[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)
* [Spanish (LATAM)](https://unit42.paloaltonetworks.com/es-la/iranian-cyberattacks-2026/)
* [French](https://unit42.paloaltonetworks.com/fr/iranian-cyberattacks-2026/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![App-ID icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)App-ID](https://unit42.paloaltonetworks.com/product-category/app-id/ "App-ID")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Cloud](https://unit42.paloaltonetworks.com/product-category/cortex-cloud/ "Cortex Cloud")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Cortex XSOAR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSOAR](https://unit42.paloaltonetworks.com/product-category/cortex-xsoar/ "Cortex XSOAR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:April 17, 2026

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Hacktivism](https://unit42.paloaltonetworks.com/category/hacktivism/)
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [APK](https://unit42.paloaltonetworks.com/tag/apk/)
  * [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/)
  * [GenAI](https://unit42.paloaltonetworks.com/tag/genai/)
  * [Hacktivism](https://unit42.paloaltonetworks.com/tag/hacktivism/)
  * [Iran](https://unit42.paloaltonetworks.com/tag/iran/)
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [Tarnished Scorpius](https://unit42.paloaltonetworks.com/tag/tarnished-scorpius/)
  * [Wiper](https://unit42.paloaltonetworks.com/tag/wiper/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/?pdf=download&lg=en&_wpnonce=f6e4b1f2e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/?pdf=print&lg=en&_wpnonce=f6e4b1f2e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=Threat%20Brief:%20Escalation%20of%20Cyber%20Risk%20Related%20to%20Iran%20(Updated%20April%2017)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Firanian-cyberattacks-2026%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Firanian-cyberattacks-2026%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Firanian-cyberattacks-2026%2F&title=Threat%20Brief:%20Escalation%20of%20Cyber%20Risk%20Related%20to%20Iran%20(Updated%20April%2017)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Firanian-cyberattacks-2026%2F&text=Threat%20Brief:%20Escalation%20of%20Cyber%20Risk%20Related%20to%20Iran%20(Updated%20April%2017)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Firanian-cyberattacks-2026%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=Threat%20Brief:%20Escalation%20of%20Cyber%20Risk%20Related%20to%20Iran%20(Updated%20April%2017)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Firanian-cyberattacks-2026%2F> "Share in Mastodon")

## Updates

### Update April 17, 2026

As of April 17, 2026, Iran has [begun restoring limited access to the internet](https://www.business-standard.com/world-news/iran-restores-limited-internet-connectivity-in-rare-move-to-stem-war-losses-126041500093_1.html) after disconnecting from it for the past [47 days](https://netblocks.org/). Iran is limiting domestic access to only websites and applications mirrored on its [National Information Network](https://en.wikipedia.org/wiki/National_Information_Network).

#### Iranian Threat Groups Renew Interest in Critical Infrastructure

In late March 2026, Unit 42 discovered a new cluster of threat activity we are tracking as CL-STA-1128 (aka Cyber Av3ngers, Storm-0784). The attacker behind this activity targeted operational technology and industrial control systems (OT/ICS) equipment manufactured by Rockwell Automation. This activity represents a shift from the cluster's historic focus on internet-connected Unitronics programmable logic controllers (PLCs).

* Unit 42 assesses with moderate confidence that the attacker behind the CL-STA-1128 activity installed Rockwell Automation's FactoryTalk software on virtual private server (VPS) infrastructure to enable their exploitation efforts. FactoryTalk is a suite of industrial automation tools and manufacturing operations management software. Our assessment is based on a review of the unique port combinations observed across all of the hosts and their correlation to known static mappings for the FactoryTalk software.
* Since April 1, [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse/attack-surface-management) scanning has observed Rockwell Automation or Allen-Bradley SCADA devices, including FactoryTalk services and various PLCs, on 5,600 IP addresses globally.
* On April 7, the U.S. Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) [released an advisory](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a) mirroring our findings. In particular, CISA noted that Cyber Av3ngers was also exploiting PLCs manufactured by Allen-Bradley.
* Since April 8, Xpanse has observed approximately 300,000 services daily in Iranian IP space, up from approximately 20,000 since February 25. Though still an order of magnitude less than peak activity observed in early- and mid-February, the increased activity is consistent with reports of limited restored access in the country.

#### Timing of Destructive Attacks

We have added more information about the timing of destructive attacks conducted by Iranian threat actors to the [Appendix](#post-174415-_4j242l3bwbnr).

### Update March 26, 2026

Unit 42 conducted an in-depth investigation into conflict-themed phishing lures identifying 7,381 related phishing URLs spanning 1,881 unique hostnames.

Recent threat activity demonstrates a widespread wave of financial fraud, credential harvesting and illicit content distribution targeting both enterprise and consumer sectors. Threat actors are heavily relying on the impersonation of highly trusted entities including major telecommunications providers, national airlines, law enforcement and critical energy corporations, to deceive victims.

The operations leverage agile evasion tactics, including top-level domain rotation, subdomain chaining and purpose-built infrastructure designed to mimic official corporate portals and government payment workflows. Furthermore, attackers are opportunistically exploiting current geopolitical events with conflict-themed lures to facilitate widespread donation and cryptocurrency scams. Ultimately, this activity highlights a sophisticated, multi-pronged approach to exploiting regional brand trust for financial and data theft.

We discuss these details in more detail in the section [Current Scope of the Attacks -- March 2026.](#post-174415-_50343o6a6han)

## Executive Summary

On Feb. 28, 2026, the United States and Israel launched a significant joint offensive code named Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel). In the hours following the initial strikes, Iran began a multi-vector retaliatory campaign, which has evolved into a significant transregional conflict. Unit 42 has observed an escalation in [cyberattacks from activists](#post-174415-_i4gh78qy6htb) outside the country. While threat activity from nation-state groups based within the country was likely stalled for hours to days, we assess with high confidence these groups [likely shifted to using very-small-aperture terminal (VSAT) services through Starlink](https://www.beyondtrust.com/blog/entry/threat-advisory-operation-epic-fury#:~:text=Check%20Point%20Research%20observed%20Handala%20campaigns%20originating%20from%20Starlink%20IP%20ranges%20during%20Iran%27s%20internet%20blackout%20in%20January%202026) and possibly other providers to resume their operational tempo.

As of April 17, 2026, Iran began restoring access to the internet to limited segments of its population, ending a 47-day near-complete internet outage. For Iran-aligned threat actors based outside of the region, we continue to assess that hacktivist groups will target organizations perceived as adversaries but their impact is likely to be of low to medium significance. Other nation-state-aligned threat actors may attempt to exploit the situation to activate cyberattacks to further their own interests.

Geographically dispersed operators and affiliated cyber proxies may also target governments in regions hosting U.S. military bases to disrupt logistics. In the near term, these activities are expected to consist of low-to-medium sophistication disruptions (for example, distributed denial of service and hack and leak campaigns).

For details on Unit 42's previous observations of cyber activity linked to Iran-backed groups and hacktivists, see the [Threat Brief: Escalation of Cyber Risk Related to Iran (Updated June 30)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2025/). That report details Iran-backed groups and hacktivists expanding their global cyber operations using website defacement, distributed-denial-of-service (DDoS) attacks, and data exfiltration and wiper attacks. The primary objectives of [Iran-aligned nation-state actors](https://docs.google.com/document/d/1A7zxGMZsRI2mLk02kpIuYko-BfGGnhKqKSE-5ZgImwI/edit?tab=t.0#heading=h.ami3q1ldy3z1) frequently include espionage and disruption. Techniques include using AI-enhanced targeted spear-phishing campaigns, the exploitation of known vulnerabilities, and the use of covert infrastructure for espionage.

Palo Alto Networks customers can receive protections from and mitigations for relevant threat actor activity through the following products and services:

* Next-Generation Firewalls with [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration)
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-url-filtering) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) identify known URLs and domains associated with this activity as malicious
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR), [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) and [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)
* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse/attack-surface-management)
* [Device Security](https://www.paloaltonetworks.com/network-security/device-security)

The [Unit 42 Incident Response](https://start.paloaltonetworks.com/contact-unit42.html) team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.

| **Related Unit 42 Topics** | [**Hacktivism**](https://unit42.paloaltonetworks.com/tag/hacktivism/), **[DDoS Attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/)** , [**Wipers**](https://unit42.paloaltonetworks.com/tag/wiper/), [**Phishing**](https://unit42.paloaltonetworks.com/tag/phishing/) |
|----------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Scope of Cyberattacks in March 2026

### Conflict-Themed Domains

Attackers have registered new conflict-themed domains, numbering in the thousands. They are being used for malicious purposes, including creating fake storefronts, running donation scams and hosting phishing portals. Screenshots of these domains are shown in Figures 1 and 2.

![Scam website homepage for Science Forward Iran, highlighting global support for Iranian science and Gaza aid through cryptocurrency donations. Includes options to "Start Donating" and "Learn More.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-383588-174415-1.png) Figure 1. Scam website iranforward\[.\]org asking for humanitarian aid in the form of cryptocurrency donations. ![Scam webpage for "Iran Crisis Support" with a focus on assisting Iranian families in communication and accessing supplies during crises. The page features statistics such as "500,000+ Iranians Connected Safely," "700+ Families Supported," and "24/7 Emergency Support." There are buttons for "Donate via Bank Transfer" and "View Crisis Updates." A note below mentions that no online payments are accepted, urging direct bank transfers only.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-386585-174415-2.png) Figure 2. Scam domain trumpvsirancoin\[.\]xyz requesting humanitarian aid for Iranian families affected by the war.

### Emirates-Focused Crypto and Financial Fraud

Palo Alto Networks has identified two separate malicious campaigns targeting people in the United Arab Emirates (UAE).

* One campaign involves financial fraud exploiting brands with "Emirates" in the name.
* The second consists of crypto and investment scams using domains branded with the word "Dubai," which leverage lures related to high-value real estate and luxury lifestyles.

Figures 3 and 4 below show examples of scam domains for asset management and banking.

![Scam website homepage of Emirates Crypto Bank displaying 'Institutional Digital Asset Management' services. Buttons for accessing the client portal and more information are present. Cryptocurrency icons and prices are listed at the bottom.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-389080-174415-3.png) Figure 3. Scam domain emiratescryptobank\[.\]com. ![Scam webpage of Emirates Trust Investment Union Bank. The header includes navigation links for personal and business banking, as well as a login option. The main section displays an advertisement for "Dream Checking" with the tagline "Fly away from complicated charges." Below, there are icons for checking, savings \& money market, time deposit, and lending. A sidebar chat option is visible.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-393096-174415-4.png) Figure 4. Scam domain emiratesinvestunion\[.\]com.

### Targeted Regional Enterprise Impersonation

We've observed two campaigns targeting a regional telecommunication brand corporate portal with impersonation, using a fake dialing-code prefix to replicate the company's enterprise portal. We also identified a billing fraud campaign masquerading as the same company. These attackers registered the same domain concept across multiple top-level domains, rotating as each is blocked.

We are tracking a wave of targeted attacks against leading organizations in Saudi Arabia. The attackers are deploying a dual-pronged strategy:

* Highly tailored enterprise credential phishing that mimics major enterprise resource planning (ERP) brands to trick employees
* Widespread financial fraud

These broader schemes are designed to trap both employees and consumers using the following:

* Malicious utility billing portals
* Corporate-branded investment scams
* Misspelled banking sites leveraging Outlook subdomain chaining to deceive victims (Figure 5 shows an example of this type of scheme)

![Scam America Invest homepage with some information redacted. The gradient background features a world map design. On the left, the text promotes partnering with elite brokers and exploring trading possibilities. On the right, a sign-up form requests name, email, and phone number, with a "Register Now" button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-396387-174415-5.png) Figure 5. Fraudulent investment portal.

### Opportunistic Criminal Credit Card Theft

Attackers are luring users to fraudulent payment pages that mimic legitimate package delivery services to steal credit card credentials. These malicious sites are characterized by using newly registered domains and generic hosting domains, frequently incorporating Emirates Post within the subdomain.

A key technical detail is attackers using the cdn-cgi/phish-bypass path on certain domains, such as traz\[.\]top. This path indicates a specific tactic designed to exploit and circumvent security challenges. Figure 6 below shows an example.
![Scam webpage from Emirates Post for confirming shipping and paying delivery costs. It includes sections for entering address details, phone number, and payment information.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-399714-174415-6.png) Figure 6. Scam domain emirates-post\[.\]racunari-bl\[.\]com urging the victim to provide sensitive information.

### Impersonation of Dubai Government Authorities

In another financially motivated campaign, attackers impersonated legitimate government entities for credit card theft. Specifically, we discovered the path payment-system/card-process?amount=125 on a domain designed to mimic a fine payment flow, as shown in Figure 7.
![Scam web page for the Dubai Police Fines Inquiry and Payment system. It includes sections for entering plate details, T.C. number, and other ticket information. There are icons for different steps in the inquiry process, currently on Plate Details. A green-red badge and “Dubai Police” logo are visible at the top. The text offers a 50% discount on active tickets.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-401820-174415-7.png) Figure 7. Scam domain dubai-polices\[.\]ae-finesquery\[.\]com urging the victim to add sensitive information.

### Iranian Bank Masquerading

Attackers are impersonating Iranian banks to manipulate victims into supplying banking credentials. We identified three domains impersonating Iranian banking brands. One domain uses an unconventional gambling top-level domain (TLD), suggesting difficulty in registering a traditional country code TLD (ccTLD). Another domain directly exposes a payment form via the /payment-form/ path.

### Iran Targeting

We identified a campaign misusing the name of Iran's largest mobile operator as the registrable domain, then embedding a convincing Microsoft URL chain in the subdomain labels to impersonate a Microsoft account recovery page.

Two identified domains use a technique that embeds globally recognized and trusted brands as subdomains within a Middle East-branded malicious registrable domain. This exploits a user's left-to-right reading pattern, presenting the legitimate brand name first. This method is effective as it doesn't require typosquatting, because the real brand name is used exactly.

### **StealC Infostealer Infrastructure**

Our analysis of [reported StealC infrastructure](https://www.zscaler.com/blogs/security-research/middle-east-conflict-fuels-opportunistic-cyber-attacks) revealed additional infrastructure and suggests that the attackers are using a numbered-increment pattern across identical top-level domains. This is likely an evasion tactic, where attackers register a new, incremented domain whenever the previous one is blocked.

The attack flow involves a malicious JavaScript that [redirects victims to a file-hosting page](https://www.zscaler.com/blogs/security-research/i-stealc-you-tracking-rapid-changes-stealc), which then delivers the StealC payload within a password-protected ZIP archive. Additional examples of these file-hosting pages are shown below in Figures 8 and 9.

![Malicious website shows a dark-themed FileFire file hosting interface. It indicates a compressed archive (ZIP) file being downloaded. The upload date is 2005-03-05 22:49. Features noted include malware scanning, secure transfer, and fast download.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-403843-174415-8.png) Figure 8. File-hosting page alpha\[.\]filehost36\[.\]sbs delivering StealC payload. ![A scam webpage displaying a blog post titled "TreeGraph: Visualizing Hierarchical Data with Ease." It includes an overview and subtitle "From Data to Diagram: Building Interactive TreeGraphs."](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-405780-174415-9.png) Figure 9. Scam domain hyperfilevault1\[.\]xyz. Unit 42 encourages organizations to remain vigilant for emerging threats related to this conflict. With the confirmed use of wipers, we strongly encourage organizations to test and validate their data backup and recovery procedures, as well as to harden their identity and privilege account management systems.

## Earlier Threat Activity From February 2026

Unit 42 has identified an active phishing [campaign](https://x.com/akaclandestine/status/2028168984789496216?s=20) using a malicious replica of the Israeli Home Front Command RedAlert application. This campaign weaponizes a [legitimate-looking Android package (APK)](https://www.virustotal.com/gui/file/83651b0589665b112687f0858bfe2832ca317ba75e700c91ac34025ee6578b72) to deliver mobile surveillance and data-exfiltrating malware (Figure 10).
![Screenshot of text message titled Oref Alert. The message is in Hebrew and includes a bitly link.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-408542-174415-10.png) Figure 10. SMS phishing message to download malicious RedAlert application.

We have also observed a surge in hacktivist activity, with some estimates of 60 individual groups active, including pro-Russian groups as of March 2, 2026. Multiple Iranian state-aligned personas and collectives have claimed responsibility for a range of disruptive operations, several of which are associated with the recently established "Electronic Operations Room" formed on Feb. 28, 2026. Key observed entities include:

* **Handala Hack,** a hacktivist persona \[linked\](https://blog.checkpoint.com/research/what-defenders-need-to-know-about-irans-cyber-capabilities/#:~:text=Handala%20(often%20branded%20%E2%80%9CHandala%20Hack,%2C%20a%20MOIS%2Daffiliated%20actor.) to Iran's Ministry of Intelligence and Security (MOIS), is the most prominent Iranian persona. The persona blends data exfiltration with cyber operations against the Israeli political and defense establishment.
  * [Claimed](https://x.com/News_Ariaz/status/2028455159941181688) responsibility for compromising an Israeli energy exploration company
  * [Claimed](https://x.com/DarkWebInformer/status/2027886887029952944?s=20) responsibility for compromising Jordan's fuel [systems](https://x.com/cyberfeeddigest/status/2028014056829771820?s=20)
  * [Claimed](https://www.timesofisrael.com/iran-linked-hacker-group-claims-to-breach-data-of-israels-largest-healthcare-network/) to target Israeli civilian healthcare to create domestic pressure just days before the kinetic war broke out
* **APT Iran,** a pro-Iranian hacktivist collective that has gained notoriety for its hack-and-leak operations
  * [Claimed](https://x.com/MonThreat/status/2028444181740376297) responsibility for [sabotage](https://x.com/xabdul/status/2028313862336872507) of Jordan's critical infrastructure
* The **Cyber Islamic Resistance** , a pro-Iranian umbrella collective that coordinates multiple hacktivist teams --- including groups like RipperSec and Cyb3rDrag0nzz --- to launch synchronized DDoS attacks, data-wiping operations and website defacements against Israeli and Western infrastructure
  * [Claimed](https://x.com/VECERTRadar/status/2028099554936058230?s=20) responsibility for compromising a drone defense and detection system
  * [Claimed](https://x.com/FalconFeedsio/status/2028102591847313869?s=20) responsibility for compromising Israeli payment infrastructure
* **Dark Storm Team** (also known as DarkStorm or MRHELL112) is a pro-Palestinian and pro-Iranian collective that specializes in large-scale DDoS and ransomware
  * [Claimed](https://x.com/cyberfeeddigest/status/2028196184997646749?s=20) to have targeted several Israeli websites, including an Israeli bank in DDoS attacks
* The **FAD Team** (often referred to in reports as the Fatimiyoun Cyber Team or Fatimion) is composed of pro-regime actors who focus on wiper malware and permanent data destruction
  * Claimed responsibility via their public Telegram board for gaining unauthorized access to multiple SCADA/PLC systems in Israel and other countries
  * Claimed responsibility via their public Telegram board for gaining unauthorized access to control systems associated with more than 24 private devices belonging to an Israeli security services company
  * Conducted an [attack](https://x.com/VECERTRadar/status/2028221867740344747?s=20) against a Turkish media outlet
* **Evil Markhors** is a pro-Iranian group typically specializing in credential harvesting and identifying unpatched critical systems
  * Claimed responsibility via their public Telegram board for targeting an Israeli bank website
* **Sylhet Gang** (often cited as Sylhet Gang-SG) acts as a message amplifier and recruitment engine for the pro-Iranian hacktivist front and participates in DDoS attacks
  * Claimed responsibility via their public Telegram board for targeting the Saudi Ministry of Home Affair's HCM and Internal Management Systems
* **313 Team** (Islamic Cyber Resistance in Iraq), is an active pro-Iranian hacktivist cell
  * [Claimed](https://x.com/DarkWebInformer/status/2028197445113454811?s=20) responsibility for targeting the Kuwait Armed Forces website
  * [Claimed](https://x.com/xabdul/status/2028319559443239306) responsibility for targeting Kuwait Ministry of Defense website
  * [Claimed](https://x.com/FalconFeedsio/status/2028109219812319248?s=20) responsibility for targeting the Kuwait Government website
* **DieNet** is a pro-Iran hacktivist group conducting DDoS attacks on various organizations across the Middle East
  * [Claimed](https://x.com/FalconFeedsio/status/2027815940705161571?s=20) responsibility for attacking an airport in Bahrain
  * [Claimed](https://x.com/xabdul/status/2028321691760263251) responsibility for attacking Sharjeh Airport in Saudi Arabia
  * [Claimed](https://x.com/xabdul/status/2028219084467486813) responsibility for targeting Riyadh Bank website
  * Claimed responsibility via their public Telegram board for targeting the Bank of Jordan
  * Claimed responsibility via their public Telegram board for targeting an airport in the United Arab Emirates

The group Handala Hack also [reportedly](https://x.com/MichaelKorine/status/2028312736229421191?s=20) [targeted](https://www.yahoo.com/news/articles/hanadala-group-places-bounty-beheading-114001223.html?guccounter=1&guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&guce_referrer_sig=AQAAAF5fj6yfKrUoFr2lGB9EhV5LjkoqqEB202DIgrShv33N5K-l2IiC-mrIGb0jLVswPeu6yNuIIkIR8TNZRAo515u_boliUZMhd6fQEPsIipQpqGdv3XHL8qBRIGGzn2v8zUxVbofX-Uw1uov7M966qtVVpmGNdPn5DWD-Y3nfgK7Q) an Iranian-American and Iranian-Canadian influencer with direct death threats via email (shown in Figure 11), claiming to have leaked their home addresses to physical operatives in their respective home locations.

This type of action represents an escalation of threatening cyber activity directed toward perceived critics of Iran.
![Email from a person reportedly named "Hussain Ali" dated March 1, 2026. The subject line references "Death to..." with a censored line. The email claims affiliation with a group called the "Handala Hack team" and mentions "Ali Hosseini Khamenei," declaring war on unspecified entities. The message mentions "the West," the "CJNG cartel," and references operations in America and Canada, along with the Piers Morgan show. There are threats and mentions of California and Ontario. The email ends with the phrase "ALLAHU AKBAR."](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/word-image-410882-174415-11.png) Figure 11. Handala Hack death threat email to U.S. and Canada influencers.

### Other Threat Group Activity

Cybercriminals are [reportedly](https://x.com/H4ckmanac/status/2028024174393102766?s=20) capitalizing on the conflict by targeting individuals in the United Arab Emirates via a social engineering vishing scam to steal credentials. The threat actors call potential victims impersonating the Ministry of Interior, claiming to be confirming receipt of a national alert and prompting for the victim's Emirates Identification Number (EID) for verification.

The ransomware-as-a-service (RaaS) group Tarnished Scorpius (aka INC Ransomware) has [listed](https://x.com/ido_cohen2/status/2028225466344059029?s=20) on its leak site an Israeli industrial machinery company, and replaced the company logo with a swastika.

### Pro-Russian Hacktivist Activity

Cardinal, a pro-Russian hacktivist [group](https://www.truesec.com/hub/blog/newly-established-russian-hacker-alliance-threatens-denmark#:~:text=The%20first%20threat%20was%20published,4%20PM%20Danish%20time)%20today.), claimed to target Israel Defense Forces (IDF) systems via their public Telegram board. The group is assessed to be state-aligned but likely operates independently of direct state funding. The group claims to have infiltrated IDF networks referencing a purportedly confidential document related to "Magen Tsafoni" (Northern Shield). The posted document includes operational movement details, command approvals and contact information.

The pro-Russian hacktivist group [NoName057(16)](<https://en.wikipedia.org/wiki/Noname057(16)>) has [claimed](https://x.com/FalconFeedsio/status/2028437006347620553?s=20) multiple Israeli targets including disruptive operations against a range of Israeli municipal, political, telecom and defense-related entities.

The pro-Russian hacktivist collective "Russian Legion," [claimed](https://x.com/FalconFeedsio/status/2028558587317170687) to have access to Israel's Iron Dome missile defense system. In their post, they claimed to be controlling radars, intercepting targets and monitoring in real-time, with reported system paralysis and loss of interception control. The group also claimed a new cyber operation it says compromised closed IDF servers.

### State-Sponsored Attacks

Unit 42 tracks various Iranian state-sponsored actors under the constellation name *Serpens*. These groups could increase or escalate activity in the coming weeks.

State-sponsored Iranian cyber capabilities are often used to project and amplify political messaging (often using destructive and psychological tactics). These efforts are likely to focus on regional targets (e.g., Israel) as well as what they deem high-value targets (e.g., politicians, key decision-makers and other directly involved entities).

State-sponsored campaigns might target their victim's supply-chains, critical infrastructure, vendors or providers.

## Conclusion

Given the rapidly changing nature of this situation, a multi-layered defense is most effective as no single tool can provide complete protection. We recommend focusing on foundational security hygiene, a proven approach that provides resilient protection against a wide range of tactics.

We recommend taking the following precautions to help mitigate the impact from possible attacks. These recommendations are consistent with previous guidance provided.

### Tactical Recommendations

* Ensure at least one copy of critical data is stored offline (air-gapped) to mitigate against encryption or deleting backups stored on the network
* Implement strict "out-of-band" verification for incoming requests via media, verifying through a separate trusted corporate channel
* Increase response to any threat signals where possible, especially those associated with internet-facing assets such as websites, virtual private network (VPN) gateways and cloud assets
* Ensure internet-facing infrastructure is up to date with security patches and other hardening best practices
* Train employees on phishing and social engineering tactics and continuously monitor for suspicious activity
* Consider implementing geographic IP address blocking from specific high-risk regions where legitimate business is not conducted
* Have a robust communications plan ready to address unauthorized access versus system compromise, as hacktivist groups often exaggerate their reach. Scoping and quickly verifying the potential compromise can prevent public panic.
* Continue to check for updates from trusted cyber agencies such as the [UK National Cyber Security Center](https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-east) and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) [Iran Threat Overview and Advisories](https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/iran) page

### Strategic Recommendations

* Begin or update business continuity plans for any staff or assets that digital or physical attacks could disrupt
* Prepare to validate and respond to claims of breaches or data leaks
  * Threat actors might use claims (even if they're untrue) to embarrass or harass victims, or to disseminate political narratives

As activity is likely to continue to intensify throughout the duration of these events, it's important to remain vigilant to potential attacks. Hacktivists and state-supported threat actors have been opportunistic, leading to potentially unexpected sources being targeted.

We will update this threat brief as more relevant information becomes available.

## How Palo Alto Networks and Unit 42 Can Help

Palo Alto Networks customers can leverage a variety of product protections and updates to identify and defend against threats related to aspects of these events.

If you think you might have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 000 800 050 45107
* South Korea: +82.080.467.8774

### Next-Generation Firewalls and Prisma Access With Advanced Threat Prevention

[Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration) has an inbuilt machine learning-based detection that can detect exploits in real time.

### Cloud-Delivered Security Services for the Next-Generation Firewall

[Advanced URL Filtering](https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/url-filtering-features/advanced-url-filtering) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) identify known URLs and domains associated with this activity as malicious.

### Cortex

[Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR), [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) and [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud) are designed to prevent the execution of known malicious malware. It is also designed to prevent the execution of unknown malware and other malicious activities using Behavioral Threat Protection and machine learning based on the Local Analysis module.

### Cortex Xpanse

[Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse/attack-surface-management) has the ability to identify exposed Rockwell Automation or Allen-Bradley devices on the public internet and escalate these findings to defenders. Customers can enable alerting on this risk by ensuring that the relevant Attack Surface Rule is enabled. Identified findings can either be viewed in the Threat Response Center or in the incident view of Expander. These findings are also available for Cortex XSIAM customers who have purchased the ASM module.

### Device Security

[Device Security](https://www.paloaltonetworks.com/network-security/device-security) can detect and alert when anomalous program download activities or mode changes are observed from a work station to a programmable logic controller (PLC) using the CIP-IP protocol. It can help identify and alert on internet-exposed Rockwell/Allen-Bradley PLCs. Device Security can also help identify instances of FactoryTalk software installed on workstations.

Device Security continuously monitors industrial networks to provide visibility to all asset behaviors. The solution can help identify assets using any [FactoryTalk App-ID](https://applipedia.paloaltonetworks.com/?search=FactoryTalk).

Additionally, alerts and risks can be used to trigger orchestration via SOAR/SIEM solutions to quarantine or isolation actions via [NGFW](https://www.paloaltonetworks.com/cyberpedia/what-is-a-next-generation-firewall-ngfw) and integrated network access controls (NACs).

## Additional Resources

* [Iranian Cyber Threat Evolution: From MBR Wipers to Identity Weaponization](https://unit42.paloaltonetworks.com/evolution-of-iran-cyber-threats/) -- Unit 42, Palo Alto Networks
* [Insights: Increased Risk of Wiper Attacks](https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/) -- Unit 42, Palo Alto Networks
* [Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/) -- Unit 42, Palo Alto Networks
* [Intelligence-Driven Active Defense Report 2026 Securing Operational Technology Environments](https://www.paloaltonetworks.com/resources/whitepapers/securing-ot-environments) -- Whitepaper, Palo Alto Networks

## Indicators of Compromise

* hxxps\[:\]www\[.\]shirideitch\[.\]com/wp-content/uploads/2022/06/RedAlert\[.\]apk
* hxxps\[:\]//api\[.\]ra-backup\[.\]com/analytics/submit.php
* hxxps\[:\]//bit\[.\]ly/4tWJhQh
* media.megafilehost2\[.\]sbs
* cache3.filehost36\[.\]sbs
* alpha.filehost36\[.\]sbs
* srv2.filehost37\[.\]sbs
* arch2.megadatahost3\[.\]homes
* media.hyperfilevault2\[.\]mom
* hyperfilevault2\[.\]mom
* www.hyperfilevault2\[.\]mom
* arch2.maxdatahost1\[.\]cyou
* hyperfilevault1\[.\]xyz
* hyperfilevault3\[.\]mom
* hyperfilevault3\[.\]pics
* pnd.86c.mytemp\[.\]website
* d1g.ccd.mytemp\[.\]website
* s0u.210.mytemp\[.\]website
* 2pd.f22.mytemp\[.\]website
* eg3.db1.mytemp\[.\]website
* f43.c76.mytemp\[.\]website
* kzw.ce3.mytemp\[.\]website
* c45.94b.mytemp\[.\]website
* kmd.8cd.mytemp\[.\]website
* c1y.bf3.mytemp\[.\]website
* m1w.4a0.mytemp\[.\]website
* njb.551.mytemp\[.\]website
* 2b1.916.mytemp\[.\]website
* 92j.130.mytemp\[.\]website
* b1z.0f6.mytemp\[.\]website
* b0p.c0d.mytemp\[.\]website
* nxj.e57.mytemp\[.\]website
* pro.iranpanel\[.\]life
* www.iran2026\[.\]org
* iranpaye\[.\]com
* www.forever-iran\[.\]net
* irandonation\[.\]org
* irancross\[.\]shop
* aramcoamericainvest\[.\]com
* trumpvsirancoin\[.\]xyz
* iran\[.\]drproxy\[.\]pro
* iran2\[.\]drproxy\[.\]pro
* iran11\[.\]drproxy\[.\]pro
* iran14\[.\]drproxy\[.\]pro
* iran15\[.\]drproxy\[.\]pro
* iran16\[.\]drproxy\[.\]pro
* iran18\[.\]drproxy\[.\]pro
* iran19\[.\]drproxy\[.\]pro
* tehran\[.\]t2.drproxy\[.\]pro
* emiratesinvestunion\[.\]com
* buydubaipropertywithcrypto\[.\]com
* cryptocurrencies-offers\[.\]com
* the-dubai-lifestyleapp.cryptocurrencies-offers\[.\]com
* emiratescryptobank\[.\]com
* secretemirates\[.\]com
* emiratespost-pay\[.\]com
* ae-payapp\[.\]com
* www.emirates-post\[.\]ae-payapp\[.\]com
* traz\[.\]top
* emiratespost\[.\]traz\[.\]top/cdn-cgi/phish-bypass?atok=
* emirates-post\[.\]racunari-bl\[.\]com/en/card.php
* myemiratespost\[.\]click
* emirates-ae\[.\]pack-541202699\[.\]azmtrust\[.\]com
* portal\[.\]sapb-aramco\[.\]com
* cnmaestro\[.\]sapb-aramco\[.\]com
* saudi-bill-pay\[.\]com
* saudidigtalbank\[.\]com
* outlook\[.\]outlook\[.\]saudidigtalbank\[.\]com
* aramcoamericainvest\[.\]com
* dubaicustonms\[.\]top
* dubai-custboms\[.\]top
* dubai-custbims\[.\]top
* dubai-customs\[.\]top
* dubaicustoms\[.\]top
* dubaicuctoms\[.\]com
* dubaiicuctoms\[.\]com
* gov-tollbillba\[.\]life
* com-govauv\[.\]top
* dubaipolice\[.\]gov-tollbillba\[.\]life
* govauv\[.\]top
* portal\[.\]0111etisalat\[.\]com
* www\[.\]portal\[.\]0111etisalat\[.\]com
* superset\[.\]0111etisalat\[.\]com
* www\[.\]superset\[.\]0111etisalat\[.\]com
* yoshi\[.\]0111etisalat\[.\]com
* \_dmarc\[.\]www\[.\]portal\[.\]0111etisalat\[.\]com
* etisalatquickpay\[.\]com
* etisalataccountquickpayae\[.\]top
* etisalataccount-quickpayae\[.\]click
* cover\[.\]www\[.\]microsoft\[.\]com\[.\]irancell\[.\]courses
* recovery\[.\]cover\[.\]www\[.\]microsoft.com\[.\]irancell\[.\]courses
* bankofamerica\[.\]com\[.\]oidscreen\[.\]gorequestlocale\[.\]emiratesbankgroup\[.\]info
* appleid\[.\]apple\[.\]com-update\[.\]required\[.\]kontol\[.\]emiratesbankgroup\[.\]info
* store\[.\]appleid-apple\[.\]com-confirmation\[.\]verif\[.\]emiratesbankgroup\[.\]info
* bankiran\[.\]bet
* irandargah\[.\]com
* iransupports\[.\]cyou
* iransupporttyst\[.\]cyou
* iransupasdports\[.\]cyou
* iransusdpportsdf\[.\]cyou
* firansupport\[.\]cyou
* kiransupport\[.\]cyou
* trdfiransupport\[.\]cyou
* airansupasdports\[.\]cyou
* biransupasdports\[.\]cyou
* kiransupportsdf\[.\]cyou
* fkiransusdpportsdf\[.\]cyou
* sffifdsfsransupasdports\[.\]cyou
* portal.0111etisalat\[.\]com
* superset\[.\]0111etisalat\[.\]com
* yoshi\[.\]0111etisalat\[.\]com
* \_dmarc\[.\]www\[.\]portal\[.\]0111etisalat\[.\]com
* etisalatquickpay\[.\]com
* etisalataccountquickpayae\[.\]top
* etisalataccount-quickpayae\[.\]click

## Appendix: Timeline of Destructive Attacks From Iranian Threat Actors

Unit 42 is tracking an increased risk of [wiper attacks](https://unit42.paloaltonetworks.com/handala-hack-wiper-attacks/) related to the conflict with Iran. Iranian actors have a history dating back to 2012 of conducting [destructive attacks](https://unit42.paloaltonetworks.com/evolution-of-iran-cyber-threats/) against high priority targets, highlighting a pattern of capability and intent. They also have a history of disruptive attacks dating back as far as 2011. Table 1 shows the three phases of Iran's use of destructive cyber operations.

|---------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Three Phases of Iran's Use of Destructive Cyber Operations**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
| **2012--2019**                                                                        | **2020--2022**                                                                                                                                                                                   | **2022--Present**                                                                                                                                                                                                                                                                                                                          |
| The first era was defined by retaliatory operations against the global energy sector. | Following the establishment of the Abraham Accords to normalize relations between Israel and several Arab nations, Iran shifted its focus toward the private sectors of its new regional rivals. | Beginning in 2022, Iran began using destructive cyber operations against certain countries. Some of the first attacks were against Albania, and destructive cyber operations have further evolved since Oct. 7, 2023. Cyberattacks have included targets in the Middle East, U.S. defense contractors and members of the Iranian diaspora. |
| Notable Victims                                                                       | Notable Victims                                                                                                                                                                                  | Notable Victims                                                                                                                                                                                                                                                                                                                            |
| \* Energy sector organizations based in the Middle East                                | \* Israeli IT software and cloud producers \* Israeli government-owned insurance and healthcare                                                                                                    | \* Middle East-based \* Research centers \* Banks and payment processors \* Medical organizations \* Energy sector organizations                                                                                                                                                                                                                |

Table 1. The three phases of Iran's use of destructive cyber operations.

*Updated March 23, 2026, at 3:30 p.m. PT to add Additional Resources section.*

*Updated March 26, 2026, at 2:00 p.m. PT to add information on conflict-themed phishing lures.*

*Updated March 30, 2026, at 3:15 p.m. PT to edit list of indicators.*

*Updated April 17, 2026 at 3:35 p.m. PT to add additional observations related to Cyber Av3ngers. Added an Appendix section. Added product protection information for Device Security and Cortex Xpanse.*
Back to top

### Tags

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")
* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")
* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")
* [Hacktivism](https://unit42.paloaltonetworks.com/tag/hacktivism/ "hacktivism")
* [Iran](https://unit42.paloaltonetworks.com/tag/iran/ "Iran")
* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [Tarnished Scorpius](https://unit42.paloaltonetworks.com/tag/tarnished-scorpius/ "Tarnished Scorpius")
* [Wiper](https://unit42.paloaltonetworks.com/tag/wiper/ "wiper")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")

### Table of Contents

* 

### Related Articles

* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")
* [When "Hi, This Is IT" Comes Through Microsoft Teams](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/ "article - table of contents")

## Related Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
