0332ee5b1cf610cdc9ecf772cea9b073ac905d886990d | Loader                  |
| 0f4b0d65468fe3e5c8fb4bb07ed75d4762e722a60136e377bdad7ef06d9d7c22 | PyPyKatz                |
| d6da885c90a5d1fb88d0a3f0b5d9817a82d5772d5510a0773c80ca581ce2486d | SharpHostInfo           |
| abb0fa128d3a75e69b59fe0391c1158eb84a799ddb0abc55d2d6be3511ef0ea1 | AK47 Ransomware         |
| 5cc047a9c5bb2aa6a9581942b9d2d185815aefea06296c8195ca2f18f2680b3e | masscan                 |
| f01675f9ca00da067bdb1812bf829f09ccf5658b87d3326d6fddd773df352574 | SharpAdidnsdump         |
| edfae1a69522f87b12c6dac3225d930e4848832e3c551ee1e7d31736bf4525ef | PsExec                  |
| 078163d5c16f64caa5a14784323fd51451b8c831c73396b967b4e35e6879937b | PsExec                  |
| dbf5ee8d232ebce4cd25c0574d3a1ab3aa7c9caf9709047a6790e94d810377de | LockBit 3.0             |
| 3b013d5aec75bf8aab2423d0f56605c3860a8fbd4f343089a9a8813b15ecc550 | LockBit 3.0 Dropper     |
| 7638069eeccf3cd7026723d794a7fd181c9fe02cecc1d1a98cf79b8228132ef5 | IIS\_backdoor            |
| 6f6db63ece791c6dc1054f1e1231b5bbcf6c051a49bad0784569271753e24619 | IIS\_backdoor            |

## Appendix A: List of Objects Checked by AK47 Ransomware

* C:\\Windows\\System32\\perfc009.dat
* C:\\Windows\\System32\\perfh009.dat
* C:\\Windows\\System32\\PerfStringBackup.ini
* C:\\Windows\\bootstat.dat
* C:\\Windows\\WindowsUpdate.log
* C:\\Windows\\Temp\\
* C:\\Users\\\*\\AppData\\Local\\Temp\\
* C:\\Users\\\*\\Local\\Temp\\

## Appendix B: List of Objects Ignored by AK47 Ransomware

* autorun.inf
* boot.ini
* bootfont.bin
* bootsect.bak
* bootmgr
* bootmgr.efi
* bootmgfw.efi
* desktop.ini
* iconcache.db
* ntldr
* ntuser.dat
* ntuser.dat.log
* ntuser.ini
* thumbs.db
* Program Files
* Program Files (x86)
* \#recycle
* How to decrypt my data.txt
* decryptiondescription.pdf
* config.json
* Important!!!.pdf

## Appendix C: List of File Extensions Ignored by AK47 Ransomware

* .x2anylock
* .386
* .adv
* .ani
* .bat
* .bin
* .cab
* .cmd
* .com
* .cpl
* .cur
* .deskthemepack
* .diagcab
* .diagcfg
* .diagpkg
* .dll
* .drv
* .exe
* .hlp
* .icl
* .icns
* .ico
* .ics
* .idx
* .ldf
* .lnk
* .mod
* .mpa
* .msc
* .msp
* .msstyles
* .msu
* .nls
* .nomedia
* .ocx
* .prf
* .ps1
* .rom
* .rtp
* .scr
* .shs
* .spl
* .sys
* .theme
* .themepack
* .wpx
* .lock
* .key
* .hta
* .msi
* .pdb
* .search-ms

*Updated Sept. 4, 2025, at 7:50 a.m. PT to add Advanced Threat Prevention coverage.*

*Updated Sept. 18, 2025, at 9:05 a.m. PT to add Cortex Xpanse coverage.*
Back to top

### Tags

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")
* [CL-CRI-1040](https://unit42.paloaltonetworks.com/tag/cl-cri-1040/ "CL-CRI-1040")
* [CVE-2025-49704](https://unit42.paloaltonetworks.com/tag/cve-2025-49704/ "CVE-2025-49704")
* [CVE-2025-49706](https://unit42.paloaltonetworks.com/tag/cve-2025-49706/ "CVE-2025-49706")
* [CVE-2025-53770](https://unit42.paloaltonetworks.com/tag/cve-2025-53770/ "CVE-2025-53770")
* [CVE-2025-53771](https://unit42.paloaltonetworks.com/tag/cve-2025-53771/ "CVE-2025-53771")
* [LockBit](https://unit42.paloaltonetworks.com/tag/lockbit/ "LockBit")
* [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/ "Microsoft")
* [SharePoint](https://unit42.paloaltonetworks.com/tag/sharepoint/ "SharePoint")
* [Storm-2603](https://unit42.paloaltonetworks.com/tag/storm-2603/ "Storm-2603")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)")

### Table of Contents

* 

### Related Articles

* [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "article - table of contents")
* [How We Added WebAuthn to a Browser-Based RDP Client](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/ "article - table of contents")
* [CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure](https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
