[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/lokibot-spike-analysis/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/lokibot-spike-analysis/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/ "Business Email Compromise")  
  [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/)

# Spike in LokiBot Activity During Final Week of 2022

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Chris Navarrete](https://unit42.paloaltonetworks.com/author/chris-navarrete/)
  * [Edouard Bochin](https://unit42.paloaltonetworks.com/author/edouard-bochin/)
  * [Durgesh Sangvikar](https://unit42.paloaltonetworks.com/author/durgesh-sangvikar/)
  * [Lei Xu](https://unit42.paloaltonetworks.com/author/lei-xu/)
  * [Yu Fu](https://unit42.paloaltonetworks.com/author/yu-fu/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:March 3, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Business Email Compromise](https://unit42.paloaltonetworks.com/tag/business-email-compromise/)
  * [Information stealer](https://unit42.paloaltonetworks.com/tag/information-stealer/)
  * [LokiBot](https://unit42.paloaltonetworks.com/tag/lokibot/)
  * [Machine Learning](https://unit42.paloaltonetworks.com/tag/machine-learning/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/lokibot-spike-analysis/?pdf=download&lg=en&_wpnonce=48697d1bdd "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/lokibot-spike-analysis/?pdf=print&lg=en&_wpnonce=48697d1bdd "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Spike%20in%20LokiBot%20Activity%20During%20Final%20Week%20of%202022&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Flokibot-spike-analysis%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Flokibot-spike-analysis%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flokibot-spike-analysis%2F&title=Spike%20in%20LokiBot%20Activity%20During%20Final%20Week%20of%202022 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flokibot-spike-analysis%2F&text=Spike%20in%20LokiBot%20Activity%20During%20Final%20Week%20of%202022 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flokibot-spike-analysis%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Spike%20in%20LokiBot%20Activity%20During%20Final%20Week%20of%202022%20https%3A%2F%2Funit42.paloaltonetworks.com%2Flokibot-spike-analysis%2F "Share in Mastodon")

## Executive Summary

Unit 42 researchers have uncovered a malware distribution campaign that is delivering the LokiBot information stealer via business email compromise (BEC) phishing emails. This malware is designed to steal sensitive information from victims' systems, such as passwords and banking information, as well as other sensitive data.

In this blog, we will explain how attackers used an innocent-looking email to lure victims into opening an attachment. The attachment contained a LokiBot information stealer.

We will provide technical details on how the LokiBot sample uses obfuscation and a persistence mechanism to avoid detection. We will also describe the command and control (C2) channel communication. Finally, we will list the various applications from which the malware steals data.

The [Appendix](#post-127127-_ivlsyj521a6a) of this blog will provide an in-depth description of each data byte in the HTTP based C2 communication, detailing the specific purpose of each byte. It will also provide a breakdown of how the data byte is structured.

Palo Alto Networks customers receive protections from and mitigations for LokiBot information stealer C2 communication in the following ways:

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with a [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) subscription can identify and block LokiBot malware with TID 85304 and 21630.
* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with an [Advanced Threat Prevention](https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/about-threat-prevention/advanced-threat-prevention) subscription can identify and block the variations of LokiBot communication using a machine learning solution.
* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire)and [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) can identify and block the attachment file described in the blog.

| **Related Unit 42 Topics** | [**LokiBot**](https://unit42.paloaltonetworks.com/tag/lokibot/) |
|----------------------------|-----------------------------------------------------------------|

## Introduction

LokiBot (often referred to as Loki-bot or Loki PWS) is notorious information-stealing malware. It collects sensitive data from web browsers, email clients, FTP servers and crypto wallets. This threat then uploads this information to an attacker-controlled machine via HTTP POST.

The malware can also create a backdoor on the infected machine, enabling an attacker to install further malicious software. First identified in 2015, LokiBot has since been used in multiple security breaches. Furthermore, the malware is constantly evolving, making it difficult to contain and protect against.

During the winter holiday season of 2022, Unit 42 researchers noticed that our machine learning-based C2 detection solution identified a particular HTTP payload as malicious. After analyzing its traffic patterns, we identified that it belonged to a LokiBot infection.

After investigating the attack vector delivering this malware and further network traffic activity, we found the original email that included a ZIP file attached, which contained an ISO file. The ISO file had the final payload.

We have found that this attempt to deliver the LokiBot malware has strong ties to a BEC campaign. BEC entails gaining unauthorized access to email leading to financial fraud, and it is one of the most prevalent and costly forms of cyberattacks today.

Signs of BEC include fraudulent wire transfer requests, as well as spam or phishing emails sent from a customer's corporate domain. Victims might also notice missing or deleted emails due to unauthorized access to email systems.
![Image 1 is a screenshot of a malspam email that delivers a LokiBot sample. Identifying information is redacted, and the language in the email is Turkish.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/03/word-image-127127-1-1.png) Figure 1. Malspam delivers a LokiBot sample.

When collecting data, we also analyzed additional threat intel data sources such as [ThreatFox](https://threatfox.abuse.ch/browse/tag/LokiBot/). We noticed that LokiBot activity had a relatively small amount of indicators of compromise (IoCs) when we first detected this sample. However, during the end of 2022, the number of occurrences peaked in the last three days of December.

Threat actors [often increase their attack efforts](https://www.cisa.gov/uscert/ncas/alerts/aa21-243a) during U.S. or other targeted nations' holidays. During this time, cyberattacks are often more effective as security and other personnel take this time off.

Figure 2 shows LokiBot activity from ThreatFox.
![Image 2 is a graph using data from ThreatFox measuring the spike in December 2022 of LokiBot activity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/03/word-image-127127-2-1.png) Figure 2. ThreatFox LokiBot monitoring. Data source: [ThreatFox](https://threatfox.abuse.ch/browse/tag/LokiBot/).

## LokiBot Malware Analysis

### First Stage

The ISO file format is typically used to package the contents of an optical disc. In this instance, it is used to deliver the LokiBot malware. By using this file format, the attackers are trying to bypass malspam detection technologies that usually focus on detecting file types more commonly used in malware infection chains (e.g., EXE and DLL files, MS Office files).

ISO files are also attractive to attackers because, while specific software was required to open them in the past, Windows includes an ISO file opener that mounts and opens the file with a simple double-click. To the victim, the opening process simply looks like a regular directory.

### Loader

Opening the ISO file gives us access to a PE EXE file that is actually a loader. This file is an obfuscated .NET file using [process hollowing](https://unit42.paloaltonetworks.com/banking-trojan-techniques/), which is a code injection technique in which an attacker removes legitimate code from an executable and replaces it with malicious code.

In this case, process hollowing was used to inject a malicious PE file into the legitimate process called aspnet\_compiler.exe. Figure 3 shows some IoCs in the memory of the infected process. Dumping the PE from the process memory gives us access to the final LokiBot payload.
![Image 3 is a screenshot of aspnet\_compiler.exe showing the IoCs in the memory of the infected process in the “Results” window.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/03/word-image-127127-3-1.png) Figure 3. The infected process that contains IoCs.

### Final Payload

#### Obfuscation

This LokiBot sample only uses one code obfuscation technique: API hashing. Malware authors use this technique to retrieve export functions from loaded libraries using a computed hash.

Replicating the hashing function implementation allows us to retrieve the corresponding APIs in the appropriate library. Figure 4 shows a Python implementation of the API hashing algorithm used in the malware sample.
![Image 4 is many lines of code showing the Python API hashing algorithm that the malware sample uses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/03/word-image-127127-4-1.png) Figure 4. API hashing algorithm.

#### Main Stealing Feature

The main function of the sample is building two arrays of 101 elements. The first array is filled with indexes, and the second array is filled with pointers to functions. The latter are the stealing functions.

These functions are made to steal credentials from different types of applications and services on the Windows operating system:

* Browsers: Safari, Internet Explorer, Firefox and Chromium-based browsers
* FTP/SSH apps and clients
* Backup applications
* Email applications
* Notes applications
* Poker applications
* Password managers
* Windows credentials

The main function of the malware is looping over these stealer functions to execute them, as shown in Figure 5.
![Image 5 is a screenshot of many lines of code showing the malware looping over stealer functions in order to execute them.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/03/word-image-127127-5-1.png) Figure 5. Main stealer function loop.

All the credentials collected and extracted from the installed software will then be compressed by the[aPLib algorithm](https://ibsensoftware.com/products_aPLib.html) and submitted to the C2 server through HTTP protocol using the POST method. We'll go into this in more detail in the [HTTP C2 Communication](#post-127127-_vszfb2ul5lc3) section.

#### Persistence

In order to establish persistence on the targeted host, the malware starts by saving a copy of itself in a new folder in the %APPDATA% directory via the MoveFileExW or CopyFileW Windows API. Then, it creates and sets a new value for the registry key HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run. This value, named as the created folder, is set to the path of the copied executable.

### HTTP C2 Communication

LokiBot exfiltrates information to the C2 through the HTTP protocol. This information includes the bot's version number (1.8) and can be found in the two bytes of the HTTP payload. It also contains a User-Agent set as "Mozilla/4.08 (Charon; Inferno)", and the Content-Key, which is a custom HTTP header whose value corresponds to a hash generated out of the HTTP header.

Figure 6 shows a HTTP POST request and its corresponding message body. This body contains the exfiltrated information, which is highlighted in different colors for each field. We've also included the corresponding offset and size to provide a better visual reference of the data structure used by the malware, and to easily cross-reference each field of interest.
![Image 6 is a screenshot of Wireshark showing the exfiltrated information (in many colors) in the message body.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/03/word-image-127127-6-1.png) Figure 6. HTTP POST request (type 27 / data exfiltration).

For a detailed list of each data field (offset and size) of the HTTP body (payload) please refer to the [Appendix](#post-127127-_ivlsyj521a6a) section.

Similar to other information-stealing malware, this threat searches for and exfiltrates the following information:

* OS architecture
* Built-in admin
* Domain host name
* Hostname
* Local admin
* Operating system
* Screen resolution
* Username information

The exfiltrated data that is unique to this information stealer malware includes the following:

* Unique key, which is an identifier that includes five randomly generated characters
* Binary ID, which indicates a domain that is commonly used in LokiBot infections (ckav\[.\]ru)
* Mutex value, which consists of a 24-character length string (taken from hashing the machine's GUID using the MD5 algorithm)
* Potential hidden files (e.g., %APPDATA%\\\\079D53\\\\3AFB91.hdb), which are taken from the mutex value (for directory name with a character range from 8-13 bytes and a file name with a character range from 13-18 bytes)
  * Hash database (.hdb)
  * Keylogger database (.kdb)
  * Lock file (.lck)
  * Malware EXE (.exe)

The bot also makes use of different payload types (located at the third and fourth byte of the HTTP body). These types include the following:

* Stolen application/credential data (0x27)
* Get C2 commands from C2 Server (0x28)
* Exfiltrate keylogger data (0x2B)

Other versions of this malware family can use additional payload types depending on the final action including the following:

* Exfiltrate cryptocurrency wallet (0x26)
* Exfiltrate files (0x29)
* Exfiltrate PoS data (0x2a)
* Exfiltrate screenshots (0x2c)

## Conclusion

LokiBot malware has been used by attackers for many years. There have been multiple versions of this threat. It takes a lot of effort for any security team to constantly monitor the behavior changes in the malware and add the necessary protections.

The Palo Alto Networks machine learning-based C2 detection solution, as part of Advanced Threat Prevention, detects and stops malicious C2 activity inline. The model is regularly updated with the latest C2 communication from various types of malware. This ensures that the detection capabilities are always up to date and capable of countering the ever-evolving threats posed by malicious actors.

We would like to extend our gratitude to Doel Santos from Unit 42 and Nina Smith for helping on this investigation.

Palo Alto Networks customers receive protections from and mitigations for LokiBot information stealer C2 communication in the following ways:

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with a [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) subscription can identify and block LokiBot malware with TID 85304 and 21630.
* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with an [Advanced Threat Prevention](https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/threat-prevention/about-threat-prevention/advanced-threat-prevention) subscription can identify and block the variations of LokiBot communication using our machine learning solution.
* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire)and [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) can identify and block the attachment file described in the blog.

We have distilled the knowledge we've gained from responding to hundreds of BEC incidents into our [BEC Readiness Assessment](https://www.paloaltonetworks.com/bec-readiness-assessment) offering, which is designed to help organizations strengthen their processes and technology to mitigate threats like the ones discussed in this blog.

If you think you may have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

### Samples

* ZIP file: 4edd01345f58b9cc04a88ca15d6b82895f44f5b9cb51ad63b809de09029670ac

* ISO: 8a5a024272361bb1ae12860c033bb52685d7b0ea3bce5fac46439f3f3ad36a84

* Loader: 1b574a66c84924886daec4841e1b107258e019aaf6f336329ae8fae7cbd52a34

### Infrastructure

* efvsx\[.\]gq
* 188\.114.96\[.\]13

## Additional Resources

* [Operation Delilah: Unit 42 Helps INTERPOL Identify Nigerian Business Email Compromise Actor](https://unit42.paloaltonetworks.com/operation-delilah-business-email-compromise-actor/)
* [Operation Falcon II: Unit 42 Helps INTERPOL Identify Nigerian Business Email Compromise Ring Members](https://unit42.paloaltonetworks.com/operation-falcon-ii-silverterrier-nigerian-bec/)
* [SilverTerrier -- Nigerian Business Email Compromise](https://unit42.paloaltonetworks.com/silverterrier-nigerian-business-email-compromise/)

## Appendix

|-------------------------|------------|----------|
| **Field Description**   | **Offset** | **Size** |
| LokiBot version         | 0x0        | 0x2      |
| Payload type            | 0x2        | 0x2      |
| BinaryID unicode        | 0x4        | 0x2      |
| BinaryID length         | 0x6        | 0x4      |
| BinaryID string         | 0xa        | 0x7      |
| Username unicode        | 0x11       | 0x2      |
| Username length         | 0x13       | 0x4      |
| Username string         | 0x17       | 0x12     |
| Hostname unicode        | 0x29       | 0x2      |
| Hostname length         | 0x2b       | 0x4      |
| Hostname string         | 0x2f       | 0x16     |
| Domain hostname unicode | 0x45       | 0x2      |
| Domain hostname length  | 0x47       | 0x4      |
| Domain hostname string  | 0x4b       | 0x16     |
| Screen width            | 0x61       | 0x4      |
| Screen height           | 0x65       | 0x4      |
| Local admin             | 0x69       | 0x2      |
| Built-In admin          | 0x6b       | 0x2      |
| 64-bit OS               | 0x6d       | 0x2      |
| OS major                | 0x6f       | 0x2      |
| OS minor                | 0x71       | 0x2      |

Back to top

### Tags

* [Business Email Compromise](https://unit42.paloaltonetworks.com/tag/business-email-compromise/ "Business Email Compromise")
* [Information stealer](https://unit42.paloaltonetworks.com/tag/information-stealer/ "information stealer")
* [LokiBot](https://unit42.paloaltonetworks.com/tag/lokibot/ "LokiBot")
* [Machine Learning](https://unit42.paloaltonetworks.com/tag/machine-learning/ "Machine Learning")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Subdomain Reputation: Detecting Malicious Subdomains of Public Apex Domains](https://unit42.paloaltonetworks.com/detecting-malicious-subdomains/ "Subdomain Reputation: Detecting Malicious Subdomains of Public Apex Domains")

### Table of Contents

* 

### Related Articles

* [The Evolution of Linux Binaries in Targeted Cloud Operations](https://unit42.paloaltonetworks.com/elf-based-malware-targets-cloud/ "article - table of contents")
* [Detecting Vulnerability Scanning Traffic From Underground Tools Using Machine Learning](https://unit42.paloaltonetworks.com/machine-learning-new-swiss-army-suite-tool/ "article - table of contents")
* [Autoencoder Is All You Need: Profiling and Detecting Malicious DNS Traffic](https://unit42.paloaltonetworks.com/profiling-detecting-malicious-dns-traffic/ "article - table of contents")

## Related Business Email Compromise Resources

![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of a IUAM ClickFix generator. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen, indicating malware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/03_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 8, 2025 [#### The ClickFix Factory: First Exposure of IUAM ClickFix Generator](https://unit42.paloaltonetworks.com/clickfix-generator-first-of-its-kind/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")

* [Phishing Kit](https://unit42.paloaltonetworks.com/tag/phishing-kit/ "Phishing Kit")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/clickfix-generator-first-of-its-kind/ "The ClickFix Factory: First Exposure of IUAM ClickFix Generator")  
  ![Pictorial representation of phishing bait using AI. A luminous cube labeled "AI" centrally placed on a futuristic circuit board landscape with glowing blue lights and connections.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/03_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 19, 2025 [#### Fashionable Phishing Bait: GenAI on the Hook](https://unit42.paloaltonetworks.com/genai-phishing-bait/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/genai-phishing-bait/ "Fashionable Phishing Bait: GenAI on the Hook")  
  ![Pictorial representation of social engineering. Digital illustration of four human profiles connected by glowing neural network lines against a dark background, symbolizing connectivity and technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/cover-1920x900-no-blades-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) July 30, 2025 [#### 2025 Unit 42 Global Incident Response Report: Social Engineering Edition](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/)

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/ "2025 Unit 42 Global Incident Response Report: Social Engineering Edition")  
  ![Pictorial representation of homograph attacks. 3D illustration of an open laptop displaying an envelope icon on the screen, accompanied by a smartphone and tablet, all set against a dark background with neon lighting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/01_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 25, 2025 [#### The Ηоmоgraph Illusion: Not Everything Is As It Seems](https://unit42.paloaltonetworks.com/homograph-attacks/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/homograph-attacks/ "The Ηоmоgraph Illusion: Not Everything Is As It Seems")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![Pictorial representation of a QR code phishing campaign. Digital artwork of a futuristic, glowing shield disintegrating into small particles, set against a dark blue, speckled background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 1, 2025 [#### Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon](https://unit42.paloaltonetworks.com/qr-code-phishing/)

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")

* [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/ "social engineering")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/qr-code-phishing/ "Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon")  
  ![An Asian woman examining data on multiple computer screens in a high-tech digital environment, surrounded by visual representations of data and code. Lens flare is prominent across the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/02/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) February 28, 2025 [#### JavaGhost's Persistent Phishing Attacks From the Cloud](https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/)

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/ "JavaGhost’s Persistent Phishing Attacks From the Cloud")  
  ![Pictorial representation of a European phishing campaign. A digital artwork depicting a glowing, futuristic shield disintegrating into small fragments against a shimmering blue background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 18, 2024 [#### Effective Phishing Campaign Targeting European Companies and Organizations](https://unit42.paloaltonetworks.com/european-phishing-campaign/)

* [EMEA](https://unit42.paloaltonetworks.com/tag/emea/ "EMEA")

* [Manufacturing](https://unit42.paloaltonetworks.com/tag/manufacturing/ "Manufacturing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/european-phishing-campaign/ "Effective Phishing Campaign Targeting European Companies and Organizations")  
  ![A pictorial representation of a campaign like BeaverTail. Digital globe with interconnected network lines and data streams on a futuristic interface, symbolizing global connectivity and information technology advancements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/01_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) November 14, 2024 [#### Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack](https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Lazarus](https://unit42.paloaltonetworks.com/tag/lazarus/ "Lazarus")

* [BeaverTail](https://unit42.paloaltonetworks.com/tag/beavertail/ "BeaverTail")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/ "Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
