[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/mirai-variant-iz1h9/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/ "Trend Reports")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![IoT Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)IoT Security](https://unit42.paloaltonetworks.com/product-category/iot-security/ "IoT Security")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Chao Lei](https://unit42.paloaltonetworks.com/author/chao-lei/)
  * [Zhibin Zhang](https://unit42.paloaltonetworks.com/author/zhibin-zhang/)
  * [Cecilia Hu](https://unit42.paloaltonetworks.com/author/cecilia-hu/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:May 25, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CVE-2023-26801](https://unit42.paloaltonetworks.com/tag/cve-2023-26801/)
  * [CVE-2023-26802](https://unit42.paloaltonetworks.com/tag/cve-2023-26802/)
  * [CVE-2023-27076](https://unit42.paloaltonetworks.com/tag/cve-2023-27076/)
  * [IoT](https://unit42.paloaltonetworks.com/tag/iot/)
  * [IZ1H9](https://unit42.paloaltonetworks.com/tag/iz1h9/)
  * [Mirai variant](https://unit42.paloaltonetworks.com/tag/mirai-variant/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/?pdf=download&lg=en&_wpnonce=64814e76fb "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/?pdf=print&lg=en&_wpnonce=64814e76fb "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Old%20Wine%20in%20the%20New%20Bottle:%20Mirai%20Variant%20Targets%20Multiple%20IoT%20Devices&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-iz1h9%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-iz1h9%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-iz1h9%2F&title=Old%20Wine%20in%20the%20New%20Bottle:%20Mirai%20Variant%20Targets%20Multiple%20IoT%20Devices "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-iz1h9%2F&text=Old%20Wine%20in%20the%20New%20Bottle:%20Mirai%20Variant%20Targets%20Multiple%20IoT%20Devices "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-iz1h9%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Old%20Wine%20in%20the%20New%20Bottle:%20Mirai%20Variant%20Targets%20Multiple%20IoT%20Devices%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-iz1h9%2F "Share in Mastodon")

## Executive Summary

On April 10, Unit 42 researchers observed a Mirai variant called IZ1H9, which used several vulnerabilities to spread itself. The threat actors use the following vulnerabilities to target exposed servers and networking devices running Linux:

* [CVE-2023-27076](https://nvd.nist.gov/vuln/detail/CVE-2023-27076): Tenda G103 command injection vulnerability
* [CVE-2023-26801](https://nvd.nist.gov/vuln/detail/CVE-2023-26801): LB-Link command injection vulnerability
* [CVE-2023-26802](https://nvd.nist.gov/vuln/detail/CVE-2023-26802): DCN DCBI-Netlog-LAB remote code execution vulnerability
* [Zyxel remote code execution vulnerability](https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-code-execution-and-denial-of-service-vulnerabilities-of-cpe)

Compromised devices can be fully controlled by attackers and become a part of the botnet. Those devices can be used to conduct further attacks, such as distributed denial-of-service (DDoS) attacks.

Palo Alto Networks [Next Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) customers receive protections through [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions) such as [IoT Security](https://www.paloaltonetworks.com/network-security/smart-devices-smarter-iot-security?utm_source=google-jg-amer-cdss&utm_medium=paid_search&utm_term=palo%20alto%20networks%20iot%20security&utm_campaign=google-cdss-iot_security-amer-ca-awareness-en&utm_content=gs-19633824690-151442986731-646705931499&sfdcid=7014u000001hHCRAA2&gclid=EAIaIQobChMI1Lm26OmS_QIVQUNyCh1G3gKWEAAYASAAEgJ3KvD_BwE), [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention), [WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire) and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering), which can help detect and block the exploit traffic and malware.

| **Related Unit 42 Topics** | [**Mirai variant**](https://unit42.paloaltonetworks.com/tag/mirai-variant/), **[IoT](https://unit42.paloaltonetworks.com/tag/iot/)** |
|----------------------------|--------------------------------------------------------------------------------------------------------------------------------------|

## Campaign Overview

Since November 2021, Unit 42 researchers have observed multiple campaigns using the Mirai IZ1H9 variant. Based on our analysis, we believe that these campaigns were operated by the same threat actor for the following reasons:

* The malware shell script downloaders used in both campaigns are almost identical.
* The botnet samples use the same XOR decryption key: 0xBAADF00D
* The botnet client samples use almost identical functions.
* Botnet client samples among those campaigns share the same infrastructure.

On April 10, 2023, Unit 42 researchers observed some abnormal traffic from our threat hunting system. This threat group tried to download and execute a shell script downloader lb.sh from IP 163.123.143\[.\]126.

If executed, the shell script downloader would first delete logs to hide its tracks. Then the following bot clients would be downloaded and executed, to accommodate different Linux architectures:

* hxxp://163.123.143\[.\]126/bins/dark.x86
* hxxp://163.123.143\[.\]126/bins/dark.mips
* hxxp://163.123.143\[.\]126/bins/dark.mpsl
* hxxp://163.123.143\[.\]126/bins/dark.arm4
* hxxp://163.123.143\[.\]126/bins/dark.arm5
* hxxp://163.123.143\[.\]126/bins/dark.arm6
* hxxp://163.123.143\[.\]126/bins/dark.arm7
* hxxp://163.123.143\[.\]126/bins/dark.ppc
* hxxp://163.123.143\[.\]126/bins/dark.m68k
* hxxp://163.123.143\[.\]126/bins/dark.sh4
* hxxp://163.123.143\[.\]126/bins/dark.86\_64

In the last step, the shell script downloader would block network connection from several ports including SSH, telnet and HTTP. It did so by modifying the device's iptable rules, so that the victim wouldn't be able to connect and recover the compromised device remotely, as depicted in Figure 1.
![Figure one is a screenshot of the modified iptable rules.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-1.png) Figure 1. Iptable modification.

## Threat Group Analysis

Unit 42 researchers conducted analysis on the downloaded botnet client samples and found two URLs hosting more shell script downloaders:

* hxxp://2.56.59\[.\]215/i.sh
* hxxp://212.192.241\[.\]72/lolol.sh

Figure 2 is a diagram illustrating the campaign overview.
![Figure 2 is a campaign overview diagram. It starts with the first IP address from April 10, 2023, and leads through the hosts, Mirai samples, the hosts, a shell script, and continues through the different downloaders.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-2.png) Figure 2. Campaign overview diagram.

The shell script downloader from 2.56.59\[.\]215 would download botnet clients from hxxp://2.56.59\[.\]215/bins/. Those botnet client samples would contact a command and control (C2) server at 195.133.40\[.\]141 where there were URLs in the malware samples that hosted two shell scripts:

* hxxp://31.210.20\[.\]100/lolol\[.\]sh
* hxxp://212.192.241\[.\]72/lolol\[.\]sh

The shell script downloader from 212.192.241\[.\]72 would download botnet clients from hxxp://212.192.241\[.\]87/bins/, and those botnet client samples would contact the C2 domain dotheneedfull\[.\]club.

## Malware Analysis

Based on behavior and patterns Unit 42 researchers observed during the analysis of the downloaded samples, we believe that they are a variant of the Mirai botnet called IZ1H9.

Discovered in August 2018, IZ1H9 is one of the most active Mirai variants. Just like the original Mirai, the IZ1H9 botnet client first checks the network portion of the infected device's IP address. The client avoids execution for a list of IP blocks, including government networks, internet providers and large tech companies.

The botnet client makes its presence visible by printing the word "Darknet" to the console. The malware also contains a function that ensures the device is running only one instance of this malware. If a botnet process already exists, the botnet client will terminate the current process and start a new one, as depicted in Figure 3.
![Figure 3 is a screenshot demonstrating how the botnet client terminates a current process, and then starts a new one. Included in the code is “instance already exists, overriding current process.”](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-3.png) Figure 3. IZ1H9 ensures there is only a single instance of execution.

The botnet client also contains a list of process names belonging to other Mirai variants and other botnet malware families. The malware checks the running process names on the infected host to terminate them.

The IZ1H9 variant tries to connect to a hard-coded C2 address: 193.47.61\[.\]75, as shown in Figure 4.
![Figure 4 is a screenshot of the malware variant trying to connect to the hardcoded command and control (C2) IP address.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-4.png) Figure 4. IZ1H9 malware C2 address.

### Botnet Client Configuration String Decryption

For botnet client configuration strings, the IZ1H9 variant will first initialize an encrypted string table. It will then retrieve the encrypted strings through an index (as shown in Figures 5 and 6).
![Figure 5 is a screenshot of the encrypted string table. Highlighted in red is table\_init().](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-5.png) Figure 5. Initializing the encrypted string table. ![Figure 6 is a screenshot of the malware variant retrieving strings. Highlighted within a red box is the code val = table retrieve val (84, 0). This is Mirai retrieving strings by index.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-6.png) Figure 6. IZ1H9 retrieving strings.

The IZ1H9 variant uses a table key during the string decryption process: 0xBAADF00D. For each encrypted character, the malware performs XOR decryption with the following bytewise operations:

cipher\_char ^ 0xBA ^ 0xAD ^ 0xF0 ^ 0x0D = plain\_char

According to the logic behind XOR operation, the configuration string key equals to

0xBA ^ 0xAD ^ 0xF0 ^ 0x0D = 0xEA

### IZ1H9 Sample Spreading Through HTTP, SSH and Telnet Protocol

For SSH and telnet channels, IZ1H9 inherits the most significant feature from the original Mirai source code: a data section with embedded default login credentials for scanner and brute-force purposes.

The original Mirai and IZ1H9 also both encrypt their login credentials with a 1 byte XOR key. The keys vary in different versions, but this variant uses 0x54, as shown in Figure 7.
![Figure 6. IZ1H9 retrieving strings.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-7.png) Figure 7. IZ1H9 variant credentials XOR decryption.

This IZ1H9 variant initializes the table of nearly 100 pairs of telnet/SSH login credentials in the scanner function. It then spreads through brute forcing network devices' weak username and password combinations.

For the HTTP channel, IZ1H9 uses four remote code execution vulnerabilities to get access to the vulnerable devices, and it executes the shellcode script downloader shown in Figure 8.
![Figure 8 is a screenshot of the exploit scanner function. It shows the Zyxlel RCE, Blink, RCE, Netlog RCE, and the Tense RCE.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-8.png) Figure 8. Exploit scanner function.

Notice that in the Tenda vulnerability exploit function, the payload downloads tenda.sh from the malware host server but executes netlog.sh, as shown in Figure 9. In this case, the exploit will not work.
![Figure 9 is a screenshot of the source code for Mirai. Highlighted in red boxes is tenda.sh, which downloads, and netlog.sh, which executes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-9.png) Figure 9: Malware executes wrong downloader.

The malware will initialize all DDoS attack functions before the botnet client establishes a connection with the C2 server. According to the Mirai source code, the malware developer will define the attack method and assign a command code to represent the attack method, as depicted in Figure 10.
![Figure 10 is a screenshot of the Mirai source code, with the definitions for all of the attack methods.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-10.png) Figure 10. Mirai attack method definition.

In this IZ1H9 sample, the threat actor defines a set of attack methods, shown in Table 1.

|-------------|--------------------------|------------------------------------------|
| **Command** | **Attack Method**        | **Description**                          |
| 0           | attack\_method\_tcpsyn     | TCP SYN flooding attack                  |
| 1           | attack\_method\_tcpack     | TCP ACK flooding attack                  |
| 2           | attack\_method\_tcpusyn    | TCP URG-SYN flooding attack              |
| 3           | attack\_method\_tcpall     | TCP DDoS with all options set            |
| 4           | attack\_method\_tcpfrag    | TCP fragmentation attack                 |
| 5           | attack\_method\_asyn       | TCP SYN-ACK flooding attack              |
| 6           | attack\_method\_udpgame    | UDP attack targets online gaming servers |
| 7           | attack\_method\_udpplain   | UDP flooding with fewer options          |
| 8           | attack\_method\_greip      | GRE IP flooding attack                   |
| 9           | attack\_method\_std        | STD flooding attack                      |
| 10          | attack\_method\_udpdns     | DNS flooding attack                      |
| 11          | attack\_method\_udpgeneric | UDP flooding attack                      |
| 12          | attack\_app\_http          | HTTP flooding attack                     |
| 13          | attack\_method\_dnsamp     | DNS amplification attack                 |

*Table 1. IZ1H9 attack method.*

## Conclusion

IoT devices have always been a lucrative target for threat actors, and remote code execution attacks continue to be the most common and most concerning threats affecting IoT devices and linux servers. Exposed vulnerable devices could lead to serious threats.

The vulnerabilities used by this threat are less complex, but this does not decrease their impact, since they could still lead to remote code execution. Once the attacker gains control of a vulnerable device, they can include the newly compromised devices in their botnet. This allows them to conduct further attacks such as DDoS.

To combat this threat, it is highly recommended that patches and updates are applied when possible.

Palo Alto Networks customers receive protection from the vulnerabilities and malware discussed above through the following products and services:

* Next Generation Firewall with a Threat Prevention security subscription can help block the attacks with Best Practices via Threat Prevention signatures: [93386](https://threatvault.paloaltonetworks.com/?query=93386), [93718](https://threatvault.paloaltonetworks.com/?query=93718), [93721](https://threatvault.paloaltonetworks.com/?query=93721), [93722](https://threatvault.paloaltonetworks.com/?query=93722).
* Advanced Threat Prevention provides inline machine learning that can detect vulnerability exploits in real time.
* WildFire can help stop the malware with static signature detections.
* Advanced URL Filtering and DNS Security are able to block the C2 domain and malware-hosting URLs.
* The Palo Alto Networks IoT Security platform can leverage network traffic information to identify the vendor, model and firmware version of a device, and it can identify specific devices that are vulnerable to particular CVEs.
* In addition, IoT Security has inbuilt machine learning-based anomaly detection that can alert the customer if a device exhibits nontypical behavior such as the sudden appearance of traffic from a new source, an unusually high number of connections, or an inexplicable surge of certain attributes typically appearing in IoT application payloads.

## Indicators of Compromise

### Artifacts

**Shell Script Downloader**

* 692a5d099e37cd94923ea2b2014d79e6e613fb061a985069736dd3d55d4330c4
* e0b1c324298eeccd54ffc2ff48288ec51fbec44f5f82229537508785a9bda6de
* 931800d4f84bda7c0368c915dfd27721d63ed0ce6a9bc9f13e1417d4c2fe88f3
* 64a350a33757f6631dc375632de191967ae59c876b4718a087e299bd54f23844

**Mirai Variant Sample**

* 23190d722ba3fe97d859bd9b086ff33a14ae9aecfc8a2c3427623f93de3d3b14
* 00b151ff78a492b5eae0c8d3c769857f171f8424cf36c3b2505f7d7889109599
* 212b1af9fd1142d86b61956ac1198623f9017153153cfc20bfeab6a9fd44004a
* 38406b2effd9fc37ce41ee914fda798de9c9b0e239a0cc94b1464dc2a9984fe9
* 21185d9b7344edcd8d9c4af174e468c38cb3b061e6bd6bd64a4be9bd3fa27ff5
* 65a46cd29dad935d067a4289445d2efb2710d44d789bf1bf0efb29f94d20e531
* 06ef6c76e481d25aa09b3b15959d702be29c22d63bd35524766397e3d36d0d2e
* 7bfb02c563ae266e81ba94a745ea7017f12010d5491708d748296332f26f04f5
* 1e29f364f502b313f01f28f1ae85bf27114fae5eede6550809fe5bca58f59174

### Infrastructure

**Malware C2**

* 193\.47.61\[.\]75
* 195\.133.40\[.\]141
* dotheneedfull\[.\]club

**Malware Host**

* 163\.123.143\[.\]126
* 2\.56.59\[.\]215
* 212\.192.241\[.\]72
* 212\.192.241\[.\]87
* 31\.210.20\[.\]100

## Additional Resources

* [Mirai Variant V3G4 Targets IoT Devices](https://unit42.paloaltonetworks.com/mirai-variant-v3g4/) - Unit 42, Palo Alto Networks
* [New Mirai Variant Targeting Network Security Devices](https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/) - Unit 42, Palo Alto Networks
* [Mirai Variant MooBot Targeting D-Link Devices](https://unit42.paloaltonetworks.com/moobot-d-link-devices/) - Unit 42, Palo Alto Networks
* [Network Security Trends: August-October 2022](https://unit42.paloaltonetworks.com/network-security-trends-aug-oct-2022/) - Unit 42, Palo Alto Networks

## Appendix

Campaign-related vulnerability information is listed below:

[**CVE-2023-27076**](https://nvd.nist.gov/vuln/detail/CVE-2023-27076)**: Tenda G103 Command Injection Vulnerability**

This malicious traffic was first detected as a part of the IZ1H9 campaign on April 10, 2023. The command injection vulnerability is due to the failure to sanitize the value of the language parameter in the cgi-bin/luci interface of Tenda G103.
![Figure 11 is a screenshot of the Tenda G103 command injection vulnerability. It shows the cgi-bin.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-11.png) Figure 11. CVE-2023-27076 exploit in the wild.

[**CVE-2023-26801**](https://nvd.nist.gov/vuln/detail/CVE-2023-26801)**: LB-Link Command Injection Vulnerability**

We captured this exploit traffic on April 10, 2023. The exploit targets a command injection vulnerability in the LB-Link wireless router's /goform/set\_LimitClinet\_cfg component, which does not successfully sanitize the user input in the time1, time2 and mac parameters. This leads to arbitrary command execution.
![Figure 12 is a screenshot of the LB-Link command injection vulnerability, including the component that is exploited.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-12.png) Figure 12. CVE-2023-26801 exploit in the wild.

[**CVE-2023-26802**](https://nvd.nist.gov/vuln/detail/CVE-2023-26802)**: DCN DCBI-Netlog-LAB Remote Code Execution Vulnerability**

The exploit was detected on April 10, 2023. The exploit works due to the Digital China Network DCBI-Netlog-LAB nsg\_masq.cgi component failing to adequately sanitize the user-supplied input data, which leads to remote command execution.
![Figure 13 is a screenshot of the DCN DCBI-Netlog-LAB Remote Code execution vulnerability. It shows the nsg\_masq.cgi component in the first line of a screenshot.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-13.png) Figure 13. CVE-2023-26802 exploit in the wild.

[**Zyxel Remote Code Execution Vulnerability**](https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-code-execution-and-denial-of-service-vulnerabilities-of-cpe)

We observed this exploit traffic on Dec. 16, 2022. The exploit targets the Zyxel router's /bin/zhttpd/ component. If insufficient input validation is found, the attacker can exploit the vulnerability to launch a remote code execution attack.
![Figure 14 is a screenshot of the Zyxel remote code execution vulnerability. Included is the line that is exploited in the router, /b/zhttpd/.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/05/word-image-128221-14.png) Figure 14. Zyxel router exploit in the wild.

*Updated May 26, 2023, at 3:30 p.m. PT.*
Back to top

### Tags

* [CVE-2023-26801](https://unit42.paloaltonetworks.com/tag/cve-2023-26801/ "CVE-2023-26801")
* [CVE-2023-26802](https://unit42.paloaltonetworks.com/tag/cve-2023-26802/ "CVE-2023-26802")
* [CVE-2023-27076](https://unit42.paloaltonetworks.com/tag/cve-2023-27076/ "CVE-2023-27076")
* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")
* [IZ1H9](https://unit42.paloaltonetworks.com/tag/iz1h9/ "IZ1H9")
* [Mirai variant](https://unit42.paloaltonetworks.com/tag/mirai-variant/ "Mirai variant")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: It's All in the Name: How Unit 42 Defines and Tracks Threat Adversaries](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/ "It’s All in the Name: How Unit 42 Defines and Tracks Threat Adversaries")

### Table of Contents

* 

### Related Articles

* [Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "article - table of contents")
* [FrostyGoop's Zoom-In: A Closer Look into the Malware Artifacts, Behaviors and Network Communications](https://unit42.paloaltonetworks.com/frostygoop-malware-analysis/ "article - table of contents")
* [New Vulnerability in QNAP QTS Firmware: CVE-2023-50358](https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
