[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# An Investigation Into Years of Undetected Operations Targeting High-Value Sectors

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 16 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Next-Generation Firewall VM series icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall VM series](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall-vm-series/ "Next-Generation Firewall VM series")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Tom Fakterman](https://unit42.paloaltonetworks.com/author/tom-fakterman/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:March 6, 2026

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CL-UNK-1068](https://unit42.paloaltonetworks.com/tag/cl-unk-1068/)
  * [DLL Sideloading](https://unit42.paloaltonetworks.com/tag/dll-sideloading/)
  * [Fast Reverse Proxy](https://unit42.paloaltonetworks.com/tag/fast-reverse-proxy/)
  * [ScanPortPlus](https://unit42.paloaltonetworks.com/tag/scanportplus/)
  * [Xnote](https://unit42.paloaltonetworks.com/tag/xnote/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/cl-unk-1068-targets-critical-sectors/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=An%20Investigation%20Into%20Years%20of%20Undetected%20Operations%20Targeting%20High-Value%20Sectors&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fcl-unk-1068-targets-critical-sectors%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcl-unk-1068-targets-critical-sectors%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcl-unk-1068-targets-critical-sectors%2F&title=An%20Investigation%20Into%20Years%20of%20Undetected%20Operations%20Targeting%20High-Value%20Sectors "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcl-unk-1068-targets-critical-sectors%2F&text=An%20Investigation%20Into%20Years%20of%20Undetected%20Operations%20Targeting%20High-Value%20Sectors "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcl-unk-1068-targets-critical-sectors%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=An%20Investigation%20Into%20Years%20of%20Undetected%20Operations%20Targeting%20High-Value%20Sectors%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fcl-unk-1068-targets-critical-sectors%2F "Share in Mastodon")

## Executive Summary

Since at least 2020, we have observed a cluster of activity targeting high-value organizations across South, Southeast and East Asia. The attacks focus on critical sectors such as aviation, energy, government, law enforcement, pharmaceutical, technology and telecommunications.

Unit 42 is tracking this ongoing, previously undocumented activity as CL-UNK-1068. We designate the term UNK to clusters of activity whose affiliation with either nation-state or cybercrime activity we have not yet determined.

We assess with high confidence that the attackers behind CL-UNK-1068 are a Chinese threat actor. This assessment is based on the origin of their tools, linguistic artifacts in configuration files, and their consistent, longstanding targeting of critical infrastructure in Asia. We assess with moderate-to-high confidence that the primary objective of the attackers is cyberespionage, although we cannot fully rule out the possibility of cybercriminal motivation at this time.

Through a long period of close observation, we identified the specific tools and techniques that define this group. Our attribution of this activity to CL-UNK-1068 is done in accordance with [Unit 42's attribution framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/). We provide a detailed analysis of the attack patterns and methods that we identified in our investigation into this cluster of activity.

Palo Alto Networks customers are better protected from the threats described through the following products and services:

* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security)
* [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) (NGFW) with [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)
* [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire)
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM)

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Related Unit 42 Topics** | **[CL-UNK-1068](https://unit42.paloaltonetworks.com/tag/cl-unk-1068/), [DLL Sideloading](https://unit42.paloaltonetworks.com/tag/dll-sideloading/), [Backdoors](https://unit42.paloaltonetworks.com/tag/backdoor/)** |

## Technical Analysis Overview

We provide a detailed analysis of the tool set deployed by the attackers behind CL-UNK-1068 across different intrusion campaigns since 2020. While these attacks demonstrate a consistent set of techniques and procedures (TTPs), it is important to note that not every tool was used in every observed intrusion. Our analysis reveals a multi-faceted tool set that includes custom malware, modified open-source utilities and living-off-the-land binaries (LOLBINs). These provide a simple, effective way for the attackers to maintain a persistent presence within targeted environments.

The CL-UNK-1068 activity cluster is characterized by cross-platform cyber capabilities, maintaining a diverse set of tools for both Windows and Linux environments. Their TTPs rely heavily on open-source utilities and malware variants popular with Chinese-speaking users, including [GodZilla](https://github.com/BeichenDream/Godzilla/), [AntSword](https://github.com/AntSwordProject), [Xnote](https://github.com/fatedier/frp) and [Fast Reverse Proxy](https://github.com/fatedier/frp) (FRP). One of the techniques we observed in these attacks is the use of legitimate Python executables to launch DLL side-loading attacks. This approach enables the attackers to stealthily load additional payloads.

## Initial Access and Web Shell Deployment

The initial access to environments targeted in CL-UNK-1068 activity is achieved by deploying and utilizing various web shells. We observed the attackers deploying the GodZilla web shell, and a variation of AntSword, both of which are written in a combination of English and Simplified Chinese. After gaining an initial foothold, the attackers use these web shells to move laterally to additional hosts and SQL servers. Figure 1 shows an alert that was triggered when an attacker attempted to exploit a Linux server.
![A screenshot of a notification card with a red "H" icon. The title reads "Webserver Exploitation," and the source is marked as "XDR BIOC" with a warning icon. Below, it says "nginx process spawning a remote shell." There are small icons on the upper right side.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-994086-174811-1.png) Figure 1. Cortex XDR alert indicating Linux webserver exploitation, triggered by CL-UNK-1068 activity.

## Exfiltrating Configuration Files for Access and Sensitive Data

After gaining access to targeted environments, the attackers attempt to steal the following files from the c:\\inetpub\\wwwroot directory of a Windows web server:

* web.config
* .aspx
* .asmx
* .asax
* .dll

The attackers could use this stolen information to extract credentials for lateral movement, or to discover vulnerabilities in the website's code.

The alert in Figure 2 shows that the attackers archived the stolen files under the names web.rar, web1.rar and web2.rar.
![A flowchart in Cortex XDR displaying a sequence of processes involving two executable files triggering multiple instances of of a EXE file labeled RAR. Each "rar.exe" process shows a command line path involving compression of files within the C drive. Multiple icons indicate the malware alert process.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-996268-174811-2.png) Figure 2. Cortex XDR alert showing the attackers archiving files for exfiltration under c:\\inetpub\\wwwroot.

After moving to additional servers, the attackers continued to steal files related to the website's configuration, such as .json files from the c:\\inetpub\\wwwroot directory, including the appsettings.json file.

In multiple instances, the attackers used a simple but effective approach to exfiltrate files:

1. Using WinRAR to archive the relevant files.
2. Executing the certutil -encode command to Base64-encode the .rar archives.
3. Executing the type command to print the Base64 content to their screen through the web shell.

By encoding the archives as text and printing them to their screen, the attackers were able to exfiltrate data without actually uploading any files. The attackers likely chose this method because the shell on the host allowed them to run commands and view output, but not to directly transfer files. Figure 3 shows the alert triggered by the data exfiltration activity.
![A flowchart in Cortex XDR displaying the CL-UNK-1068 data exfiltration process, showing the sequence of file archiving with WinRAR, Base64 encoding, and outputting the data via a command-line tool for web shell retrieval.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-998731-174811-3.png) Figure 3. Cortex XDR alert showing the attackers exfiltrating archived files.

In addition to stealing configuration files, the attackers stole other types of sensitive data:

* Browser history and web browser bookmarks
* Sensitive XLSX and CSV files from desktops and USER directories
* .bak files from MSSQL servers (database backup files)

In certain instances, the attackers deployed [usql](https://github.com/xo/usql), a universal command-line interface for multiple databases. The use of this interface may indicate that one of the goals of CL-UNK-1068 activity is to extract data directly from SQL servers.

## Tool Set

We analyzed the most noteworthy tools and utilities that the attackers behind CL-UNK-1068 used across multiple intrusion campaigns since 2020. A detailed analysis of additional tools and utilities used during this activity is provided in [Appendix B](#post-174811-_dqn7va5cjyh6).

### DLL Side-Loading Using Legacy Python Programming Language Executables

In attacks that we observed, the attackers behind CL-UNK-1068 frequently used DLL side-loading to execute their tool set. They deployed a legitimate Python programming language executable like python.exe or pythonw.exe alongside a malicious side-loaded DLL that served as a loader, using a name like python20.dll. The attackers also dropped an obfuscated shellcode file with a similar name, to match the legitimate executable naming convention (e.g., python or pythonw).

When the legitimate python.exe is executed, it side-loads a malicious loader named python20.dll. The malicious loader reads the obfuscated shellcode, deobfuscates it in memory, and then executes it within the memory space of the legitimate Python process. The shellcode then decrypts and executes the payload in memory.

The attackers used this technique to load and execute several tools as payloads, including [FRP](https://github.com/fatedier/frp), [PrintSpoofer](https://github.com/itm4n/PrintSpoofer) and a custom scanner that they named ScanPortPlus. Figure 4 shows the legitimate python.exe process used to read shellcode from a file named python and execute a decrypted payload for ScanPortPlus in memory.
![A flowchart in Cortex XDR alert showing a legitimate Python executable is used for DLL side-loading to execute the decrypted ScanPortPlus payload in memory.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-1034-174811-4.png) Figure 4. Cortex XDR alert showing that python.exe reads shellcode from the python file and executes the decrypted ScanPortPlus in memory.

### ScanPortPlus: A Custom Multi-Platform Scanning Toolkit

The attackers behind CL-UNK-1068 scanned compromised networks using a custom scanner that they internally named ScanPortPlus. This custom tool is written in [Go](https://go.dev/learn/), and the threat actor compiled versions for both Windows and Linux systems. Figure 5 shows the command-line options of ScanPortPlus, which include IP address, port and vulnerability scanning.
![A screenshot of command-line options for the ScanPortPlus custom scanning toolkit, detailing functions for IP address, port, and vulnerability scanning.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-3140-174811-5.png) Figure 5. ScanPortPlus command-line options.

### Communication Tunneling: Custom FRP Variant with Unique Identifiers

In some of the events that we observed, the attackers deployed [FRP](https://github.com/fatedier/frp), to establish persistent access while bypassing firewalls. The attackers used versions of their own custom-compiled FRP for Windows and Linux systems, including a custom FRP that had several unique identifiers:

* **Unique authentication token:** Attackers used the authentication token frpforzhangwei ("frp for zhang wei"). Zhang Wei is a common Chinese name.
* **Proxy naming convention:** The proxy names appear to have a consistent naming convention across the versions:
  * Windows: 10014-win-nic-32-v
  * Linux:
    * 20012-linux-64-V
    * 10013-linux-64-V
* **Unique common password** : The password for the FRP is the same in all samples that the threat actor used: f\*ckroot123 (profanity masked).

Figure 6 highlights the identifiers that we discovered in the FRP samples.
![A sceenshot of a configuration from the custom Fast Reverse Proxy (FRP) samples, including the unique authentication token and consistent proxy naming conventions used by CL-UNK-1068.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-4936-174811-6.png) Figure 6. Configuration from FRP samples used in CL-UNK-1068 activity.

### Deploying Xnote Linux Backdoor

In some instances, the attackers behind CL-UNK-1068 deployed the Xnote malware on Linux servers. First discovered in 2015, [Xnote](https://vms.drweb.com/virus/?i=4372602) is a Linux backdoor that various Chinese threat actors [previously used](https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/exposing-earth-berberoka-a-multiplatform-apt-campaign-targeting-online-gambling-sites). Xnote has several variants, each with slightly different functionality. The Xnote used by CL-UNK-1068 primarily provides distributed denial-of-service (DDoS) attack capabilities, in addition to other commands.

Table 1 lists some of the capabilities of this Xnote variant.

|------------------------|----------------------------------------------------------------------------------------------------|
| **Internal Task Name** | **Task Function**                                                                                  |
| 9CFileTask             | Interact with file system, upload and download files, execute shell commands                       |
| 10CShellTask           | Reverse shell                                                                                      |
| 10CProxyTask           | No current function; likely a remnant from previous versions, since replaced by 13CNewProxyTask    |
| 11CDDosCCTask          | Execute a [CC DDoS attack](https://www.tencentcloud.com/techpedia/117843)                          |
| 12CDdosNtpTask         | Execute [NTP DDoS attack](https://www.cloudflare.com/learning/ddos/ntp-amplification-ddos-attack/) |
| 12CDDosSynTask         | Execute [SYN Flood DDoS attack](https://www.cloudflare.com/learning/ddos/syn-flood-ddos-attack/)   |
| 12CDDosUDPTask         | Execute a [UDP Flood DDoS attack](https://www.cloudflare.com/learning/ddos/udp-flood-ddos-attack/) |
| 12CPortMapTask         | Establish port forwarding on tde machine                                                           |
| 13CNewProxyTask        | Set a reverse proxy or tunnel                                                                      |

Table 1. Xnote task names and functions.

### Host-Level Reconnaissance Operations

Our observations reveal that in 2020, the attackers deployed a custom tool named SuperDump for reconnaissance. In the years following, we saw that the attackers transitioned to a new method of using batch scripts for reconnaissance purposes.

#### Gathering Host Information Using Custom SuperDump Tool

In intrusions dating back to 2020, the attackers behind CL-UNK-1068 attempted to use a custom .NET tool that they named SuperDump. The tool's purpose is to collect information from Windows hosts, such as:

* User information
* Host information: IP address, running processes, system information, drive information
* Files from desktop and document folders
* Installed programs
* Local Security Authority Subsystem Service (LSASS) process dump content
* Registry information:
  * Navicat configuration (database management tool)
  * WinSCP configuration
  * RDP configuration
  * Internet Explorer settings
  * Environment variables
  * PuTTY configuration
  * FileZila data
  * NetSarang Xmanager data (remote desktop software)
  * SSH data
  * PowerShell history
  * Microsoft\\Windows\\Recent registry key (recent programs)

Figure 7 shows the functions in SuperDump's code that gather information.
![A code snippet in C# language. Function names from the SuperDump tool's code responsible for gathering extensive host reconnaissance information on Windows systems.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-7525-174811-7.png) Figure 7. Function names in SuperDump code that are responsible for information gathering.

We discovered that the use of SuperDump was later replaced by batch script files called hpp.bat and hp.bat, which also collect host information. The functionality of these batch files is detailed in the following section.

#### Host Reconnaissance Using Batch Scripts

In more recently observed cases, after successfully compromising an endpoint, the attackers initiate the reconnaissance phase. This involves deploying custom batch scripts to gather initial host telemetry and map the local environment.

The specific naming conventions for both scripts and output files constitute a unique signature that we observed across multiple attacks over several years.

We observed that in several instances, the attackers executed a batch script named hp.bat or hpp.bat, and on one occasion, a.bat. Each of these batch scripts executed multiple commands and saved the results in matching .txt files. The attackers utilized these scripts to perform host reconnaissance, gather telemetry on the local system and map other potential servers in the environment. For a detailed analysis of the scripts, output filenames and executed commands, see [Appendix B](#post-174811-_dqn7va5cjyh6).

After all the output files were written to disk, attackers executed an additional rar.bat/rr.bat batch script that was responsible for archiving the result files using commands such as:

* rar.exe a -df host.rar \*.txt
* rar a -df host.rar \*.txt \*.db
* rar a -df host.rar \*.txt \*.db \*hist\* \*book\*

### Credential Theft Tool Set

This section provides a comprehensive description of the various tools and methods utilized in CL-UNK-1068 activity to execute credential theft.

#### Mimikatz and LsaRecorder

The attackers used Mimikatz to dump passwords from memory, and a dumping tool named LsaRecorder, as Figure 8 shows.
![A flowchart showing execution view of the LsaRecorder tool, a memory-dumping utility used by the threat actor for password theft.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-9482-174811-8.png) Figure 8. Execution of LsaRecorder.

The LsaRecorder tool captures login passwords by hooking the [LsaApLogonUserEx2](https://learn.microsoft.com/en-us/windows/win32/api/ntsecpkg/nc-ntsecpkg-lsa_ap_logon_user_ex2) callback function. The [LsaRecorder tool](https://bbs.kanxue.com/thread-251888.htm) was shared on the Chinese security forum called Kanxue in 2019. Figure 9 shows the LsaRecorder command-line options, which include the ability to record a user's logon password.
![A code snippet showing a command line interface options for the LsaRecorder tool, highlighting its capability to capture a user’s logon password.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-11325-174811-9.png) Figure 9. Command-line options of LsaRecorder.

#### DumpIt and Volatility

The attackers behind CL-UNK-1068 attempted to use [DumpIt](https://github.com/MagnetForensics/dumpit-linux), a free multiplatform forensics tool, in combination with the widely known [Volatility](https://github.com/volatilityfoundation/volatility) framework to extract password hashes from memory. As shown in Figure 10, they used DumpIt to dump the victim machine's memory. Next, they used several Volatility modules:

* windows.hashdump: Extracts local user account NTLM password hashes from the SAM registry hive
* windows.registry.lsadump.Lsadump: Dumps LSA Secrets such as service account passwords, cached domain credentials
* windows.registry.cachedump.Cachedump: Dumps cached domain credentials

In addition, in some instances the attackers executed DumpIt and Volatility, using batch scripts named dmp.bat and vo.bat.
![A flowchart of Cortex XDR alert showing the combined use of the DumpIt and Volatility frameworks to extract password hashes from a compromised machine's memory.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-13194-174811-10.png) Figure 10. Cortex XDR alert triggered when attackers used DumpIt and Volatility to dump machine memory and extract password hashes.

#### SQL Server Management Studio Password Export Tool

The sqlstudio.bin file stores saved connection info for Microsoft SQL Server Management Studio (SSMS). Attackers attempted to extract data from this file using a tool named SQL Server Management Studio Password Export Tool, deployed as ssms.exe. This [tool was published](https://www.zcgonvh.com/post/SQL_Server_Management_Studio_saved_password_dumper.html) on a Chinese security blog in 2015.

The attackers ran the tool locally and attempted to exfiltrate the sqlstudio.bin file. They used the certutil -encode command to Base64-encode the file, and the type command to read the encoded file. Figure 11 shows this sequence of events.
![A flowchart of Cortex XDR alert showing the use of a tool to extract saved passwords from SQL Server Management Studio configuration files.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-15321-174811-11.png) Figure 11. Cortex XDR alert triggered when attackers used the SQL Server Management Studio Password Export Tool to extract passwords.

## Conclusion

We assess with high confidence that CL-UNK-1068 represents activity from a threat group that communicates in Chinese. The group behind this activity cluster has been targeting high-value sectors across South, Southeast and East Asia since at least 2020. Using primarily open-source tools, community-shared malware and batch scripts, the group has successfully maintained stealthy operations while infiltrating critical organizations.

This cluster of activity demonstrates versatility by operating across both Windows and Linux environments, using different versions of their tool set for each operating system. While the focus on credential theft and sensitive data exfiltration from critical infrastructure and government sectors strongly suggests an espionage motive, we cannot yet fully rule out cybercriminal intentions.

We advise defenders to move beyond static indicators and focus on behavioral anomalies. Detection logic should be tuned to identify any hallmark techniques. In the case of CL-UNK-1068 activity, signs to detect include:

* Misuse of legitimate Python binaries for side-loading
* Deployment of unauthorized tunneling tools like FRP
* Execution of custom reconnaissance batch scripts

### Palo Alto Networks Protection and Mitigation

Palo Alto Networks customers are better protected from the threats discussed above through the following products and services:

### Cortex Xpanse

[Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) has the ability to identify exposed VMWare vCenter Server devices on the public internet and escalate these findings to defenders. Customers can enable alerting on this risk by ensuring that they've enabled the VMware vCenter Attack Surface Rule. Identified findings can be viewed in the incident view of Expander. These findings are also available for Cortex XSIAM customers who have purchased the ASM module.

#### Cortex XDR Forensics: Linux

The [Forensics](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Forensic-investigations) feature of Cortex XDR enables analysts to perform forensic analysis by collecting all necessary artifacts and displaying them in an intuitive forensics console. This feature also enables in-depth analysis of specific endpoints, to fully understand the activities that occurred. Supported forensic artifacts include environment variables, command history, session history, network connections and file listing. Figure 12 shows the command history of a CL-UNK-1068 interactive attack on a Linux server.
![A command history on a Linux server, captured by Cortex XDR Forensics, detailing an interactive attack by the CL-UNK-1068 threat actor.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-17324-174811-12.png) Figure 12. Command history of a Linux server during a CL-UNK-1068 interactive attack.

#### Cortex XDR Analytics: Linux

The new Cortex XDR [Analytics Engine](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Analytics-engine) enhances behavioral detection for Linux through two key mechanisms:

* Uncommon Linux process communication to a rare external host: This detector flags command-and-control (C2) initiation. Tailored for Linux, it identifies low-prevalence or recurring outbound patterns that are used by advanced threats to maintain network connections.
* Uncommon attempt to discover a sensitive file: This detector identifies credential theft attempts, such as unauthorized access to /etc/hosts and /etc/ssl/private/.\*. This exposes misused utilities and threat actor activity targeting user secrets. Figure 13 displays an "Uncommon attempt" alert that CL-UNK-1068 activity triggered.

![A screenshot of a Cortex XDR security alert flagging an uncommon attempt by the FRP tunneling tool to access sensitive files.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-19529-174811-13.png) Figure 13. Cortex XDR alert for FRP attempting to access /etc/hosts during a CL-UNK-1068 attack.

Other Palo Alto Networks products and services that can help include:

* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) identify known domains and URLs associated with this activity as malicious.
* [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with the [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention) security subscription can help block the attacks with best practices via the following Threat Prevention signature/s 94655, 91671, 91662, 86680, 81881, 81819, 81815, 81816, 81817, 81803
* The [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire) machine-learning models and analysis techniques have been reviewed and updated in light of the indicators shared in this research.
* [Cortex XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) incorporates all [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) features, as well as additional protections.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 000 800 050 45107

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

SHA256 hashes for shellcode loader (m.exe/l.exe)

* 524734501be19e9ed1bfab304b0622a2263a4f9e3db0971f3fae93f7e7369c20

SHA256 hashes for Mimikatz shellcode binary (m.bin)

* 26483f0886078cc9f5f9912d3ffce1301e297b435920ab1c86c9107bbdce4db2
* 99bd09e1c500866b2b809fd9170f1b8b7e120da21a1f2eed6165fcf81bf519b7

SHA256 hashes for LsaRecorder (ls.exe)

* 8a3345f0d8f1a7d78ea485ae11358cf2ae3d51cb7975524d6d67ba05a08a37ea

SHA256 hashes for shellcode loader DLL (python20.dll)

* 6ddbfd3a96834087501f0c9415a925cafdb92cb8ff34685f138833b4795416d6
* 3b2b6a3ee023dfa168f257b292a28f5fbdbacb5aa2250e1efb36e650529db1b5
* cfdcbc553bc7464aedfb6758b0a38acc78d9537eabe9717e60ab0d8d3b355225

SHA256 hashes for web shells

* d8378cf105146217e6ded438187c4ea0edcadb6cf27f5eeddda3fd80cce76d72
* 5c986203242e2ed25458b0606ee7be57070f6d66b7472b453d92b1b6786443bd
* cfcbb3014ecc560ba36103213b36fc62d6b0ef22c49067ff0d860fd7253a7c94
* fb9400d763a009b3bd2b9468410e0c69ee8a4f58400e532f086cef749422210d

SHA256 hashes for SQL Server Management Studio Password Export Tool (ssms.exe)

* c880936ba0ca153719c2cca33c1925a9480d28abc88cf4daa02f34cc8cc1c9e5

SHA256 hashes for ScanPortPlus: Windows version (sp.exe)

* d6ed94589b0e6a7c3e1a6052e18f3962ca78c385c78036972d5ea72c07a5772c
* 3e698c85660e2c012b3db7f47ca3f2b1af2b6b0e0a0d2bdb7903f91cf9d31732  
  0d03934eb181c2befbc5341208c4eb8f939e00382ac632216397b8210225c937

SHA256 hashes for ScanPortPlus: Linux version (sp/spp)

* 8d3907d56b1dd1609053cb55dd66f33499e1ea091133df76d8fe6f08f25f37b2

SHA256 hashes for FRP: Windows version (32.exe)

* 082a55731f972cd15e103104229a68175a8c59a52bae05daa8ed4302df7c2dec

SHA256 hashes for FRP: Linux version (nginx/httpd)

* e1ff808321ce952384b7fff720584c48ec0fd36480d6bc9ac0d5db036102c368
* cdb90179188a142d24147edcb72be8b574fac4f6833fff15a6ee803754dec0c0
* f6ac9e5e76bc9daf4772c5be43c9eac1d2611caafd49fac70bbb8eebfa4781ac

SHA256 hashes for CVE-2023-34048 Python Executable (vc.exe)

* 96f52e4666aa8df67f8d7d00a523cd25e11402108157156775603b3d9514925c
* e9541e8afa502e13c18734756270b10e3c07f1071283387e63c8f8b0ba591343

SHA256 hashes for srunas.exe (srunas.exe)

* f7c73b1ac9aff545b184ec7121f2bc706c5064dc3c17f59e9a39469031bf2ef6

SHA256 hashes for Xnote (80/iptable6)

* b87cee18720c176c1972cf5c74e3c09877177e0c49c34a04b910bb3c70839b71
* f710dc61c2edc85841fd733a17b7977dfb889d6476c59bb3c54a5b2fd393ac13

SHA256 hashes for SuperDump (super.exe/superdump.exe)

* edc0287da3c6bb62a7b2fd3949be5688628fc0e893b5822bd5734a63c39f7ab1
* 0c7db12ec29f333bf5f53dc5c73ec446b2265fca3aad5144c3569409e15123cb

SHA256 hashes for PwnKit (PwnKit.so)

* 8af434c2af2d901694cb27ec8639e7054f84938110a5cc4492c1bac597026d50

SHA256 hashes for PrintProgram

* ce20c033dcadf17d9cca325869f946efdd82ab0756fa56e262b6f573252d457c

SHA256 hashes for Sliver (agent.exe)

* 52c817465a56ccd0fb4e914a3274a9e9a93e872583e6239bc6461e4f3e40c567

IP addresses

* 13\.250.108\[.\]65
* 43\.255.189\[.\]67
* 52\.77.253\[.\]4
* 79\.141.169\[.\]123
* 107\.148.33\[.\]60
* 107\.148.51\[.\]251
* 107\.148.130\[.\]22

## Additional Resources

* [AntSwordProject](https://github.com/AntSwordProject), GitHub
* [Universal Command-Line Interface for SQL Databases (usql)](https://github.com/xo/usql), GitHub
* [Fast Reverse Proxy](https://github.com/fatedier/frp), GitHub
* [PrintSpoofer](https://github.com/itm4n/PrintSpoofer), GitHub
* [Xnote Analysis](https://vms.drweb.com/virus/?i=4372602), Dr.WEB
* [Exposing Earth Berberoka](https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/exposing-earth-berberoka-a-multiplatform-apt-campaign-targeting-online-gambling-sites), Trend Micro
* [What are the differences and connections between CC attacks and DDoS attacks?](https://www.tencentcloud.com/techpedia/117843) Tencent Cloud
* [NTP amplification DDoS attack](https://www.cloudflare.com/learning/ddos/ntp-amplification-ddos-attack/), Cloudflare
* [SYN flood DDoS attack](https://www.cloudflare.com/learning/ddos/syn-flood-ddos-attack/), Cloudflare
* [UDP flood DDoS attack](https://www.cloudflare.com/learning/ddos/udp-flood-ddos-attack/), Cloudflare
* [LSA\_AP\_LOGON\_USER\_EX2 Callback Function](https://learn.microsoft.com/en-us/windows/win32/api/ntsecpkg/nc-ntsecpkg-lsa_ap_logon_user_ex2), Microsoft Learn
* [LsaApLogonUserEx2](https://bbs.kanxue.com/thread-251888.htm), Kanxue Security Forum
* [SQL Server Management Studio Password Export Tool](https://www.zcgonvh.com/post/SQL_Server_Management_Studio_saved_password_dumper.html), Alpaca House (zcgonvh)

## Appendix A: Attribution

Our attribution is based on the victimology, tool set provenance and linguistic indicators found within the malware strings. In accordance with Unit 42's [attribution framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/), we assess with high confidence that a threat actor communicating in Chinese is behind the CL-UNK-1068 activity that we observed.

### Tool Provenance and Community Sources

The group's toolkit includes open-source tools and utilities shared within the Chinese security and hacking communities, including:

* **Web shells**: Authors developed both GodZilla and AntSword using a combination of English and Simplified Chinese. These web shells are derivatives of the China Chopper web shell.
* **Community-sourced utilities**: Tools such as the SQL Server Management Studio Password Export Tool and LsaRecorder were traced back to posts on Chinese security forums and blogs dating back to 2015 and 2019 respectively.

### Linguistic Indicator

Analysis of the FRP tool configuration revealed the unique authentication token frpforzhangwei. Zhang Wei is a common Chinese name.

### Malware

Xnote is a Linux backdoor originally discovered in 2015. According to publicly available documentation, this backdoor has only been used by Chinese threat actors since its discovery.

### Victimology

The targeting of critical industries across South, Southeast and East Asia is [consistent](https://unit42.paloaltonetworks.com/analysis-of-three-attack-clusters-in-se-asia/) with [common](https://unit42.paloaltonetworks.com/advanced-backdoor-squidoor/) goals of China-aligned threat actors.

### Motivation

We assess with moderate-to-high confidence that CL-UNK-1068's primary objective is cyberespionage. This assessment stems from the actor's post-compromise behavior --- specifically, their targeted exfiltration of SQL database content and backups.

The consistent targeting of critical infrastructure and government entities across South, Southeast and East Asia aligns with the interests typically associated with nation-state actors.

While the victimology aligns with state interests, attackers could alternatively have monetized exfiltrated data through extortion or sold on underground markets. As such, it is possible that the threat actor behind CL-UNK-1068 is an independent cybercriminal group or a dual-use actor.

## Appendix B: CL-UNK-1068 Tools and Utilities

The following tools and utilities have been part of CL-UNK-1068 activity across multiple campaigns since 2020.

### Host Reconnaissance Using Batch Scripts (Full Description)

Table 2 lists the commands executed by the a.bat, hp.bat and hpp.bat host reconnaissance batch scripts, the result filenames and the purpose of each command.

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Commands**                                                                                                                                                                                                                                                                                                                                                                                                                | **Results Filename**                            | **Command Purpose**                                                                                                                                              |
| quser  net user net localgroup administrators ipconfig /all netstat -ano tasklist /v ipconfig /displaydns systeminfo C:\\Windows\\system32\\inetsrv\\appcmd.exe list site C:\\Windows\\system32\\inetsrv\\AppCmd.exe LIST vdir C:\\Windows\\system32\\inetsrv\\appcmd.exe list apppool C:\\Windows\\system32\\inetsrv\\appcmd.exe list app C:\\Windows\\system32\\inetsrv\\appcmd.exe list Modules route print arp -a | host.txt                                        | System reconnaissance:  \* User accounts \* System information \* Network information \* Active connections \* Running processes \* Web Server (IIS) Enumeration |
| wevtutil qe security /format:text /q:"Event\[System\[(EventID=4624)\]\]"                                                                                                                                                                                                                                                                                                                                                    | sec.txt                                         | Find all successful logon events from the Windows Security log.                                                                                                  |
| WMIC patd win32\_process get Caption,Processid,Commandline                                                                                                                                                                                                                                                                                                                                                                   | pro.txt                                         | List running processes. Shows the full command line.                                                                                                             |
| wmic LOGICALDISK get name,Description,filesystem,size,freespace  wmic LOGICALDISK get name |findstr :                                                                                                                                                                                                                                                                                                                | disk.txt                                        | Get drive information.                                                                                                                                           |
| C:\\Windows\\system32\\cmd.exe /c dir c:\\users\\ /b                                                                                                                                                                                                                                                                                                                                                                        | dir.txt                                         | List all user profiles on the machine.                                                                                                                           |
| wmic process get name,executablepatd,processid                                                                                                                                                                                                                                                                                                                                                                              | list.txt                                        | List all running processes. Shows the full path.                                                                                                                 |
| reg query HKEY\_USERS                                                                                                                                                                                                                                                                                                                                                                                                        | sid.txt                                         | Query the Windows Registry to list all user profiles currently loaded on the system.                                                                             |
| reg query "HKLM\\Software\\Microsoft\\Windows\\Currentversion\\Uninstall" /s /v Display\*  reg query "HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall" /s /v Display\* reg query "HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall" /s /v Display\*                                                                                                                           | install.txt                                     | Get a list of all installed software.                                                                                                                            |
| reg export "HKEY\_USERS\\\[%SID%\]\\SOFTWARE\\SimonTatdam\\PuTTY\\SshHostKeys"                                                                                                                                                                                                                                                                                                                                               | \[%SID%\].putty.txt                             | Discover servers on the network by dumping the PuTTY SSH connection history.                                                                                     |
| reg export "HKEY\_USERS\\\[%SID%\]\\Software\\Microsoft\\Terminal Server Client"                                                                                                                                                                                                                                                                                                                                             | \[%SID%\].txt                                   | Discover servers on the network by dumping the RDP connection history.                                                                                           |
| reg export "HKEY\_USERS\\\[%SID%\]\\Software\\RealVNC"                                                                                                                                                                                                                                                                                                                                                                       | \[%SID%\].RealVNC.txt                           | Discover servers on the network and steal saved VNC passwords by dumping the RealVNC (remote desktop software) configuration from the registry.                  |
| reg export "HKEY\_USERS\\\[%SID%\]\\SOFTWARE\\TightVNC\\Server" reg export HKEY\_LOCAL\_MACHINE\\SOFTWARE\\Wow6432Node\\TightVNC\\Serverreg export HKEY\_LOCAL\_MACHINE\\SOFTWARE\\TightVNC\\Server                                                                                                                                                                                                                              | \[%SID%\].TightVNC.txt  vnc1.txt vnc2.txt | Steal the passwords for TightVNC (remote desktop software) by dumping the configuration from the registry.                                                       |

Table 2. Commands executed by the host reconnaissance batch scripts, the results filenames and the purpose of each command.

### Additional Batch Scripts Used in CL-UNK-1068 Activity

The attackers behind CL-UNK-1068 frequently used batch scripts to perform various functions. Table 3 details some of tde scripts used.

|---------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Script Purpose and Name**                             | **Function**                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Clear Logs**  \* cl.bat                          | Clear different logs on the system to remove their tracks, as an anti-forensics technique.  The attackers used the Windows Event Utility (wevtutil) commands to clear logs: \* wevtutil cl Security \* wevtutil cl system \* wevtutil cl application \* wevtutil cl setup \* wevtutil cl "windows powershell"                                                                                                                                                     |
| **Query Domain**  \* dom.bat                       | Batch script to execute commands that query domain information such as:  \* net user:$USER$ \* net group /domain \* "net group ""domain admins"" /domain " \* "net group ""enterprise admins"" /domain " \* net localgroup administrators /domain \* "net group ""domain controllers"" /domain " \* "net group ""domain computers"" /domain "                                                                                                                       |
| **Weaken RDP Security**  \* 3389.bat               | Batch script to execute a command that weakens the security of Remote Desktop (RDP) on the target machine (partially redacted to prevent misuse):  reg add "HKEY\_LOCAL\_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-TCP" /v UserAutdentication /t REG\_DWORD /d \[REDACTED\_VALUE\] /f This command disables Network Level Authentication (NLA) for RDP, which makes the server potentially more vulnerable to RDP exploits. |
| **Dumping SAM and SYS Files**  \* sam.bat/sam1.bat | Used to execute the reg save HKLM\\SYSTEM sys.hiv and reg save HKLM\\SAM sam.hiv commands.                                                                                                                                                                                                                                                                                                                                                                         |
| **DumpIt and Volatility**  \* dmp.bat and vo.bat   | Used to execute DumpIt and Volatility.                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **File Archiving**  \* rar.bat/rr.bat              | Batch script to archive the results of other batch scripts. Examples of commands executed are:  \* rar.exe a -df host.rar \*.txt \* rar a -df host.rar \*.txt \*.db \* rar a -df host.rar \*.txt \*.db \*hist\* \*book\*                                                                                                                                                                                                                                        |

Table 3. Additional batch scripts used in CL-UNK-1068 activity.

### Privilege Escalation Methods

This section details the tools and utilities observed in CL-UNK-1068 activity, outlining how the attackers used these components to bypass security measures and escalate privileges.

#### PrintProgram

CL-UNK-1068 attackers used the open-source [PrintSpoofer](https://github.com/itm4n/PrintSpoofer) tool to elevate privileges.

They also used a custom .NET version named PrintProgram to write a web shell with elevated privileges, as Figure 14 shows.
![A screenshot of a code snippet displaying the detection of an anomalous process execution. Within the method, obfuscated code constructs a command-line instruction using JavaScript and ASP.NET directories.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-21443-174811-14.png) Figure 14. Code snippet from PrintProgram showing the command used to write a web shell.

#### srunas.exe

In some intrusions, the attackers used srunas.exe to elevate privileges. This custom tool executes processes with higher privileges by copying the access token from another process, as Figure 15 shows.
![A screenshot of colorful code visualizing network flow or C2 communication patterns associated with the custom FRP variant used by the CL-UNK-1068 Chinese threat actor. The code involves functions for token lookup, privilege assignments, and error handling.statements and function calls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-23424-174811-15.png) Figure 15. Code snippet from srunas.exe showing access token duplication.

#### Sliver Shell Implant

The attackers attempted to use a [Sliver](https://github.com/BishopFox/sliver/tree/master) shell implant to elevate privileges. Sliver is an open-source framework that defenders can use to simulate adversarial activities. The attackers used a Sliver implant that acts as a privilege escalation shell. It attempts to find spoolsv.exe or lsass.exe and uses [parent process ID spoofing](https://attack.mitre.org/techniques/T1134/004/) to spawn cmd.exe as a child of those system processes, either with or without additional command-line arguments. Figure 16 shows a snippet of Sliver code for parent process ID spoofing.
![A screenshot of a Cortex XSIAM dashboard code showing file hashes and network infrastructure related to the CL-UNK-1068 activity cluster.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-25297-174811-16.png) Figure 16. Code snippet showing parent process ID spoofing.

#### PwnKit: CVE-2021-4034

Attackers deployed [PwnKit](https://github.com/ly4k/PwnKit), a self-contained exploit ([CVE-2021-4034](https://nvd.nist.gov/vuln/detail/cve-2021-4034)) to achieve local privilege escalation on Linux systems.

#### Custom Python EXE: CVE-2023-34048

The attackers attempted to use a [Nuitka](https://nuitka.net/)-compiled Python executable, probably to make analysis of this tool more difficult, as Nuitka cannot be fully decompiled to Python code. This appears to be exploitation of [CVE-2023-34048](https://nvd.nist.gov/vuln/detail/cve-2023-34048), a vulnerability in VMware vCenter Server that allows for remote code execution. Figure 17 shows that the tool receives two arguments: a target address and a command to execute.
![A screenshot of command-line application usage guide. It describes the attack chain, from initial web shell access to data exfiltration.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-27046-174811-17.png) Figure 17. CVE-2023-34048 Python executable command-line arguments.
Back to top

### Tags

* [CL-UNK-1068](https://unit42.paloaltonetworks.com/tag/cl-unk-1068/ "CL-UNK-1068")
* [DLL Sideloading](https://unit42.paloaltonetworks.com/tag/dll-sideloading/ "DLL Sideloading")
* [Fast Reverse Proxy](https://unit42.paloaltonetworks.com/tag/fast-reverse-proxy/ "Fast Reverse Proxy")
* [ScanPortPlus](https://unit42.paloaltonetworks.com/tag/scanportplus/ "ScanPortPlus")
* [Xnote](https://unit42.paloaltonetworks.com/tag/xnote/ "Xnote")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild](https://unit42.paloaltonetworks.com/ai-agent-prompt-injection/ "Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild")

### Table of Contents

* 

### Related Articles

* [Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation](https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/ "article - table of contents")
* [Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns](https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/ "article - table of contents")
* [Nation-State Actors Exploit Notepad++ Supply Chain](https://unit42.paloaltonetworks.com/notepad-infrastructure-compromise/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
