[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/analysis-of-bunnyloader-malware/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/analysis-of-bunnyloader-malware/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Inside the Rabbit Hole: BunnyLoader 3.0 Unveiled

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 16 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Prisma Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Prisma Cloud](https://unit42.paloaltonetworks.com/product-category/prisma-cloud/ "Prisma Cloud")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Amanda Tanner](https://unit42.paloaltonetworks.com/author/amanda-tanner/)
  * [Anthony Galiette](https://unit42.paloaltonetworks.com/author/anthony-galiette/)
  * [Jerome Tujague](https://unit42.paloaltonetworks.com/author/jerome-tujague/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:March 15, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [BlackByte](https://unit42.paloaltonetworks.com/tag/blackbyte/)
  * [RaaS](https://unit42.paloaltonetworks.com/tag/raas/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/analysis-of-bunnyloader-malware/?pdf=download&lg=en&_wpnonce=7c3dfffa8c "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/analysis-of-bunnyloader-malware/?pdf=print&lg=en&_wpnonce=7c3dfffa8c "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Inside%20the%20Rabbit%20Hole:%20BunnyLoader%203.0%20Unveiled&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fanalysis-of-bunnyloader-malware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fanalysis-of-bunnyloader-malware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fanalysis-of-bunnyloader-malware%2F&title=Inside%20the%20Rabbit%20Hole:%20BunnyLoader%203.0%20Unveiled "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fanalysis-of-bunnyloader-malware%2F&text=Inside%20the%20Rabbit%20Hole:%20BunnyLoader%203.0%20Unveiled "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fanalysis-of-bunnyloader-malware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Inside%20the%20Rabbit%20Hole:%20BunnyLoader%203.0%20Unveiled%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fanalysis-of-bunnyloader-malware%2F "Share in Mastodon")

## Executive Summary

This article will focus on the newly released BunnyLoader 3.0, as well as historically observed BunnyLoader infrastructure and an overview of its capabilities. BunnyLoader is dynamically developing malware with the capability to steal information, credentials and cryptocurrency, as well as deliver additional malware to its victims.

In an increasingly cutthroat market, cybercriminals must regularly update and retool their malware to compete with other cybercriminals, security tools and researchers alike. Since its initial discovery in September of 2023, BunnyLoader malware as a service (MaaS) has frequently updated its functionality to include the following:

* Bug fixes
* Additional antivirus evasion and protections
* Multiple data recovery functionalities for the stealer portion
  * Additional browser paths
  * Keylogger functionality

Additional activity discovered in October 2023 by Unit 42 threat researchers revealed the threat actor continued to modify and retool BunnyLoader. The threat actor frequently changed their tactics in an effort to deliver and execute the malware in what appears to be an attempt to further obfuscate and evade detection.

Samples collected during this time included packed binaries using PureCrypter, UPX and Themida during various campaigns in November. In December, the BunnyLoader payload was delivered as a follow-up payload to a PureCrypter infection using a novel .NET injector. Threat actors changed filenames of the malware to mimic legitimate video games and other applications.

Frequent changes in tactics, techniques and procedures (TTPs) like infrastructure, packers, encryption and method of exfiltration help the attacker evade detection. It's also meant to undermine cybersecurity researchers' ability to detect and analyze the threat actor's activities.

On Feb. 11, 2024, the threat actor behind BunnyLoader announced the release of BunnyLoader 3.0, boasting the malware has been "completely redesigned and enhanced by 90%."

The threat actor claims enhancements to BunnyLoader payloads include:

* Payloads/modules "completely rewritten for improved performance"
* Reduced payload size
* Advanced keylogging capabilities

By revealing the threat actor's continued development of the malware and its evolving TTPs, we aim to empower readers to detect and hopefully prevent this threat.

Palo Alto Networks customers are better protected from BunnyLoader through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam), as well as through [Prisma Cloud](https://docs.prismacloud.io/en). Customers are also better protected through our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions), including [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire), [DNS Security](https://www.paloaltonetworks.com/network-security/dns-security), and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering).

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**MaaS**](https://unit42.paloaltonetworks.com/tag/malware-as-a-service/) |
|----------------------------|---------------------------------------------------------------------------|

## Behind the Ears of BunnyLoader

BunnyLoader has had a rapid development cycle. Version 1.0 was first seen at the beginning of September 2023, advertised on the dark web as a MaaS botnet and loader malware written in C/C++. It had a variety of capabilities such as the following:

* Fileless loading
* Credential theft
* Cryptocurrency theft
* Clipboard theft

The threat actor behind this malware is known as "Player" or "Player\_Bunny." The buyer determines what malware BunnyLoader delivers. The author of this malware prohibits its use against Russian systems.

Malware authors residing in or around Russian territory commonly prohibit the use of their malware against Russian targets. Threat actors likely use this restriction as a way to stay off of Russian law enforcement's radar.

As early as Sept. 4, 2023, the threat actor "Player" initially offered BunnyLoader version 1.0 on various forums at $250 for lifetime access. An example of this advertisement is shown below in Figure 1.
![Image 1 is a screenshot of a forum post on the dark web advertising BunnyLoader. The post was made Monday, September 4, 2023 by member PLAYER. The title of the post is New BunnyLoader, v1.0 Botnet! C/C++ fileless loader and stealer + much more! It introduces what it does, and discusses its different features. It also lists the features for the client. It is posted by a user named breach. The post was made on Monday, September 4, 2023.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-549750-132991-1.png) Figure 1. Dark web post advertising BunnyLoader 1.0. Source: [@DailyDarkWeb on X (Twitter)](https://twitter.com/DailyDarkWeb/status/1699090008827990058).

By the end of September 2023, BunnyLoader underwent a rapid retooling. According to the BunnyLoader advertisement, new features include the following:

* Command-and-control (C2) panel bug fixes
* Antivirus evasion
* Multiple data recovery methods used for information theft
* Added browser paths
* Keylogger functionality
* Anti-analysis protections

The malware loader ecosystem is normally in a state of flux. During the previous month, August 2023, there was significant impact to the prolific malware family Qakbot with the joint law enforcement [takedown operation](https://www.justice.gov/usao-cdca/pr/qakbot-malware-disrupted-international-cyber-takedown).

This event likely signaled an opportunity for other MaaS loader operators to gain a market foothold. As such, the aggressive retooling and updating by the BunnyLoader author might have been to attract market interest and increase its adoption. By the end of September, the author had released BunnyLoader 2.0 and it was [seen in the wild](https://www.virustotal.com/gui/ip-address/37.139.129.145/relations).

In October, the author offered a "private" version of the malware for $350. Unlike the original version, the author obfuscated this private version, and they made regular updates to evade antivirus protections. Threat actors were likely motivated to make these updates because security researchers discovered the malware in late September.

The threat actor advertised their most recent version, BunnyLoader 3.0, on their Telegram channel on Feb. 11, 2024.

## Observed Infrastructure: From Burrows to Bytes

When security researchers initially discovered BunnyLoader 1.0 in September, it used 37.139.129\[.\]145 for its C2 server, as noted in Figure 2.
![Image 2 is a screenshot of an X post. Hashtag Malware and BunnyLoader. Bunny login link. 142 bots. BTC wallet. Screenshot of BunnyLoader login page. Logo and Username and Password fields.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-553216-132991-2.png) Figure 2. X (formerly known as Twitter) post by security researcher 0xperator. Source: [@0xperator on X (Twitter)](https://twitter.com/0xperator/status/1706402486083350586).

In the earliest known samples of BunnyLoader, the client communicated with C2 servers using a standardized directory structure of http://\[url\]/Bunny/\[PHP endpoint\], as shown below in Figure 3. This pattern remains consistent throughout all samples leading up to the release of BunnyLoader 3.0.

![Image 3 is a list of many URLs observed as part of the BunnyLoader C2 server structure.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-555840-132991-3.png) Figure 3. URLs we have observed reflecting the directory structure on the C2 server at 37.139.129\[.\]145. BunnyLoader 2.0 uses URLs ending with Add.php to initially register the BunnyLoader client with the C2 server. Prior to registration, the malware enumerates the device and uses the collected information as a fingerprint to identify distinct targets.

Once BunnyLoader establishes communication with the C2, it repeatedly sends requests using URLs ending with TaskHandler.php. Responses from these requests initialized further malicious tasks performed by BunnyLoader.

Threat authors coded these tasks into separate functions, which included the following:

* Keylogging
* Clipboard theft
* Downloading additional malware
* Remote command execution
* Crypto wallet theft
* Application credential theft

During October, we observed new C2 infrastructure hosted at 185.241.208\[.\]83. That month, we also found BunnyLoader samples delivered via a conspicuous ZIP archive named Shovel Knight.zip. Further analysis revealed the contents of Shovel Knight.zip include a Windows executable, which is the stager for BunnyLoader 2.0.

Shovel Knight is a well-known video game for which development was crowdfunded. It was then released by major video game platforms. The threat actors' use of the names of legitimate software is undoubtedly an effort to trick users into opening and executing the malicious files.

During November, we identified subsequent campaigns using C2 servers hosted at:

* 195\.10.205\[.\]23
* 172\.105.124\[.\]34

Samples we collected in November 2023 used Themida to pack Windows executable files for BunnyLoader. In addition to Themida, we observed a cluster of PureCrypter samples in November 2023 designed to deliver BunnyLoader. These techniques indicate the operators of BunnyLoader started taking additional measures to protect their malware.

During December, we observed new C2 servers at:

* 134\.122.197\[.\]80
* 91\.92.254\[.\]31

That month's infection chain was far more complex than seen in previous months. We observed additional changes in TTPs, where the infection chain started with a previously unseen dropper leading to PureCrypter and forking into two branches as shown in Figure 4.
![Image 4 is a diagram of the December 2023 BunnyLoader infection. Delphi resource dropper containing NUIANS.exe. In-memory loader NUIANS.exe. Staged PureCrypter loader. Branch one: IP address. Purelogs loader. Purelogs stealer. Branch two: IP address. .NET injector. EXE injects BunnyLoader into EXE. BunnyLoader downloads and loads Meduza Stealer. Meduza Stealer.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-558987-132991-4.png) Figure 4. Overview of December infection chain.

One branch from the PureCrypter infection continues to deploy additional Pure malware by dropping the PureLogs loader and then delivering the [PureLogs stealer](https://any.run/cybersecurity-blog/pure-malware-family-analysis/#staged-and-stageless-loader-6639). The second branch results in PureCrypter leveraging a .NET injector to deliver BunnyLoader, which masquerades as the file notepet.exe. Notepet is a pet health tracker application for pet owners.

We also observed BunnyLoader using a misspelling of the app for the filename notep.exe. Threat actors used this file to deliver the [Meduza stealer](https://www.resecurity.com/blog/article/new-version-of-medusa-stealer-released-in-dark-web) malware.

Following the December activity, the threat author advertised another massive retooling with the release of BunnyLoader 3.0 on Feb. 11, 2024, as shown in Figure 5. Senior threat intelligence researcher @RussianPanda9xx first publicly shared this announcement on X (Twitter) as shown below in Figure 6.
![Image 5 is a screenshot for BunnyLoader as advertised on Telegram. February 11. Video of BunnyLoader. Video still is of the BunnyLoader login page. Download button. 105.5 MB. BunnyLoader (ADE) 3.0 Update. Webpanel/CnC. Completely redesigned and enhanced by 90%.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-561768-132991-5.png) Figure 5. Advertisement for BunnyLoader 3.0 on Telegram. ![Image 6 is a screenshot of a Twitter post by @RussianPanda. BunnyLoader announced a big 3.0 update. Maybe something to hunt for. Laugh behind hand emoji. She tagged two different people in the post. Screenshots of BunnyLoader updates that include list of upgrades to the malware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-564697-132991-6.png) Figure 6. X (formerly known as Twitter) post by threat intelligence researcher @RussianPanda.

The latest version of BunnyLoader, version 3.0, uses a different directory structure on its C2 servers than we saw in version 2.0. This directory structure is formatted as http://\[C2\]/\[path\]/\[PHP API\]. We discuss this information in more detail in the section [Hopping Through the Bytes](#post-132991-_i7cc014zwyn4)*.*

In BunnyLoader 3.0, the threat actor uses a dropper delivered via a CMD file with the BunnyLoader malware embedded in the dropper to deliver the actual malicious payload. Once attackers deliver BunnyLoader to the target machine, the malware reaches out to a C2 server at 91.92.247\[.\]212, which then responds and waits for further instruction from the threat actor.

## Sample Analysis: Hopping Through the Bytes of BunnyLoader 3.0

On Feb. 14, 2024, security researcher [Germán Fernández](https://twitter.com/1ZRR4H/status/1757967052898250930) identified the first known sample of BunnyLoader 3.0 contained in a malicious .cmd script discovered by [@ViriBack](https://twitter.com/ViriBack).

Unit 42 researchers tracking this threat analyzed the updated BunnyLoader file extracted from the .cmd script. We identified several major changes from prior versions, including updates to the C2 communication protocol and modularization of the binary.

As many aspects of BunnyLoader have not changed and are well documented in other write-ups, we focused our analysis in this article on new features. The following sections are not a comprehensive analysis but rather highlight key features found in the new version.

### Command and Control Update

The base URI structure of the C2 communication remains unchanged from prior versions, using the format http://\[C2\]/\[path\]/\[PHP API\]*.* The sample of BunnyLoader mentioned previously is configured to communicate with the C2 server located at hxxp://ads\[.\]hostloads\[.\]xyz/BAGUvIxJu32I0/gate.php. While previous versions of BunnyLoader used the string Bunny in the URL path, BunnyLoader 3.0 allows the operator to specify the path name.

Prior to the release of version 3.0, BunnyLoader servers used multiple PHP API endpoints to receive communication from clients (shown in Figure 3). All samples of BunnyLoader 3.0 observed by Unit 42 use one endpoint, gate.php.

Rather than sending HTTP parameters in cleartext, as seen in previous versions, BunnyLoader 3.0 will obfuscate these values using RC4 encryption. A random 32-character key is generated each time BunnyLoader is executed, which is used to RC4 encrypt all HTTP query parameter values. The encrypted values are subsequently converted into charcode and URL encoded, as seen in Figure 7, wherein a client is making an initial connection to the C2 server.
![Image 7 is a screenshot of many lines of code. The GET, User-Agent, Host and Cache-Control are highlighted in red. The rest of the information is highlighted in blue.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-568101-132991-7.png) Figure 7. Example of HTTP headers from an initial connection to the BunnyLoader C2 server.

For the C2 server to differentiate between client requests, each client function uses a unique URI parameter format, along with a specific user agent. Table 1 below outlines all possible C2 communication routines, including their purpose and parameters used.

HTTP query parameter names and values are listed in the rightmost column, with notations in parentheses to indicate usage. Unit 42 created the ID column for reference purposes.

|--------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **ID** | **Purpose**                                                                                                                                                          | **User Agent**   | **HTTP/S URI Parameters**                                                                                                                                                                         |
| 1      | Establishes initial connection to the C2 server.                                                                                                                     | Windows Defender | ipaddress hostname version (BunnyLoader version) system (Operating System) privileges (Local or Admin) arch (CPU Architecture) antivirus disk\_id (Bot ID) key (BL Operator Key) enc\_key (RC4 Key) |
| 2      | Sends a heartbeat to the C2 every 50 seconds.                                                                                                                        | Avast            | heart (BL Operator Key) hostname system (Operating System) arch (CPU Architecture) heart\_enc\_key (RC4 Key)                                                                                        |
| 3      | Sends a request every two seconds. The expected response is a command run via the Windows command line.                                                              | ESET SECURITY    | hostname system arch cecho (BL Operator Key) enc\_cecho (RC4 Key)                                                                                                                                  |
| 4      | Response to the C2 after executing the command in the previous row.                                                                                                  | McAffe           | val (BL Operator Key) hostname system arch value (command output) va\_enc\_key (RC4 Key)                                                                                                            |
| 5      | Sends a request every two seconds. The expected response is a specially formatted command parsed by the client.                                                      | AVG              | BID (Bot ID) bid\_enc\_key (RC4 Key)                                                                                                                                                                |
| 6      | Response to the C2 after executing the command in the previous row.                                                                                                  | Google Chrome    | CID (Command ID) bid (Bot ID) enc\_key (RC4 Key)                                                                                                                                                   |
| 7      | Sends a request every two seconds. The expected response is a specially formatted command parsed by the client. Used to download the denial-of-service (DoS) module. | Avast            | DBID (Bot ID) DBID\_enc\_key (RC4 Key)                                                                                                                                                              |
| 8      | Response to the C2 after executing the command in the previous row.                                                                                                  | Google Chrome    | DCID (Command ID) DBID (Bot ID) d\_enc\_key (RC4 Key)                                                                                                                                               |

*Table 1. BunnyLoader C2 functions and associated communications.*

The C2 address, C2 path, BunnyLoader version and operator ID are all hard-coded in the binary. This function also generates the RC4 key, as shown in Figure 8 below.
![Image 8 is a screenshot of many lines of code in IDA pro.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-571490-132991-8.png) Figure 8. BunnyLoader client configuration function as seen using IDA Pro.

### Modularization of BunnyLoader Binary

The second major change in BunnyLoader 3.0 is the transition from one file to a smaller base client with features available as downloadable modules. While most of the client code is similar to previous versions, BunnyLoader's custom stealer, clipper, keylogger and new DoS functions are now separated into distinct binaries. Operators of BunnyLoader can choose to deploy these modules or use BunnyLoader's built-in commands to load their choice of malware.

When running on a target computer, BunnyLoader will check in with the C2 every two seconds (see row five in Table 1), awaiting a specifically formatted command. These instructions facilitate the download and execution of additional malware on the target's computer and are formatted in the following manner:  
ID --\> \[value\]; Task\_Name --\> \[value\]; Task\_Args --\> \[value\]; DLL --\> \[value\]

|---|-------------------------------------------------------------------------------------------|
| 1 | ID --\> \[value\]; Task\_Name --\> \[value\]; Task\_Args --\> \[value\]; DLL --\> \[value\] |

The Task\_Name and Task\_Arg values are extracted from the command and passed to corresponding functions, which instruct the client how to download and execute the new payload. All HTTP download requests performed via these commands will utilize either the user agent ESET NOD32 (download is saved to disk) or curl/1.0 (fileless injection), and all downloaded files are saved to the victim's %localappdata%\\Temp folder.

The client will send a response back to the C2 containing the Command ID (CID) value extracted from the command, using the format shown in row six of Table 1.

Table 2 below summarizes all possible tasks that the C2 can send to the client.

|--------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------|
| **Task Name**                                                                                          | **Summary**                                                                                                                            |
| Download \& Inject (Executable) \[FileLess\]                                                           | Downloads .exe specified by Task\_Arg and injects it into notepad.exe, entirely in memory.                                              |
| Download \& Inject (DLL) \[RTI\]                                                                       | Downloads .dll specified by Task\_Arg to the %localappdata%/Temp folder, and injects it into calc.exe.                                  |
| Download \& Execute (Executable)                                                                       | Downloads .exe specified by Task\_Arg to the %localappdata%/Temp folder and executes it using CreateProcessA.                           |
| Download \& Execute (DLL)                                                                              | Downloads .dll specified by Task\_Arg to the %localappdata%/Temp folder and executes it using rundll32.                                 |
| Download \& Execute (Batch)                                                                            | Downloads .bat or .cmd script specified by Task\_Arg to the %localappdata%/Temp folder and executes it using CreateProcessA.            |
| Download \& Execute (PowerShell)                                                                       | Downloads .ps1 specified by Task\_Arg to the %localappdata%/Temp folder and executes it using powershell -ExecutionPolicy Bypass -File. |
| Download \& Execute (VBS)                                                                              | Downloads .vbs specified by Task\_Arg to the %localappdata%/Temp folder and executes it using cscript.exe.                              |
| Run Stealer                                                                                            | Downloads the BunnyLoader stealer module from a path hard-coded in the binary and injects it into notepad.exe, entirely in memory.     |
| Run Keylogger                                                                                          | Downloads the BunnyLoader keylogger module from a path hard-coded in the binary and injects it into notepad.exe, entirely in memory.   |
| (Any of the following) Bitcoin, Bitcoin Cash, Monero, Ethereum, Litecoin, Dogecoin, ZCash, Tether, XRP | Downloads the BunnyLoader clipper module from a path hard-coded in the binary and injects it into notepad.exe, entirely in memory.     |

*Table 2. BunnyLoader commands.*

The new DoS module download is handled in a separate thread, which will check in with the C2 every two seconds (see row seven in Table 1), awaiting a specifically formatted command. Upon receiving the appropriate command, the client will download and inject the DoS module into notepad.exe.

We noted the following URL structures used to download the BunnyLoader 3.0 modules, as shown in Table 3 below. The filenames and URL format remained constant across multiple samples.

|---------------------------------------------------|------------------|
| **Module URL**                                    | **Purpose**      |
| http://\[C2\]/\[path\]/Modules/eSentire.exe       | Stealer module   |
| http://\[C2\]/\[path\]/Modules/zScaler.exe        | DoS module       |
| http://\[C2\]/\[path\]/Modules/any\_run.exe        | Clipper module   |
| http://\[C2\]/\[path\]/Modules/NextronSystems.exe | Keylogger module |

*Table 3. BunnyLoader 3.0 module URLs.*

The following sections highlight the key functions of each BunnyLoader 3.0 module.

#### Keylogger Module

The BunnyLoader 3.0 keylogger records all keystrokes, saving them to log files in the %localappdata%\\Temp folder. The keylogger also attempts to identify when the victim authenticates to sensitive applications or services. To do so, the keylogger uses the GetForegroundWindow and GetWindowTextA APIs to identify when the victim is interacting with targeted applications or services. It will log the respective keystrokes to separate, hard-coded files, as shown in Table 4 below.

|-------------------------------------------------------|--------------------------------------|
| **Window Title or Application Name**                  | **Log Location (Hard-Coded)**        |
| CredentialUIBroker.exe  mstsc.exe               | %localappdata%\\Temp\\ADE\_RDP.txt    |
| Log in to your PayPal                                 | %localappdata%\\Temp\\ADE\_PAYPAL.txt |
| Nord Account                                          | %localappdata%\\Temp\\ADE\_NORD.txt   |
| Sign in - chase.com                                   | %localappdata%\\Temp\\ADE\_CHASE.txt  |
| Bank of America - Banking, Credit Cards, Loans        | %localappdata%\\Temp\\ADE\_BOA.txt    |
| Sign On to View Your Personal Accounts | Wells Fargo | %localappdata%\\Temp\\ADE\_WF.txt     |
| Citi.com                                              | %localappdata%\\Temp\\ADE\_CITI.txt   |
| All other keystrokes                                  | %localappdata%\\Temp\\ADE\_KEY.txt    |

*Table 4. BunnyLoader keylogger log file locations.*

#### Stealer Module

The BunnyLoader 3.0 stealer module operates autonomously, stealing credentials and exfiltrating data directly to the C2 server, using the same http://\[C2\]/\[path\]/\[PHP API\] format as the base client.

All information theft functions will store collected data in the %localappdata%\\Temp\\ADE\_LOGS folder. The stealer is also responsible for uploading logs from the keylogger module, which it will search for and copy to the same folder.

Once all data has been collected, the stealer will use PowerShell to compress the ADE\_LOGS folder into a .zip file. Before exfiltrating the .zip, the stealer will send a GET request to the C2 with a summary of the stolen data, with the user agent Windows Defender.

Query parameters of the HTTP GET requests are outlined in Table 5 below.

|--------------------------|------------------------------------------------------------------------------------------------------------|
| **HTTP Query Parameter** | **Value**                                                                                                  |
| theft\_id                 | Bot ID                                                                                                     |
| ipaddress                | Target IP address                                                                                          |
| system                   | Operating system                                                                                           |
| chromium                 | Number of browsers captured                                                                                |
| messages                 | Number of messaging services captured                                                                      |
| wallets                  | Number of crypto wallets captured                                                                          |
| keystrokes               | Number of keystroke log files found                                                                        |
| games                    | Number of gaming platforms captured                                                                        |
| vpns                     | Number of VPN services captured                                                                            |
| files                    | Number of targeted files captured (see [Appendix](#post-132991-_spl68fql0mp) for targeted file extensions) |
| extensions               | Number of Chrome extensions captured                                                                       |
| type                     | Hard-coded value of ZIP                                                                                    |
| size                     | Size of ZIP file                                                                                           |
| link                     | String in the format: http://\[C2\]/\[path\]/Logs/ADE\_LOGS\_\[hostname\].zip                                |
| key\_code                 | Operator ID                                                                                                |
| enc\_key                  | RC4 Key                                                                                                    |

*Table 5. BunnyLoader stealer module, parameters in the first request to C2.*

If the C2 responds appropriately, the stealer module will upload the .zip file, using the user agent Uploader and a custom Content-Type HTTP header, as shown in Figure 9 below. Once the upload is complete, the stealer will delete the collected data and the .zip file.
![Image 9 is a screenshot of the HTTP traffic exfiltrated by BunnyLoader. Many lines of code are highlighted in blue and red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/03/word-image-574455-132991-9.png) Figure 9. HTTP traffic of data exfiltration by BunnyLoader's stealer module.

A full list of information targeted by the stealer module can be found in the [Appendix](#post-132991-_frfuzxcfaemr).

#### Clipper Module

The BunnyLoader 3.0 clipper module periodically checks in with the C2, using the communication routine specified in rows five and six of Table 1. The C2 activates the clipper by sending the name of a cryptocurrency wallet to the target, along with a corresponding wallet address controlled by the threat actor.

The clipper uses regex patterns to identify whether the target's clipboard contains a desired wallet address type. If it finds a match, it will replace the victim's address with the malware operator's address. Table 6 below shows the targeted wallets and the regex statements used to identify them.

|----------------|--------------------------------------------|
| **Wallet**     | **Regex**                                  |
| Bitcoin\_Legacy | ^(bc1|\[13\])\[a-zA-HJ-NP-Z0-9\]{25,39}$ |
| Bitcoin\_Bech32 | ^\[13\]\[a-km-zA-HJ-NP-Z1-9\]{25,34}$     |
| erc-20         | ^T\[1-9A-HJ-NP-Za-km-z\]{33}$             |
| trc-20         | ^0x\[0-9a-fA-F\]{40}$                     |
| Bitcoin Cash   | ^((bitcoincash:)?(q|p)\[a-z0-9\]{41})    |
| Monero         | ^4(\[0-9\]|\[A-B\])(.){93}               |
| Litecoin       | ^\[LM3\]\[a-km-zA-HJ-NP-Z1-9\]{26,33}$    |
| Dogecoin       | ^\[DB\]\[1-9A-HJ-NP-Za-km-z\]{26,34}$     |
| ZCash          | ^t1\[a-zA-Z0-9\]{33}$                     |
| xrp\_address    | r\[1-9A-HJ-KM-NP-Za-km-z\]{25,34}          |

*Table 6. Wallets targeted by the BunnyLoader 3.0 clipper module and their associated regex patterns.*

#### Denial of Service Module

The BunnyLoader 3.0 DoS module waits for commands from the C2 using the communication routine specified in rows seven and eight of Table 1. The C2 can instruct the module to perform either a GET or POST HTTP flood attack against a specified URL.

To perform the attack, the module will spawn a new thread and enter an infinite loop, repeatedly sending GET or POST requests to the target server with the following user agent:

Mozilla/5.0 (compatible; U; ABrowse 0.6; Syllable) AppleWebKit/420+ (KHTML, like Gecko)

## Conclusion

In the ever changing landscape of MaaS, BunnyLoader continues to evolve, demonstrating the need for threat actors to frequently retool to evade detection. Revealing these evolving tactics and the dynamic nature of this threat empowers readers to bolster their defense posture and better protect their assets.

### Protections and Mitigations

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire):
  * Advanced WildFire recognizes and blocks the samples referenced in this post as malicious.
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR):
  * Cortex XDR recognizes and blocks the samples referenced in this post as malicious.
* [Next-Generation Firewalls (NGFW)](https://docs.paloaltonetworks.com/ngfw):
  * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [DNS Security](https://www.paloaltonetworks.com/network-security/dns-security) block related malicious URLs and IP addresses.
* [Prisma Cloud](https://docs.paloaltonetworks.com/prisma/prisma-cloud):
  * Compute [WildFire integration](https://www.paloaltonetworks.com/blog/prisma-cloud/prisma-cloud-and-wildfire-integration/) allows for Prisma Cloud's runtime compute defender agents to detect, alert on and prevent known malicious malware within cloud resources including virtual machines, serverless and containers.
  * The Web Application and API Security ([WAAS](https://www.paloaltonetworks.com/prisma/cloud/web-application-API-security)) module is a Prisma Cloud Defender agent-based application that allows Prisma Cloud to detect, alert on and prevent malicious API and cloud web application HTTP requests. Deploying the WAAS module on cloud-based Web Application and API endpoints can detect and prevent the initial compromising events used by BunnyLoader 3.0.

If you think you might have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

### Files for BunnyLoader:

|--------------------------------------------------------------------------------------------|----------------------------------------|----------------|
| **SHA256**                                                                                 | **Notes**                              | **First Seen** |
| 3a64f44275b6ff41912654ae1a4af1d9c629f94b8062be441902aeff2d38af3e                           | UPX-packed EXE                         | Sep. 9, 2023   |
| 0f425950ceaed6578b2ad22b7baea7d5fe4fd550a97af501bca87d9eb551b825                           | UPX-packed EXE                         | Sep. 9, 2023   |
| 82a3c2fd57ceab60f2944b6fea352c2aab62b79fb34e3ddc804ae2dbc2464eef                           | Themida-packed EXE                     | Nov. 11, 2023  |
| 2ab21d859f1c3c21a69216c176499c79591da63e1907b0d155f45bb9c6aed4eb                           | PureCrypter EXE                        | Nov 18, 2023   |
| c006f2f58784671504a1f2e7df8da495759227e64f58657f23efee4f9eb58216                           | PureCrypter EXE                        | Nov. 18, 2023  |
| 52b7cdf5402f77f11ffebc2988fc8cdcd727f51a2f87ce3b88a41fd0fb06a124                           | PureCrypter EXE                        | Nov. 18, 2023  |
| 5f09411395c8803f2a735b71822ad15aa454f47e96fd10acc98da4862524813a                           | PureCrypter EXE                        | Nov. 18, 2023  |
| cc2acf344677e4742b22725ff310492919499e357a95b609e80eaddc2b155b4b                           | PureCrypter EXE                        | Nov. 18, 2023  |
| ebc17dbf5970acb38c35e08560ae7b38c7394f503f227575cd56ba1a4c87c8a4                           | PureCrypter EXE                        | Nov. 18, 2023  |
| 2d39bedba2a6fb48bf56633cc6943edc6fbc86aa15a06c03776f9971a9d2c550                           | PureCrypter EXE                        | Nov. 18, 2023  |
| 2e9d6fb42990126155b8e781f4ba941d54bcc346bcf85b30e3348dde75fbeca1                           | PureCrypter EXE                        | Nov. 18, 2023  |
| 74c56662da67972bf4554ff9b23afc5bdab477ba8d4929e1d7dbc608bdc96994                           | PureCrypter EXE                        | Nov. 18, 2023  |
| fffdf51cdb54f707db617b29e2178bb54b67f527c866289887a7ada4d26b7563                           | PureCrypter EXE                        | Nov. 18, 2023  |
| 62f041b12b8b4e0debd6e7e4556b4c6ae7066fa17e67900dcbc991dbd6a8443f                           | PureCrypter EXE                        | Dec. 16, 2023  |
| 1a5ad9ae7b0dcdc2edb7e93556f2c59c84f113879df380d95835fb8ea3914ed8 (BunnyLoader 3.0 Dropper) | .cmd script                            | Feb. 14, 2024  |
| c80a63350ec791a16d84b759da72e043891b739a04c7c1709af83da00f7fdc3a (BunnyLoader 3.0)         | EXE payload from the above .cmd script | Feb. 14, 2024  |

### BunnyLoader Network Indicators:

|------------------|---------------------|----------------|
| **BotID**        | **C2 IP address**   | **Seen**       |
| BotID=880873019  | 37.139.129\[.\]145  | September 2023 |
| BotID=3565265299 | 37.139.129\[.\]145  | September 2023 |
| BotID=272148461  | 37.139.129\[.\]145  | September 2023 |
| BotID=2475708340 | 37.139.129\[.\]145  | September 2023 |
| BotID=2341255921 | 37.139.129\[.\]145  | September 2023 |
| BotID=3763204704 | 185.241.208\[.\]83  | October 2023   |
| BotID=337525325  | 185.241.208\[.\]83  | October 2023   |
| BotID=2098524523 | 185.241.208\[.\]83  | October 2023   |
| BotID=774055690  | 185.241.208\[.\]83  | October 2023   |
| BotID=3408378377 | 195.10.205\[.\]23   | November 2023  |
| BotID=2219025839 | 195.10.205\[.\]23   | November 2023  |
|                  | 172.105.124\[.\]34  | November 2023  |
|                  | 185.241.208\[.\]104 | November 2023  |
| BotID=4040267350 | 134.122.197\[.\]80  | December 2023  |
| BotID=1662989558 | 134.122.197\[.\]80  | December 2023  |
| BotID=3860674539 | 134.122.197\[.\]80  | December 2023  |

### YARA Rule

rule u42\_crime\_win\_bunnyloader\_3 { meta: author = "Unit 42 Threat Intelligence" date = "2024-02-28" description = "Detects Bunnyloader 3.0, a loader with additional capabilities including keylogger, stealer, clipper, and DoS modules." hash1 = "c80a63350ec791a16d84b759da72e043891b739a04c7c1709af83da00f7fdc3a" malware\_family = "bunnyloader" strings: $x1 = "Windows Defender" fullword ascii $x2 = "ONLINE" fullword ascii $x3 = "Blacklisted" fullword ascii $x4 = "ESET NOD32" fullword ascii $x5 = "McAffee" fullword ascii $x6 = "SecurityCenter2 path AntiVirusProduct get displayName" fullword ascii $cc1 = "\&va\_enc\_key=" fullword ascii $cc2 = "\&value=" fullword ascii $cc3 = "\&arch=" fullword ascii $cc4 = "\&system=" fullword ascii $cc5 = "\&hostname" fullword ascii $cc6 = "\&DBID\_enc\_key=" fullword ascii $cc7 = "/gate.php?DBID=" fullword ascii $cc8 = "/gate.php?DCID=" fullword ascii $cc9 = "(ID|Layer|Windows\_Argument)" ascii condition: all of them }

|-------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 | rule u42\_crime\_win\_bunnyloader\_3 { meta: author = "Unit 42 Threat Intelligence" date = "2024-02-28" description = "Detects Bunnyloader 3.0, a loader with additional capabilities including keylogger, stealer, clipper, and DoS modules." hash1 = "c80a63350ec791a16d84b759da72e043891b739a04c7c1709af83da00f7fdc3a" malware\_family = "bunnyloader" strings: $x1 = "Windows Defender" fullword ascii $x2 = "ONLINE" fullword ascii $x3 = "Blacklisted" fullword ascii $x4 = "ESET NOD32" fullword ascii $x5 = "McAffee" fullword ascii $x6 = "SecurityCenter2 path AntiVirusProduct get displayName" fullword ascii $cc1 = "\&va\_enc\_key=" fullword ascii $cc2 = "\&value=" fullword ascii $cc3 = "\&arch=" fullword ascii $cc4 = "\&system=" fullword ascii $cc5 = "\&hostname" fullword ascii $cc6 = "\&DBID\_enc\_key=" fullword ascii $cc7 = "/gate.php?DBID=" fullword ascii $cc8 = "/gate.php?DCID=" fullword ascii $cc9 = "(ID|Layer|Windows\_Argument)" ascii condition: all of them } |

## Additional Resources

* [BunnyLoader, the Newest Malware as a Service](https://www.zscaler.com/blogs/security-research/bunnyloader-newest-malware-service) -- Zscaler, ThreatLabz
* [#Malware #BunnyLoader V2.0 C2 Panel](https://twitter.com/0xperator/status/1706402486083350586) -- X (Twitter) post from @0xperator

## Appendix

This appendix contains additional information on the stealer module associated with BunnyLoader 3.0.

### Stealer Module: Target Enumeration Log Format

\------------------\>BunnyLoader (A.D.E) 3.0\<-------------------- A. Architecture --\> B. Graphics Processing Unit (GPU) --\> C. Central Processing Unit (CPU) → D. Hostname --\> E. Disk ID --\> F. System --\> G. AntiVirus --\> H. Country --\> I. Public IP --\> J. RAM --\> K. UserName --\> L. Log Date --\>

|-------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 | ------------------\>BunnyLoader (A.D.E) 3.0\<-------------------- A. Architecture --\> B. Graphics Processing Unit (GPU) --\> C. Central Processing Unit (CPU) → D. Hostname --\> E. Disk ID --\> F. System --\> G. AntiVirus --\> H. Country --\> I. Public IP --\> J. RAM --\> K. UserName --\> L. Log Date --\> |

### Stealer Module: Targeted Browsers

* \\7Star\\7Star\\User Data\\
* \\CentBrowser\\User Data\\
* \\Chedot\\User Data\\
* \\Vivaldi\\User Data\\
* \\Kometa\\User Data\\
* \\Elements Browser\\User Data\\
* \\Epic Privacy Browser\\User Data
* \\uCozMedia\\Uran\\User Data\\
* \\Fenrir Inc\\Sleipnir5\\setting\\modules\\ChromiumViewer\\
* \\CatalinaGroup\\Citrio\\User Data\\
* \\Coowon\\Coowon\\User Data\\
* \\liebao\\User Data\\
* \\QIP Surf\\User Data\\
* \\Orbitum\\User Data\\
* \\Comodo\\Dragon\\User Data\\
* \\Amigo\\User\\User Data\\
* \\Torch\\User Data\\
* \\Yandex\\YandexBrowser\\User Data\\
* \\Comodo\\User Data\\
* \\360Browser\\Browser\\User Data\\
* \\Maxthon3\\User Data\\
* \\K-Melon\\User Data\\
* \\Google\\Chrome\\User Data\\\\Sputnik\\Sputnik\\User Data\\
* \\Nichrome\\User Data\\
* \\CocCoc\\Browser\\User Data\\
* \\Uran\\User Data\\
* \\Chromodo\\User Data\\
* \\Mail.Ru\\Atom\\User Data\\
* \\Microsoft\\Edge\\User Data\\
* \\BraveSoftware\\Brave-Browser\\User Data\\

### Stealer Module: Targeted Cryptocurrency Wallets

* Armory
* Bytecoint
* Jaxx
* Exodus
* Ethereum
* Atomic
* Coinomi
* ZCash
* Guarda

### Stealer Module: Targeted File Extensions and File System Locations

* .txt
* .csv
* .log
* .json
* .xml
* .html
* .md
* .yaml
* .bat
* .ps1
* .doc
* .docx
* .odt
* .pp
* .pptx
* .rtf
* .css
* .vbs
* .php
* .c
* .cpp
* .cs
* .PNG
* .png
* .jpeg
* .jpg
* .db
* .sql
* .rdp
* .yar
* .yara
* (Current User Directory)
* Documents
* Downloads
* Music
* Pictures
* Videos

### Stealer Module: Targeted VPNs, Gaming and Messaging Platforms

* ProtonVPN
* OpenVPN
* Tox
* Signal
* Element
* ICQ
* Skype
* Discord
* Minecraft
* Ubisoft Game Launcher
* Uplay

### Stealer Module: Targeted Wallets

|----------------------------------|----------------------|
| **Extension**                    | **Description**      |
| fhbohimaelbohpjbbldcngcnapndodjp | \\Chrome Binance     |
| fihkakfobkmkjojpchpfgcmhfjnmnfpi | \\Chrome Bitapp      |
| aeachknmefphepccionboohckonoeemg | \\Chrome Coin98      |
| blnieiiffboillknjnepogjhkgnoapac | \\Chrome Equal       |
| nanjmdknhkinifnkgdcggcfnhdaammmj | \\Chrome Guild       |
| flpiciilemghbmfalicajoolhkkenfel | \\Chrome Iconex      |
| afbcbjpbpfadlkmhmclhkeeodmamcflc | \\Chrome Math        |
| fcckkdbjnoikooededlapcalpionmalo | \\Chrome Mobox       |
| bfnaelmomeimhlpmgjnjophhpkkoljpa | \\Chrome Phantom     |
| ibnejdfjmmkpcnlpebklmnkoeoihofec | \\Chrome Tron        |
| bocpokimicclpaiekenaeelehdjllofo | \\Chrome XinPay      |
| nphplpgoakhhjchkkhmiggakijnkhfnd | \\Chrome Ton         |
| nkbihfbeogaeaoehlefnkodbefgpgknn | \\Chrome Metamask    |
| fhmfendgdocmcbmfikdcogofphimnkno | \\Chrome Sollet      |
| pocmplpaccanhmnllbbkpgfliimjljgo | \\Chrome Slope       |
| mfhbebgoclkghebffdldpobeajmbecfk | \\Chrome Starcoin    |
| cmndjbecilbocjfkibfbifhngkdmjgog | \\Chrome Swash       |
| cjmkndjhnagcfbpiemnkdpomccnjblmj | \\Chrome Finnie      |
| dmkamcknogkgcdfhhbddcghachkejeap | \\Chrome Keplr       |
| pnlfjmlcjdjgkddecgincndfgegkecke | \\Chrome Cocobit     |
| fhilaheimglignddkjgofkcbgekhenbh | \\Chrome Oxygen      |
| jbdaocneiiinmjbjlgalhcelgbejmnid | \\Chrome Nifty       |
| kpfopkelmapcoipemfendmdcghnegimn | \\Chrome Liquality   |
| klfhbdnlcfcaccoakhceodhldjojboga | \\Edge Auvitas       |
| dfeccadlilpndjjohbjdblepmjeahlmm | \\Edge Math          |
| ejbalbakoplchlghecdalmeeeajnimhm | \\Edge Metamask      |
| oooiblbdpdlecigodndinbpfopomaegl | \\Edge MTV           |
| aanjhgiamnacdfnlfnmgehjikagdbafd | \\Edge Rabet         |
| bblmcdckkhkhfhhpfcchlpalebmonecp | \\Edge Ronin         |
| akoiaibnepcedcplijmiamnaigbepmcb | \\Edge Yoroi         |
| fbekallmnjoeggkefjkbebpineneilec | \\Edge Zilpay        |
| ajkhoeiiokighlmdnlakpjfoobnjinie | \\Edge Terra Station |
| dmdimapfghaakeibppbfeokhgoikeoci | \\Edge Jaxx          |

### Stealer Module: Credit Cards

* BCGLobal
* Carte Blanche
* Diners Club
* Discover
* Insta Payment
* Korean Local
* Laser
* Maestro
* Mastercard
* Switch
* Union Pay
* Visa Master

### Stealer Module: Miscellaneous Targets

* \\AppData\\Local\\ngrok\\ngrok.yml
* \\AppData\\Local\\ngrok

*Updated March 15, 2024, at 3:15 p.m. PT to change Nanocore to PureCrypter in the Executive Summary.*

*Updated April 4, 2024, at 9:o5 a.m. to adjust the YARA rule.*
Back to top

### Tags

* [BlackByte](https://unit42.paloaltonetworks.com/tag/blackbyte/ "BlackByte")
* [RaaS](https://unit42.paloaltonetworks.com/tag/raas/ "RaaS")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "Wireshark Tutorial: Exporting Objects From a Pcap")

### Table of Contents

* 

### Related Articles

* [No Manners Here: The Ruthless Rise of The Gentlemen Ransomware](https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/ "article - table of contents")
* [The Golden Scale: 'Tis the Season for Unwanted Gifts](https://unit42.paloaltonetworks.com/new-shinysp1d3r-ransomware/ "article - table of contents")
* [Threat Assessment: Repellent Scorpius, Distributors of Cicada3301 Ransomware](https://unit42.paloaltonetworks.com/repellent-scorpius-cicada3301-ransomware/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
