[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/ "Cybercrime")  
  [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)

# Examining the Cybercrime Underground, Part 1: Crypters

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Tomer Bar](https://unit42.paloaltonetworks.com/author/tomer-bar/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:February 19, 2015

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [419 Evolution](https://unit42.paloaltonetworks.com/tag/419-evolution/)
  * [Crypter](https://unit42.paloaltonetworks.com/tag/crypter/)
  * [Cybercrime Underground](https://unit42.paloaltonetworks.com/tag/cybercrime-underground/)
  * [DarkComet](https://unit42.paloaltonetworks.com/tag/darkcomet/)
  * [DataScrambler](https://unit42.paloaltonetworks.com/tag/datascrambler/)
  * [LightCore](https://unit42.paloaltonetworks.com/tag/lightcore/)
  * [Remote Administration Tools](https://unit42.paloaltonetworks.com/tag/remote-administration-tools/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/examining-cybercrime-underground-part-1-crypters/?pdf=download&lg=en&_wpnonce=92524fc9d4 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/examining-cybercrime-underground-part-1-crypters/?pdf=print&lg=en&_wpnonce=92524fc9d4 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Examining%20the%20Cybercrime%20Underground,%20Part%201:%20Crypters&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fexamining-cybercrime-underground-part-1-crypters%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fexamining-cybercrime-underground-part-1-crypters%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fexamining-cybercrime-underground-part-1-crypters%2F&title=Examining%20the%20Cybercrime%20Underground,%20Part%201:%20Crypters "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fexamining-cybercrime-underground-part-1-crypters%2F&text=Examining%20the%20Cybercrime%20Underground,%20Part%201:%20Crypters "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fexamining-cybercrime-underground-part-1-crypters%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Examining%20the%20Cybercrime%20Underground,%20Part%201:%20Crypters%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fexamining-cybercrime-underground-part-1-crypters%2F "Share in Mastodon")
  *This post is the first in a new series titled [**Examining the Cybercrime Underground**](https://blog.paloaltonetworks.com/tag/cybercrime-underground/). Each post will delve into different aspects of how cybercriminals operate, using current examples of tools and techniques.* *What are their tools of the trade? How do they get them? How do they overcome challenges posed by security and anti-fraud systems? How do criminals profit from scams and turn stolen data into cash? Answering these questions will help readers better understand one of their primary cyberadversaries and use that knowledge to better protect their networks.*

### What is a crypter?

Crypters are software tools that use a combination of encryption, obfuscation, and code manipulation of malware to make them FUD (Fully Undetectable) by legacy security products.

### Why do attackers use crypters?

To understand the role that crypters play in cybercrime, it's helpful to try to understand the cybercriminal mindset. The Holy Grail for cybercriminals is fully undetectable malware that would allow them to use the same malware repeatedly without being detected by a security solution. They also want their attacks randomized to make sure that the failure of one attack won't affect the outcome of attacks against other victims.

Knowing this, let's look at a common attack scenario used by cybercriminals. Cybercriminals often use Remote Administration Tools (RAT) to steal online banking credentials, credit card numbers, personal data, or other valuable pieces of information. One of the oldest and and most widely used RAT is DarkComet. This tool lets criminals perform a variety of functions including:

* Steal passwords and credit card numbers
* Download, upload, delete, and rename files
* Install viruses and worms
* Edit a computer's registry
* Silently install applications
* Log keystrokes or install keystroke capture software
* Open a CD-ROM tray
* Control the mouse or keyboard
* Record sound with a connected microphone
* Record video with a connected webcam
* Shutdown, restart, or log-off the computer
* Record and control a victim's screen remotely
* View, kill, and start tasks in task manager

This screen shot, for example, shows an attacker eavesdropping on a webcam session using a RAT on the attacker's CNC server:

[![crypter2](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter21-500x252.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter21.png)

[![crypter1](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter1.jpg)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter1.jpg)

But using DarkComet is a problem for the attacker's perspective, because almost any legacy security solution can detect it.

For example, this DarkComet sample has 47/56 detection rate from VirusTotal.com

sha256 - 2e93eb3e3266cf53280ba7314eefb5727fbe0277fe7ccba53d2e5355417a76f0

[![crypter3](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter3.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter3.png)

However, using crypters will allow the cybercriminal to bypass legacy security solutions and use the DarkComet tool undetected.

### Famous Crypters

How does a newbie cybercriminal find himself a crypter? It's surprisingly easy. A Google search for "fud crypter download" yielded 152,000 results, including places where crypter software can be purchased just as easily as a legitimate software download.

[![crypter4](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter4.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter4.png)

[![crypter5](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter5-500x330.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter5.png) [![crypter6](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter6-500x290.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter6.png)

Palo Alto Networks researchers recently detected a new cybercrime campaign using the notorious DataScrambler crypter, previously disclosed and analyzed in the Unit 42 research paper [419 Evolution](https://connect.paloaltonetworks.com/adversary-report).

### Data scrambler updates

It seems that since the publication of our [report](https://www.paloaltonetworks.com/resources/research/419evolution.html) the crypter developer/seller rebranded the crypter "LightCore" as "DataScrambler."

[![crypter7](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter7-500x234.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter7.png)

LightCore crypter GUI on the left compared to DataScrambler GUI on the right.

#### Features comparison

LightCore feature list is identical to the DataScrambler's feature list mentioned in the [419 Evolution](https://connect.paloaltonetworks.com/adversary-report) paper. Even the order in which the features are listed order remained the same:

[![crypter8](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter8.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter8.png)

This is the promotions website page content:

*"Welcome to DataScrambler!"*

*DataScrambler is the most advanced crypter on the market and has tons of features for a cheap price. You cannot go wrong with our product and on top of the cheap prices, you get free support and updates.*

#### Full support for "customers"

The "semi-commercial" seller offers full support services, and the following is one attacker's instructions for his "customers":

*"I want to make it clear to all customers, in case the crypted file should become detected, it will be updated within 48 hours. Please do not post your issues or detections in the sales thread. For help with DataScrambler, click on the help button, Please read the guide before contacting me."*

#### *Term*s of service comparison

Also identical:  
[![crypter9](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter9.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter9.png)

### Original Crypter developer/seller identity

As it seems that the original DataScrambler developer/seller has changed, there are two different scenarios:

1. The original developer is using a new identity, or
2. The original developer sold the crypter code/copyrights to another developer/seller

Based on publicly available data, the original identity behind DataScrambler is:

Name: Mace Michael  
Street: 1807 Frederiksberg C  
Postal Code: 1529  
City: Koebenhavn  
Country: DK  
Phone: +4523702947  
Email: [macekings@gmail.com](mailto:macekings@gmail.com)MSN:**theheadmaster151@live.com** Skype:**supporter747**

We also connected him to other Crypters that he apparently sold. TITANCRYPTER.COM is written in his name.

ADDAM\`S FUD CRYPTER | FUD More Than 1 Month | BYPASS KIS-AVG | Extension Changer

Information:  
[Kaspersky Test](https://www.youtube.com/watch?v=-vLbNchctlc) (DarkComet bypass kis2012)  
[Sonar Test](https://www.youtube.com/watch?v=5sayQPtm2Mc)[Avg Test](https://www.youtube.com/watch?v=b76V62wrmiw)[Extension Changer](https://www.youtube.com/watch?v=XggBVbx1bQY)MSN **: theheadmaster151@live.com** Skype **: supporter747** - the same as the contact of Data Scrambler

#### Client Mesh RAT

*"I am Reseller on Client Mesh RAT also*

*TO GET SPECIAL DISCOUNT USE THE COUPON CODE 'head2015' WHEN CHECKING OUT TO BUY IT FOR $35 ONLY!*

*https://www.sinister.ly/Thread-ClientMesh-RAT-In-Built-FUD-Crypter-Stable-DDoSer-No-PortForwading-40-Lifetime*

*this market is managed by unverified@hotmail.com*

*Contact Information:*  
*MSN : **theheadmaster151@live.com***  
*Skype : **supporter747**" - the same as the contact of Data Scrambler*

### The current Crypter developer/seller identity

[![crypter10](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter10-500x283.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter10.png) [![crypter11](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter11-500x296.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter11.png)

This person mentioned that in the past he worked for Cheetah Mobile (the number two Internet and mobile security company in China which is not related to this crypter in any way). But we can assume the developer's security knowledge and experience was to develop this crypter.

### Case study: the saga continues

A recent attack using advanced crypter starts by spear phishing with RAR attachment:

*Inquiry No: QP #1400358.1 URGENT INQUIRIES*

*Expand Messages*

*Jason Clerk*  
*Apr 23, 2014*  
*1 Attachment 1.8 MB*  
*1.8 MB*

***New Purchase Order.rar***

*Dear,*

*Please quote us your best price for the following items, if this order*

*will be possible to be moves up in one week? Buyer wants them urgent!*

*You will find the Artwork and the new purchase order at this LINK:*

*See attached on the LINK you will find the new order:*

*LINK: https://app.box.com/s/xxxxxxxxxxxxxxxxxxxxxx*

*Please state of the following:*

*Price Validity*

*Price Term*

*.......*

*Yours Faithfully*  
*for DENAI SUPPLY \& SERVICES LTD*

*Jason Clerk*  
*Sourcing Procurement Clerk*  
*E-mail :jason.clerk@...; sales@...*  
*H/P : 011-15762383*  
*DENAI SUPPLY \& SERVICES LTD ....*

### Exposing the attacker

In another attack, the attacker sent the spear phishing mail under a stolen identity, "GPS Trading" company founder and CEO, Mr. Panos Dimitriadis. The attachment name is Quotation\_inquiry.scr (also sent to [import\[at\]gpstrading.com](mailto:import@gpstrading.com)).

Please note that GPSTrading Company is not connected to this attack and the attacker used their CEO's identity in an effort to exploit the victim's trust and to increase the infection's probability of success.

We have discovered the following new attacks, publicly unknown so far, using those sha256 hashes:

a3cedb916a21c89b6c17bf1a816d5e9dcbf0fd3ce5a7d42b449758d45788165a

02c80443fb49915b1943b44ab8ec4dce5b1ca53f3fcdb84fae23abcf45d34a66

f2991b653686dee801b1fb4163cc46343aa8cfdcc601b9a9acc31399e7548af5

38ccb84bfc5899317926b7384904c1987dcd6cf70397850050fafa34b1c85134

2b66b0aadabc85736226382a47972bfb950861ec0d218d7c5c45fd8ca6594717

623815f40ffceaec8eb08294750c89ad94a54694414fd8a70a965a71e122fc69

The CNC Server address won't be published here because it's still active. It is a Windows based server with FTP, cifs and Windows terminal server interfaces.

### In-depth analysis

The file attached to the email "**New Purchase Order.rar"** contains: **first stage** SFX**infector - sample.exe**

sha256 - 02c80443fb49915b1943b44ab8ec4dce5b1ca53f3fcdb84fae23abcf45d34a66 unknown to VirusTotal.com

sample.exe is SFX (self-executable) with a fake pdf icon that contains one executable file and many others with random extensions:

[![crypter12](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter12-500x341.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter12.png)

The SFX contains a lot of junk commands (for bypassing legacy security solutions) but in the in the middle it hides the command to auto-execute dmpbr.exe with parameter dhwdv.gko. This is one of the files in the SFX.

#### AutoIt application - Dmpbr.exe

This is a verified and signed AutoIt application:

sha256 - fb73a819b37523126c7708a1d06f3b8825fa60c926154ab2d511ba668f49dc4b

It's a benign file although on Virus Total it scores 2/56 (2 false positive from VirusTotal.com).

#### Crypter's first stage - dhwdv.gko

AutoIt script -- this is the crypter's first stage.

sha256 - f8dc0013a94017cc19b8f865948daf83b64692db47199a994efab032d8b737f3 unknown to VirusTotal.

The file contains a lot of junk data to bypass legacy security solutions by using obfuscated commands (like raw 435)

[![crypter13](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter13-500x434.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter13.png)

The script reads data from the other scripts (extracted from the SFX file) which in turn read data from another script and so on. In the end, a final obfuscated crypter script is built.

We successfully de-obfuscated the final script. For example, all strings internal AutoIt functions and Windows API functions used by the crypter are obfuscated with a simple but working algorithm (reverse hex bytes and decode them to ASCII strings).

This is a simple python tool we scripted to DE-obfuscate the strings:

[![crypter14](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter14-500x386.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter14.png)

### Final Crypter file

sha256- 082b41f71cc5a5118e1f70f49e059763d48fc072e7fc28f8efb11076537461f3 is 3/52 from VirusTotal (but it is textual so can be changed without much effort by the attacker).

This crypter supports:

Decrypt DarkComet with RC2 decryption algorithm in memory, check the registry for the default browser, creates browser process suspended, write DarkComet to verified signed browser process, uses setThreadContext to change the execution flow to the injected code and resume the process and delete itself.

[![crypter15](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter15-500x383.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter15.png)

**The result is signed browser executable** (in our case it is Chrome and signed by Google  
1c9e1a3aef25e34ea0fda67d3840c53a5449d63db6e9070f6dfc66f2fef92b15 0/55) **that connects to DarkComet CNC execute attackers command**.

No unsigned file is written to disk beside the AutoIt obfuscated textual files and signed trusted AutoIt.

The crypter adds its own capabilities (beside DarkComet) by reading the commands from YMQGIX, an INI file:

[![crypter16](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter16-500x238.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter16.png)

Commands include:

* Anti-sandbox
* Facebook password stealing
* Disable task manager (not working on the analyzed sample, because of attackers misspellings, (check wrong process name instead of taskmgr.exe)
* Disable system restore
* Anti-Emulator

We suspect we found a bug in the anti-emulator code. It works by opening mshta.exe seven times and killing it and then loops until those processes are killed, but it is unclear why the author assumes that will protect him from emulators.

See crypter's code of anti-emulator function:

[![crypter17](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter17-500x223.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter17.png)

#### Anti-VM, download and execute of another malware

[![crypter18](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter18-500x239.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter18.png)

#### INI config file - YMQGIX

INI commands and settings for crypter

sha256 - c547ad05ebed04bad9e5509cb979413fb05c88bfab6313ef110a00b035de9aad is unknown to VirusTotal.

[![crypter19](http://blog.paloaltonetworks.com/wp-content/uploads/2015/02/crypter19-500x289.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/02/crypter19.png)

#### rc2 encrypted malware extap

rc2 encrypted malware decrypted by the crypter on runtime

sha256-7f88d9a894da7b2ccfb331d223307cc0c94730849f4b58a8fa43513ba98c4b63 unknown to VirusTotal.

### Conclusion

The cybercrime underground is evolving, and enterprises using legacy security solutions won't be protected without a next-generation enterprise security platform. Our next post on the cybercrime underground will be focused on the after-attack phases, including how attackers use victims' credit card data to steal money, and the current state of the phishing market underground.
Back to top

### Tags

* [419 Evolution](https://unit42.paloaltonetworks.com/tag/419-evolution/ "419 Evolution")
* [Crypter](https://unit42.paloaltonetworks.com/tag/crypter/ "crypter")
* [Cybercrime Underground](https://unit42.paloaltonetworks.com/tag/cybercrime-underground/ "Cybercrime Underground")
* [DarkComet](https://unit42.paloaltonetworks.com/tag/darkcomet/ "DarkComet")
* [DataScrambler](https://unit42.paloaltonetworks.com/tag/datascrambler/ "DataScrambler")
* [LightCore](https://unit42.paloaltonetworks.com/tag/lightcore/ "LightCore")
* [Remote Administration Tools](https://unit42.paloaltonetworks.com/tag/remote-administration-tools/ "Remote Administration Tools")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Palo Alto Networks Researcher Identifies 3 Critical Internet Explorer Vulnerabilities](https://unit42.paloaltonetworks.com/palo-alto-networks-researcher-identifies-3-critical-internet-explorer-vulnerabilities/ "Palo Alto Networks Researcher Identifies 3 Critical Internet Explorer Vulnerabilities")

### Related Articles

* [SilverTerrier: 2019 Nigerian Business Email Compromise Update](https://unit42.paloaltonetworks.com/silverterrier-2019-update/ "article - table of contents")
* [Exploring the Cybercrime Underground: Part 4 - Darknet Markets](https://unit42.paloaltonetworks.com/unit42-exploring-cybercrime-underground-part-4-darknet-markets/ "article - table of contents")
* [Exploring the Cybercrime Underground: Part 3 -- Into the RAT Nest](https://unit42.paloaltonetworks.com/unit42-exploring-cybercrime-underground-part-3-rat-nest/ "article - table of contents")

## Related Cybercrime Resources

![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 28, 2026 [#### 2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/)

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")

* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface")  
  ![Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 27, 2026 [#### Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")  
  ![Pictorial representation of the APT Boggy Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 16, 2026 [#### Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Boggy Serpens](https://unit42.paloaltonetworks.com/tag/boggy-serpens/ "Boggy Serpens")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "Boggy Serpens Threat Assessment")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) February 10, 2026 [#### A Peek Into Muddled Libra's Operational Playbook](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/tag/scattered-spider/ "Scattered Spider")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/ "A Peek Into Muddled Libra’s Operational Playbook")  
  ![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) January 29, 2026 [#### Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "Understanding the Russian Cyberthreat to the 2026 Winter Olympics")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Pictorial representation of Gh0st RAT malware. A woman analyzes code on a computer screen in an office setting, with another individual working in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/04_Security-Technology_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 14, 2025 [#### Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT](https://unit42.paloaltonetworks.com/impersonation-campaigns-deliver-gh0st-rat/)

* [DLL Sideloading](https://unit42.paloaltonetworks.com/tag/dll-sideloading/ "DLL Sideloading")

* [Gh0st Rat](https://unit42.paloaltonetworks.com/tag/gh0st-rat/ "Gh0st Rat")

* [PDNS](https://unit42.paloaltonetworks.com/tag/pdns/ "PDNS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/impersonation-campaigns-deliver-gh0st-rat/ "Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
