[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/darkside-ransomware/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/darkside-ransomware/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/ "Threat Actor Groups")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# DarkSide Ransomware Gang: An Overview

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read  
Related Products  
[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSOAR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSOAR](https://unit42.paloaltonetworks.com/product-category/cortex-xsoar/ "Cortex XSOAR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Ramarcus Baylor](https://unit42.paloaltonetworks.com/author/ramarcus-baylor/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 12, 2021

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [DarkSide](https://unit42.paloaltonetworks.com/tag/darkside/)
  * [DDoS](https://unit42.paloaltonetworks.com/tag/ddos/)
  * [Ransomware threat report](https://unit42.paloaltonetworks.com/tag/ransomware-threat-report/)
  * [Worried Scorpius](https://unit42.paloaltonetworks.com/tag/worried-scorpius/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/darkside-ransomware/?pdf=download&lg=en&_wpnonce=edee969a51 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/darkside-ransomware/?pdf=print&lg=en&_wpnonce=edee969a51 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=DarkSide%20Ransomware%20Gang:%20An%20Overview&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fdarkside-ransomware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdarkside-ransomware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdarkside-ransomware%2F&title=DarkSide%20Ransomware%20Gang:%20An%20Overview "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdarkside-ransomware%2F&text=DarkSide%20Ransomware%20Gang:%20An%20Overview "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fdarkside-ransomware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=DarkSide%20Ransomware%20Gang:%20An%20Overview%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fdarkside-ransomware%2F "Share in Mastodon")

## Executive Summary

It took an attack on a major U.S. pipeline company, and the possibility of disruption in the delivery of gasoline and jet fuel supplies to a large part of the country, to show the world that ransomware attackers are not going to rest on their laurels after shaking down municipal governments, school districts and hospitals.

DarkSide became one of the world's most well-known hacking groups after the [FBI confirmed](https://www.fbi.gov/news/pressrel/press-releases/fbi-statement-on-compromise-of-colonial-pipeline-networks) it is responsible for the highly publicized attack. When a shadowy group can sit halfway across the world and, with a few keystrokes, threaten fuel supplies on the U.S. Eastern Seaboard, then people do begin to take notice.

The impact of this attack is a reflection of the fact that ransomware operators are always on the move -- improving, automating and becoming more effective at targeting larger and larger organizations. And they're getting a lot more money for their efforts. The average cyber ransom paid more than doubled in 2020 -- to $312,493 -- compared to 2019, according to the [2021 Unit 42 Ransomware Threat Report](https://unit42.paloaltonetworks.com/ransomware-threat-report-highlights/). So far in 2021, the average payment has nearly tripled compared to the previous year -- to about $850,000.

DarkSide has helped boost those averages by constantly focusing on ways to optimize its business model in the short time it's been active (we first encountered the group about a year ago). Like [other leading ransomware gangs](https://unit42.paloaltonetworks.com/ransomware-threat-assessments/), DarkSide recently embraced the Ransomware-as-a-Service (RaaS) model. It outsourced code development, infrastructure and operations and turned to the dark web to recruit new staff. As a result, the group can now better focus on getting to know victims and targeting the most valuable types of data at each organization, so it can extract the largest-possible ransom and boost the return on investment in its criminal businesses.

The group started getting the attention of Unit 42 responders around October 2020. Since then, we've been finding its fingerprints in a growing number of cases. What makes DarkSide stand out is that the group has shown discipline we've traditionally only seen with nation-state actors -- once the threat actors are in, they really dig in. That said, researchers have noted DarkSide is likely a criminal network operating out of Russia; no one has yet directly connected this to the Russian government.

It is interesting to note that back in November, one ransomware negotiation firm placed the DarkSide operation on an internal restricted list after it announced plans to [host infrastructure in Iran](https://www.bleepingcomputer.com/news/security/darkside-ransomware-will-now-vet-targets-after-pipeline-cyberattack/) -- because Iran is under U.S. sanctions, facilitating payments to that location might run afoul of the law.

Wherever they may be, there are indications that DarkSide attackers are [highly experienced](https://www.reuters.com/business/energy/ransom-group-linked-colonial-pipeline-hack-is-new-experienced-2021-05-09/) and accomplished in mounting ransomware attacks. They clearly operate at the high end of the ransomware ecosystem, focusing on a smaller pool of victims from whom they can extract steep ransoms.

Palo Alto Networks customers are protected from this threat by:

* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire): All known samples are identified as malware.
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) with:
  * indicators for DarkSide.
  * Anti-Ransomware Module to detect DarkSide encryption behaviors.
  * Local Analysis detection to detect DarkSide binaries.
* Cortex XSOAR: Cortex XSOAR's [**ransomware content pack**](https://blog.paloaltonetworks.com/security-operations/cortex-xsoar-for-automated-ransomware-response/) can immediately help incident response, threat intelligence and SecOps teams to standardize and speed-up post-intrusion response processes. This content pack automates most of the ransomware response steps, allowing the incident response and SecOps teams to add their guidance and input.
* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall): DNS Signatures detect the known command and control (C2) domains, which are also categorized as malware in [URL Filtering](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/web-security).
* [AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus): Tracking related activity using the [DarkSide](https://autofocus.paloaltonetworks.com/#/tag/Unit42.DarkSide) tag.

If you think you may have been impacted, please email [unit42-investigations@paloaltonetworks.com](mailto:unit42-investigations@paloaltonetworks.com) or call (855) 875-4631 to get in touch with the Unit 42 Incident Response team.

## Doubling and Tripling Their Pressure

The DarkSide group is aggressive in pressuring victims to pay. The threat actors don't like to be ignored. If victims don't respond within two or three days, they send threatening emails to employees. If that doesn't work, they start calling senior executives on mobile phones. And then they might threaten to start contacting customers or the press. And if that doesn't work, they might launch DDoS to take down external websites.

DarkSide is one of a growing number of ransomware operators that we have seen push the boundaries of their trade to include these tactics, which we refer to as double and triple extortion (others include [Maze](https://unit42.paloaltonetworks.com/threat-brief-maze-ransomware-activities/), Sodin, [Clop](https://unit42.paloaltonetworks.com/clop-ransomware/), [NetWalker](https://unit42.paloaltonetworks.com/ransomware-threat-assessments/2/) and Conti).

These aggressive techniques build on the pattern of a typical ransomware attack, in which files are encrypted and a ransom is demanded to decrypt them and restore access. Some victims have backed up their data and do not see a need to pay for decryption keys to restore access to corrupted systems. To prepare for that scenario, attackers also exfiltrate sensitive information and study the victim's network so they can up the ante if a target refuses to pay. Then they threaten to release the data or launch a DDoS attack.

DarkSide even purports to operate under a "code of conduct," seeking to position the group as a trustworthy security "partner." When victims pay, the threat actors will do things to demonstrate good will including providing decryption keys or presenting evidence that appears to show they have deleted stolen data. When asked, they will sometimes even tell victims how they got in so security gaps can be closed.

## DarkSide Ransomware: Tactics, Techniques and Procedures

We have seen the following software and tools leveraged by the DarkSide group to gain access to the victims' data:

* Legitimate **remote monitoring and management (RMM)** tools to maintain access into a victim's network, such as AnyDesk and TeamViewer.
* **Reconnaissance tools (ADRecon)** to gather information about victims' Active Directory prior to ransomware encryption.
* A **credential harvesting utility**, Mimikatz, to dump password credentials.
* **PowerShell** to carry out objectives, such as to apply GPO to create a scheduled task to execute the ransomware.
* **Password management utilities**such as Dashlane and LastPass to gain access to additional credentials.
* **Utilities such as SQLDumper.exe** to target SQL Server.
* Victims' **internal messaging software** to contact members of the IT staff.
* **File transferring software** Rclone to exfiltrate data to cloud sharing websites (such as PCloud and MegaSync).

Not many groups target non-Windows based systems, but in early 2021, DarkSide introduced an ESXI version of their ransomware that targets VMware virtual machines (VMs), which many organizations use to leverage server virtualization to reduce operating costs and increase IT productivity.

Why does this matter? While we found that in many cases the client's endpoint security did its job protecting Windows PCs from being encrypted, because the servers were heavily virtualized through VMware's ESXI, the ESXI version of the ransomware made it possible for the DarkSide group to encrypt the virtual infrastructure. The threat actors then essentially shut down applications and services, such as file shares, DNS and email, leaving the victims' networks in a deteriorated state or, worse, not functional.

## What Can We Learn From This?

We've been noting for some time that ransomware attackers are becoming increasingly professionalized, outsourcing code development, infrastructure and C2 operations, as well as operating RaaS. Many of them are organized enough to respond to media inquiries and operate victim hotlines.

As these threat actors continue to up their game, organizations need to follow best practices to safeguard their data and protect against groups such as the DarkSide ransomware gang.

Organizations should also make sure to have an incident response plan in place in case of an attack. Unit 42 offers a [Ransomware Readiness Assessment](https://www.paloaltonetworks.com/ransomware-readiness-assessment) to help organizations get started on bolstering defenses.

Palo Alto Networks customers are protected from this threat by:

* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire): All known samples are identified as malware.
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) with:
  * indicators for DarkSide.
  * Anti-Ransomware Module to detect DarkSide encryption behaviors.
  * Local Analysis detection to detect DarkSide binaries.
* Cortex XSOAR: Cortex XSOAR's [**ransomware content pack**](https://blog.paloaltonetworks.com/security-operations/cortex-xsoar-for-automated-ransomware-response/) can immediately help incident response, threat intelligence and SecOps teams to standardize and speed-up post-intrusion response processes. This content pack automates most of the ransomware response steps, allowing the incident response and SecOps teams to add their guidance and input.
* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall): DNS Signatures detect the known command and control (C2) domains, which are also categorized as malware in [URL Filtering](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/web-security).
* [AutoFocus](https://www.paloaltonetworks.com/cortex/autofocus): Tracking related activity using the [DarkSide](https://autofocus.paloaltonetworks.com/#/tag/Unit42.DarkSide) tag.

## IOCs

Indicators associated with Darkside are available on [GitHub](https://github.com/pan-unit42/iocs/tree/master/Darkside), have been published to the Unit 42 [TAXII](https://stix2.unit42.org/)feed and are viewable via the ATOM Viewer.

## Courses of Action

This section documents relevant tactics, techniques and procedures (TTPs) used with DarkSide and maps them directly to Palo Alto Networks product(s) and service(s). It also further instructs customers on how to ensure their devices are configured correctly.

|-----------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Product / Service** | **Course of Action**                                                                                                                                                                                                                                                                                                |
| **Initial Access, Lateral Movement, Command and Control, Execution, Exfiltration, Persistence, Collection, Privilege Escalation, Discovery, Defense Evasion**                                                                                                                                                                              ||
| **Exploit Public-Facing Application \[T1190\], External Remote Services \[T1133\], Remote Desktop Protocol \[T1021.001\], Web Protocols \[T1071.001\], Multi-hop Proxy \[T1090.003\], Valid Accounts \[T1078\], Phishing \[T1566\], PowerShell \[T1059.001\], Automated Exfiltration \[T1020\], Scheduled Task \[T1053.005\], Archive Collected Data \[T1560\], Automated Collection \[T1119\], Bypass User Account Control \[T1548.002\], Account Discovery \[T1087\] Modify Registry \[T1112\]** ||
| NGFW                  | Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone                                                                                                                                                                                                      |
| NGFW                  | Ensure 'Service setting of ANY' in a security policy allowing traffic does not exist                                                                                                                                                                                                                                |
| NGFW                  | Ensure 'Security Policy' denying any/all traffic to/from IP addresses on Trusted Threat Intelligence Sources Exists                                                                                                                                                                                                 |
| NGFW                  | Ensure that User-ID is only enabled for internal trusted interfaces                                                                                                                                                                                                                                                 |
| NGFW                  | Ensure that 'Include/Exclude Networks' is used if User-ID is enabled                                                                                                                                                                                                                                                |
| NGFW                  | Ensure that the User-ID Agent has minimal permissions if User-ID is enabled                                                                                                                                                                                                                                         |
| NGFW                  | Ensure that the User-ID service account does not have interactive logon rights                                                                                                                                                                                                                                      |
| NGFW                  | Ensure remote access capabilities for the User-ID service account are forbidden                                                                                                                                                                                                                                     |
| NGFW                  | Ensure that security policies restrict User-ID Agent traffic from crossing into untrusted zones                                                                                                                                                                                                                     |
| NGFW                  | Set up File Blocking                                                                                                                                                                                                                                                                                                |
| NGFW                  | Ensure 'SSL Forward Proxy Policy' for traffic destined to the Internet is configured                                                                                                                                                                                                                                |
| NGFW                  | Ensure 'SSL Inbound Inspection' is required for all untrusted traffic destined for servers using SSL or TLS                                                                                                                                                                                                         |
| NGFW                  | Ensure that the Certificate used for Decryption is Trusted                                                                                                                                                                                                                                                          |
| Threat Prevention †   | Ensure a Vulnerability Protection Profile is set to block attacks against critical and high vulnerabilities, and set to default on medium, low and informational vulnerabilities                                                                                                                                    |
| Threat Prevention †   | Ensure a secure Vulnerability Protection Profile is applied to all security rules allowing traffic                                                                                                                                                                                                                  |
| Threat Prevention †   | Ensure that antivirus profiles are set to block on all decoders except 'imap' and 'pop3'                                                                                                                                                                                                                            |
| Threat Prevention †   | Ensure a secure antivirus profile is applied to all relevant security policies                                                                                                                                                                                                                                      |
| Threat Prevention †   | Ensure an anti-spyware profile is configured to block on all spyware severity levels, categories, and threats                                                                                                                                                                                                       |
| Threat Prevention †   | Ensure DNS sinkholing is configured on all anti-spyware profiles in use                                                                                                                                                                                                                                             |
| Threat Prevention †   | Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in use                                                                                                                                                                                                                                 |
| Threat Prevention †   | Ensure a secure Anti-Spyware profile is applied to all security policies permitting traffic to the Internet                                                                                                                                                                                                         |
| Threat Prevention †   | Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned and set to appropriate actions                                                                                                                                                                       |
| Threat Prevention †   | Ensure that User Credential Submission uses the action of 'block' or 'continue' on the URL categories                                                                                                                                                                                                               |
| DNS Security †        | Enable DNS Security in Anti-Spyware profile                                                                                                                                                                                                                                                                         |
| URL Filtering †       | Ensure that URL Filtering is used                                                                                                                                                                                                                                                                                   |
| URL Filtering †       | Ensure that URL Filtering uses the action of 'block' or 'override' on the \<enterprise approved value\> URL categories                                                                                                                                                                                              |
| URL Filtering †       | Ensure that access to every URL is logged                                                                                                                                                                                                                                                                           |
| URL Filtering †       | Ensure all HTTP Header Logging options are enabled                                                                                                                                                                                                                                                                  |
| URL Filtering †       | Ensure secure URL Filtering is enabled for all security policies allowing traffic to the internet                                                                                                                                                                                                                   |
| WildFire †            | Ensure that WildFire file size upload limits are maximized                                                                                                                                                                                                                                                          |
| WildFire †            | Ensure forwarding is enabled for all applications and file types in WildFire file blocking profiles                                                                                                                                                                                                                 |
| WildFire †            | Ensure a WildFire Analysis profile is enabled for all security policies                                                                                                                                                                                                                                             |
| WildFire †            | Ensure forwarding of decrypted content to WildFire is enabled                                                                                                                                                                                                                                                       |
| WildFire †            | Ensure all WildFire session information settings are enabled                                                                                                                                                                                                                                                        |
| WildFire †            | Ensure alerts are enabled for malicious files detected by WildFire                                                                                                                                                                                                                                                  |
| WildFire †            | Ensure 'WildFire Update Schedule' is set to download and install updates every minute                                                                                                                                                                                                                               |
| Cortex XSOAR          | Deploy XSOAR Playbook Cortex XDR - Isolate Endpoint                                                                                                                                                                                                                                                                 |
| Cortex XSOAR          | Deploy XSOAR Playbook - Access Investigation Playbook                                                                                                                                                                                                                                                               |
| Cortex XSOAR          | Deploy XSOAR Playbook - Impossible Traveler                                                                                                                                                                                                                                                                         |
| Cortex XSOAR          | Deploy XSOAR Playbook - Block Account Generic                                                                                                                                                                                                                                                                       |
| Cortex XSOAR          | Deploy XSOAR Playbook - Block URL                                                                                                                                                                                                                                                                                   |
| Cortex XSOAR          | Deploy XSOAR Playbook - Palo Alto Networks - Hunting And Threat Detection                                                                                                                                                                                                                                           |
| Cortex XSOAR          | Deploy XSOAR Playbook - PAN-OS Query Logs for Indicators                                                                                                                                                                                                                                                            |
| Cortex XSOAR          | Deploy XSOAR Playbook - Phishing Investigation - Generic V2                                                                                                                                                                                                                                                         |
| Cortex XSOAR          | Deploy XSOAR Playbook - Endpoint Malware Investigation                                                                                                                                                                                                                                                              |
| Cortex XDR            | Configure Host Firewall Profile                                                                                                                                                                                                                                                                                     |
| Cortex XDR            | Enable Anti-Exploit Protection                                                                                                                                                                                                                                                                                      |
| Cortex XDR            | Enable Anti-Malware Protection                                                                                                                                                                                                                                                                                      |
| Cortex XDR            | Look for the following BIOCs alerts to detect activity\*:  Cortex XDR Analytics - Possible LSASS memory dump Cortex XDR Analytics - Unsigned process executed as a scheduled task Cortex XDR Analytics - Connection to a TOR anonymization proxy Cortex XDR Analytics - Dumping Registry hives with passwords |
| **Discovery**                                                                                                                                                                                                                                                                                                                              ||
| **File and Directory Discovery \[T1083\], Process Discovery \[T1057\]**                                                                                                                                                                                                                                                                    ||
| Cortex XDR            | Look for the following BIOCs alerts to detect activity\*:  Cortex XDR Analytics - Multiple Discovery Commands                                                                                                                                                                                                 |
| **Impact**                                                                                                                                                                                                                                                                                                                                 ||
| **Service Stop \[T1489\], Inhibit System Recovery \[T1490\], Data Encrypted for Impact \[T1486\]**                                                                                                                                                                                                                                         ||
| Cortex XDR            | Look for the following BIOCs alerts to detect activity\*:  Manipulation of Volume Shadow Copy configuration                                                                                                                                                                                                   |
| Cortex XSOAR          | Deploy XSOAR Playbook - Ransomware Manual                                                                                                                                                                                                                                                                           |

*Table 1. Courses of Action for Darkside ransomware.\*\*†These capabilities are part of the NGFW security subscriptions service.* *\* These analytic detectors will trigger automatically for Cortex XDR Pro customers.*

Back to top

### Tags

* [DarkSide](https://unit42.paloaltonetworks.com/tag/darkside/ "DarkSide")
* [DDoS](https://unit42.paloaltonetworks.com/tag/ddos/ "DDoS")
* [Ransomware threat report](https://unit42.paloaltonetworks.com/tag/ransomware-threat-report/ "ransomware threat report")
* [Worried Scorpius](https://unit42.paloaltonetworks.com/tag/worried-scorpius/ "Worried Scorpius")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: File Transfer Threats: Risk Factors and How Network Traffic Visibility Can Help](https://unit42.paloaltonetworks.com/file-transfer-threats/ "File Transfer Threats: Risk Factors and How Network Traffic Visibility Can Help")

### Table of Contents

* 

### Related Articles

* [Unit 42 Ransomware and Extortion Report Highlights: Multi-Extortion Tactics Continue to Rise](https://unit42.paloaltonetworks.com/multi-extortion-rise-ransomware-report/ "article - table of contents")
* [Understanding REvil: REvil Threat Actors May Have Returned (Updated)](https://unit42.paloaltonetworks.com/revil-threat-actors/ "article - table of contents")
* [2022 Unit 42 Ransomware Threat Report Highlights: Ransomware Remains a Headliner](https://unit42.paloaltonetworks.com/2022-ransomware-threat-report-highlights/ "article - table of contents")

## Related Ransomware Resources

![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Constellation image representing the constellation schema used by Palo Alto Networks Unit 42 to track nation-state and cybercrime threat actor groups](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/Generic-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) August 1, 2025 [#### Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/)

* [Academic Serpens](https://unit42.paloaltonetworks.com/tag/academic-serpens/ "Academic Serpens")

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agonizing Serpens](https://unit42.paloaltonetworks.com/tag/agonizing-serpens/ "Agonizing Serpens")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)")  
  ![Pictorial representation of Unit 42 threat attribution system. Illustration featuring a white triangle centered within an abstract cosmic background of purple and blue swirls and stars.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/Generic-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) July 31, 2025 [#### Introducing Unit 42's Attribution Framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Bookworm](https://unit42.paloaltonetworks.com/tag/bookworm/ "Bookworm")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/ "Introducing Unit 42’s Attribution Framework")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![A pictorial representation of Akira ransomware, distributed by Howling Scorpius. A person's hand typing on a keyboard with a digital screen displaying the word "password" highlighted in blue, set against a backdrop of various cybersecurity interface graphics.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/09_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) December 2, 2024 [#### Threat Assessment: Howling Scorpius (Akira Ransomware)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/)

* [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/ "Howling Scorpius")

* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")

* [Torrenting](https://unit42.paloaltonetworks.com/tag/torrenting/ "torrenting")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/ "Threat Assessment: Howling Scorpius (Akira Ransomware)")  
  ![Pictorial representation of a threat like BlackSuit ransomware. An illustration of a modern workspace with a laptop displaying cybersecurity icons, surrounded by stacks of coins and a credit card, all depicted in a neon, digital art style.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/04_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) November 20, 2024 [#### Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/)

* [BlackSuit ransomware](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/ "BlackSuit ransomware")

* [Construction](https://unit42.paloaltonetworks.com/tag/construction/ "construction")

* [Education](https://unit42.paloaltonetworks.com/tag/education/ "Education")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/ "Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware")  
  ![A representation of a threat group like Jumpy Pisces. Illustrative image featuring two fish and the Pisces constellation superimposed on a stylized, abstract background with flowing purple waves and a starry night sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/Pisces-NK-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) October 30, 2024 [#### Jumpy Pisces Engages in Play Ransomware](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/ "Jumpy Pisces")

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/ "Jumpy Pisces Engages in Play Ransomware")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
