[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/mirai-variant-v3g4/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/mirai-variant-v3g4/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Mirai Variant V3G4 Targets IoT Devices

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 9 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![IoT Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)IoT Security](https://unit42.paloaltonetworks.com/product-category/iot-security/ "IoT Security")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Chao Lei](https://unit42.paloaltonetworks.com/author/chao-lei/)
  * [Zhibin Zhang](https://unit42.paloaltonetworks.com/author/zhibin-zhang/)
  * [Aveek Das](https://unit42.paloaltonetworks.com/author/aveek-das/)
  * [Cecilia Hu](https://unit42.paloaltonetworks.com/author/cecilia-hu/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:February 15, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/)
  * [IoT Vulnerability](https://unit42.paloaltonetworks.com/tag/iot-vulnerability/)
  * [Mirai variant](https://unit42.paloaltonetworks.com/tag/mirai-variant/)
  * [V3G4](https://unit42.paloaltonetworks.com/tag/v3g4/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/mirai-variant-v3g4/?pdf=download&lg=en&_wpnonce=0e33cfdd78 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/mirai-variant-v3g4/?pdf=print&lg=en&_wpnonce=0e33cfdd78 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Mirai%20Variant%20V3G4%20Targets%20IoT%20Devices&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-v3g4%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-v3g4%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-v3g4%2F&title=Mirai%20Variant%20V3G4%20Targets%20IoT%20Devices "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-v3g4%2F&text=Mirai%20Variant%20V3G4%20Targets%20IoT%20Devices "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-v3g4%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Mirai%20Variant%20V3G4%20Targets%20IoT%20Devices%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fmirai-variant-v3g4%2F "Share in Mastodon")

## Content Warning

We are providing a content warning because the following contains usage of a racial slur by a threat actor, which is not condoned in any instance by Unit 42. Unit 42 has partially redacted the racial slur to provide researchers with the ability to identify it and check IoCs as needed.

## Executive Summary

From July to December 2022, Unit 42 researchers observed a Mirai variant called V3G4, which was leveraging several vulnerabilities to spread itself. The vulnerabilities exploited include the following:

* [CVE-2012-4869](https://nvd.nist.gov/vuln/detail/CVE-2012-4869): FreePBX Elastix Remote Command Execution Vulnerability
* [Gitorious Remote Command Execution Vulnerability](https://www.exploit-db.com/exploits/18393)
* [CVE-2014-9727](https://nvd.nist.gov/vuln/detail/CVE-2014-9727): FRITZ!Box Webcam Remote Command Execution Vulnerability
* [Mitel AWC Remote Command Execution Vulnerability](https://www.exploit-db.com/exploits/15807)
* [CVE-2017-5173](https://nvd.nist.gov/vuln/detail/CVE-2017-5173): Geutebruck IP Cameras Remote Command Execution Vulnerability
* [CVE-2019-15107](https://nvd.nist.gov/vuln/detail/cve-2019-15107): Webmin Command Injection Vulnerability
* [Spree Commerce Arbitrary Command Execution Vulnerability](https://web.archive.org/web/20110726024546/http://www.spreecommerce.com/blog/2011/04/19/security-fixes/)
* [FLIR Thermal Camera Remote Command Execution Vulnerability](https://www.exploit-db.com/exploits/42788)
* [CVE-2020-8515:](https://nvd.nist.gov/vuln/detail/CVE-2020-8515) DrayTek Vigor Remote Command Execution Vulnerability
* [CVE-2020-15415](https://nvd.nist.gov/vuln/detail/CVE-2020-15415): DrayTek Vigor Remote Command Injection Vulnerability
* [CVE-2022-36267](https://nvd.nist.gov/vuln/detail/CVE-2022-36267): Airspan AirSpot Remote Command Execution Vulnerability
* [CVE-2022-26134](https://nvd.nist.gov/vuln/detail/CVE-2022-26134): Atlassian Confluence Remote Code Execution Vulnerability
* [CVE-2022-4257](https://nvd.nist.gov/vuln/detail/CVE-2022-4257): C-Data Web Management System Command Injection Vulnerability

Once the vulnerable devices are compromised, they will be fully controlled by attackers and become a part of the botnet. The threat actor has the capability to utilize those devices to conduct further attacks, such as distributed denial-of-service (DDoS) attacks. The exploit attempts captured by Unit 42 researchers leverage the aforementioned vulnerabilities to spread V3G4, which targets exposed servers and networking devices running Linux.

Palo Alto Networks [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) customers receive protections through [cloud-delivered security services](https://www.paloaltonetworks.com/network-security/security-subscriptions) such as [IoT Security](https://www.paloaltonetworks.com/network-security/smart-devices-smarter-iot-security?utm_source=google-jg-amer-cdss&utm_medium=paid_search&utm_term=palo%20alto%20networks%20iot%20security&utm_campaign=google-cdss-iot_security-amer-ca-awareness-en&utm_content=gs-19633824690-151442986731-646705931499&sfdcid=7014u000001hHCRAA2&gclid=EAIaIQobChMI1Lm26OmS_QIVQUNyCh1G3gKWEAAYASAAEgJ3KvD_BwE), [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention), [WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire), and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering), which can help detect and block the exploit traffic and malware.

|----------------------------|----------------------------------------------------------------------------------------------------------------------------------|
| **Related Unit 42 Topics** | [**Mirai**](https://unit42.paloaltonetworks.com/tag/mirai-variant/)**,** [**IoT**](https://unit42.paloaltonetworks.com/tag/iot/) |

## Campaign Overview

Since July 2022, Unit 42 researchers have observed three campaigns utilizing the Mirai V3G4 variant. Based on our analysis, we believe the campaigns were operated by the same threat actor for the following reasons:

* The hardcoded command and control (C2) domains among these three campaigns contain the same string (8xl9)
* The malware shell script downloaders are almost identical between the three campaigns
* The botnet client samples use the same XOR decryption key
* The botnet client samples use the same "stop list" (a list of target processes that the botnet client searches for and terminates)
* The botnet client samples use almost identical functions

The threat actor exploited 13 vulnerabilities that could lead to remote code execution. Upon successful exploitation, the wget and curl utilities are automatically executed to download Mirai client samples from malware infrastructure and then execute the downloaded bot clients.

The utilized vulnerabilities are listed in Figure 1 below, and the detailed vulnerability information is listed in the [Appendix](#post-126924-_ajb20h1i7fau) section.
![Image 1 is a timeline overview of the V3G4 campaign. For each of the three campaigns it lists the callback IP, the botnet C2, the month and year, and the exploited vulnerabilities. The campaigns were in July, September, and December of 2022.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-1.png) Figure 1. V3G4 Campaign Overview.

## V3G4 Malware Analysis

Based on behavior and patterns Unit 42 researchers observed during analysis of the downloaded botnet client samples, we believe that the botnet sample is a variant of the Mirai botnet.

Upon execution, the botnet client prints xXxSlicexXxxVEGA. to the console. The malware also contains a function that makes sure only one instance of this malware is executing on the infected device. If a botnet process already exists, the botnet client will simply print a string from the console and exit, as depicted in Figure 2.
![Image 2 is a screenshot of the botnet printing a string from the console.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-2.png) Figure 2. V3G4 ensures single instance execution.

The botnet client also contains a list of process names, and it tries to terminate those processes by checking the running process names on the infected host. The process names in that list belong to other botnet malware families and other Mirai variants. The full stop list is shown in Figure 3.
![Image 3 is a screenshot of the full stop list of V3G4.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-3.png) Figure 3. V3G4's stop list.

The V3G4 variant tries to connect to its hardcoded C2. This activity is shown in Figure 4.
![Image 4 is a screenshot of many lines of code where the V3G4 variant is trying to connect to the hardcoded C2.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-4.png) Figure 4. V3G4 malware C2 domain.

Most Mirai variants use the same key for string encryption. However, this V3G4 variant uses different XOR encryption keys for different scenarios.

### **Botnet Client Execution-Related String Decryption**

For strings related to botnet client execution, this V3G4 variant will first initialize an encrypted string table. It will then retrieve the encrypted string through an index (shown in Figures 5 and 6).
![Image 5 is a screenshot of the V3G4’s initialization of an encrypted string table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-5.png) Figure 5. Encrypted string table. ![Image 6 is a screenshot of V3G4’s retrieved strings from the encrypted string table. Highlighted is the line where V3G4 retrieves strings from the index.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-6.png) Figure 6. V3G4 retrieves strings.

All the botnet client execution-related strings are decrypted with four rounds of XOR decryption (shown in Figure 7). The decryption keys used are the following:

* First round: 0xbc
* Second round: 0x69
* Third round: 0x3a
* Fourth round: 0xe6

![Image 7 is a screenshot of four rounds of XOR decryption by V3G4 using the keys 0xbc, 0x69, 0x3a and 0xe6.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-7.png) Figure 7. V3G4 four rounds of XOR decryption.

### **Brute Force Credential String Decryption**

V3G4 inherits its most significant feature from the original Mirai variant -- a data section with embedded default login credentials for the scanner and brute force purposes. Like the original Mirai, it also encrypts all credentials with XOR key 0x37.
![Image 8 is a screenshot of V3G4’s encrypting credentials with XOR key 0x37.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-8.png) Figure 8. V3G4 credentials XOR Decryption.

The V3G4 variant initializes the table of telnet/SSH login credentials in the scanner function. It then spreads itself through brute forcing network devices' weak username/password combinations.

Before the botnet client establishes a connection with the C2 server, the malware will first initialize all DDoS attack functions (shown in Figure 9). Once the client establishes a connection with the C2 server, the threat actor can issue commands to the client to launch DDoS attacks.
![Image 9 is a screenshot of the malware’s DDoS attack functions. Four of them are highlighted in red, all starting with “attack.”](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-9.png) Figure 9. V3G4 DDoS functions.

We also noticed that the malware samples from the three campaigns we observed are slightly different. The original Mirai botnet sample spread itself by brute-forcing weak telnet/SSH credentials, whereas some Mirai variants utilize both brute-force and embedded exploits to spread themselves. However, samples from the September and December 2022 campaigns don't contain the functions of vulnerability exploitation and brute force of credentials (this is shown in Figure 10).
![Image 10 is a sample comparison of the July and December campaigns. Highlighted in the July campaign in red with an arrow is “scanner\_init()”.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-10.png) Figure 10. Campaign samples comparison.

## Conclusion

The vulnerabilities mentioned above have less attack complexity than previously observed variants, but they maintain a critical security impact that can lead to remote code execution. Once the attacker gains control of a vulnerable device in this manner, they could take advantage by including the newly compromised devices in their botnet to conduct further attacks such as DDoS. Therefore, it is highly recommended that patches and updates are applied when possible.

Palo Alto Networks customers receive protection from the vulnerabilities and malware discussed above through the following products and services:

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with a Threat Prevention security subscription can help block the attacks with Best Practices via Threat Prevention signatures [56254](https://threatvault.paloaltonetworks.com/?query=56254), [56954](https://threatvault.paloaltonetworks.com/?query=56954), [92632](https://threatvault.paloaltonetworks.com/?query=92632), [55935](https://threatvault.paloaltonetworks.com/?query=55935), [55933](https://threatvault.paloaltonetworks.com/?query=55933), [58668](https://threatvault.paloaltonetworks.com/?query=58668), [35131](https://threatvault.paloaltonetworks.com/?query=35131), [55798](https://threatvault.paloaltonetworks.com/?query=55798), [57897](https://threatvault.paloaltonetworks.com/?query=57897), [56256](https://threatvault.paloaltonetworks.com/?query=56256), [55934](https://threatvault.paloaltonetworks.com/?query=55934), [93332](https://threatvault.paloaltonetworks.com/?query=93332) and [93392](https://threatvault.paloaltonetworks.com/?query=93392).
* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention) has an inbuilt machine learning-based detection that can detect vulnerability exploits in real-time.
* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) can help stop the malware with static signature detections.
* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [DNS Security](https://www.paloaltonetworks.com/network-security/dns-security) are able to block the C2 domain and malware-hosting URLs.
* The Palo Alto Networks [IoT Security](https://www.paloaltonetworks.com/network-security/smart-devices-smarter-iot-security?utm_source=google-jg-amer-cdss&utm_medium=paid_search&utm_term=palo%20alto%20networks%20iot%20security&utm_campaign=google-cdss-iot_security-amer-ca-awareness-en&utm_content=gs-19633824690-151442986731-646705931499&sfdcid=7014u000001hHCRAA2&gclid=EAIaIQobChMI1Lm26OmS_QIVQUNyCh1G3gKWEAAYASAAEgJ3KvD_BwE) platform can leverage network traffic information to identify the vendor, model and firmware version of a device and identify specific devices that are vulnerable to particular CVEs.
* In addition, IoT Security has inbuilt machine learning-based anomaly detection that can alert the customer if a device exhibits nontypical behavior such as a sudden appearance of traffic from a new source, an unusually high number of connections or an inexplicable surge of certain attributes typically appearing in IoT application payloads.

## Indicators of Compromise

### Infrastructure

#### Malware C2

![IoCs with slur removed](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-11.png)

comeanalyze.8x19\[.\]com

#### Malware Host

176\.123.9\[.\]238  
198\.98.49\[.\]79  
104\.244.72\[.\]64

### Artifacts

#### Shell Script Downloader

0837de91aa6bd52ef79d744daba4238a5a48a79eb91cb1a727da3e97d5b36329  
c32f8df3cb019e83e0ac49ab0462c59ec70733c3d516ade011727408751c9d42  
f295904d966889afb0f6b3625e504a1420a978434e2b6a9e9b85b688a44593fa

#### V3G4 Sample

July Campaign

7bc99c87a1e0582b5f15f40141226862fbe726b496e1e77c7f95993e8e945733  
88f7b9a8c4f9bb28582c485549b328d6123e8aea33009ce7657f7fc0ef829e03  
64545e94daafba191669333e1dd0c6e1190df47e0742bd515911cce0cdbd4fd1  
69bb44736817dabe88e3014c6207ba702f644fb43f6feaec23091af0b5224bc6  
eaa387fcc12f2d8a7d42f12d27e7dccb4f3e11492a7d3a3a1ce830a11b539d28  
a987d1e113b858d21596bb2dfffe79721d5149bfa782e693aafc0cf47aa8c6dc  
afca95eb143e0180f1594517a44b2d226a2e44de5cbd2cd49b8c6cdb2a0b61ee  
b651f9320f07d7eade9af523297b4bcfd0e0af187272e368e889c988a55ed78e  
6229041985c466c131e48b9ba0d1bb80bdb7556c941ee84aa461fe2efbf1e853  
1dc4777dac6dc4e8c650241e211311c4a418a35ebded72fcdd6bcb965ccf918b  
3e69e8ed741ab39b0914f7e95bf13b2f0ae9f3c1227dcffdea3369e03e8bb792  
b2e4ee94783062658ddf2c41e9acafb401d0f93e3848c027383a5ca19289b786  
dd91943b0d453ace3b19779c88da19c9a386dd3e9d2322c85a4cdcf84a22c663  
a93d999dc0515066c5c2a261f1be47233b358889d0594c14409309818d86347d

September Campaign

31926da5ca004a11c1f46947edb220afe3a53f81cf245b3afae7ea1abaec7c38  
eed4690f6e4d92b511fcde9a712b1a8405c5333e0ad78a4c676a64b22412e149  
210f3f1ffd2ec66a5076a7fea5d83caa8bbcdb0f3bc3bd030c77eded6f4b5d90  
73cc00acc478bf09658a679a4689f34598fe6e92086efe82900242f3cc5b7aec  
1218da43a62da76927484bca73a3eee53425c54625147f8d01149bcef2f09d1e  
2944db28e4505fc439599dae15b10bf57b7cf6c2597f618f41b99bfc65443c61  
4bffc171c0748cc9e3398b1ce8135b125f54f46752768c981c45d3390e8359a1  
b3a17934f6f72941b9a60097ab09228d873a2f8737ee0ea93b08e5f1cc3916d1  
916e00391279b014e53d73c2216a84bd528e18f1f633ba0101288aa963f77c5b  
7dea8dac3f455f3a57fecfa5a047439126556858c239e73cd8feec2dc13bae2c  
a10ce475f64f3821ab32c88f6b013effd40843dd575ceaab46a57f134c2478b6  
d9b5199f36fc416d8a87d798926e0d9dcbb2fe97610cf08d6887dae1355e9439  
feda096ed8ddf4206365d326b3b7cb2d57ca1e89999b0b1da80fb9658dff6e44

December Campaign:

63ACD589A53BDEC49C624F3CB2FC8319218DF721F486E2F15F3C07ABED97AAE6  
1cf3879d9e93d1ff30ce5ec0f64ff15b1db7d8237160c83efed688d800e5ef12  
c5be50880e2b5a8a8d43a5f1fd6f5d36fc665ab9b4031a9b6a4d52222004c2c1  
9b7f36cabbb90dfe9cd75f12c01fb64766dd1ec0f4247dbf8f4477dd64407fbf  
7d9cdf3afb1d52f49d82b1ffe28a3da08c6aeeaa8c5047ba37c73802d2cd9ec2  
9a0d39265b53e1959df49dbc8727ad344abc12a8bc0bd8d8b76f8b150525dca6  
d00fbfc439cb9c5c850690134b0d51f262021c0d04d9934df464980c346c1dc5  
b4f23a88de9b566ce980a8188674319039d2fbe13b049859f8fe4821c92f9200  
3f3fb70e16d65f5f4b21777b87c9aae6072022c3dfbefd177f37c8aef4a6aeee  
67379740ed15e8da8604cc1f0ea715c8641674de66e553c461b3ae782a5d0cbe  
ab3d61a76197003822252124e89987d061d6a4a33b9891cea778d3708cd50447  
6f654198e8efd5aff1c7a903353967d0e96aeff0402cb0a79fabbc10d18c63d2  
c288c200cf7bbebe7a81fd42ca1bd4c6cb6080f28f2cec297a0d3e6aff7876fe

## Additional Resources

* [New Mirai Variant Targeting Network Security Devices](https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/) - Unit 42, Palo Alto Networks
* [Mirai Variant MooBot Targeting D-Link Devices](https://unit42.paloaltonetworks.com/moobot-d-link-devices/) - Unit 42, Palo Alto Networks
* [Network Security Trends: August-October 2022](https://unit42.paloaltonetworks.com/network-security-trends-aug-oct-2022/) - Unit 42, Palo Alto Networks

## Appendix

Campaign-related vulnerability information is listed below:

[**CVE-2012-4869**](https://nvd.nist.gov/vuln/detail/CVE-2012-4869)**: FreePBX Elastix Remote Command Execution Vulnerability**

This malicious traffic was first detected as part of the V3G4 campaign on July 4, 2022. The exploit targets a command injection vulnerability in the FreePBX Elastix callme\_startcall function, which does not successfully sanitize the user input in the callmenum parameter, leading to arbitrary command execution.
![A few lines of code showing the CVE-2012-4869 exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-12.png) Figure 11. CVE-2012-4869 exploit in the wild.

[**Gitorious Remote Command Execution Vulnerability**](https://www.exploit-db.com/exploits/18393)

We captured this exploit traffic on July 4, 2022. The exploit works due to Gitorious' insufficient input validation, which allows the attacker to exploit the vulnerability to launch a command injection.
![A few lines of code showing the Gitorious vulnerability exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-13.png) Figure 12. Gitorious vulnerability exploit in the wild.

[**CVE-2014-9727**](https://nvd.nist.gov/vuln/detail/CVE-2014-9727)**: FRITZ!Box Webcam Remote Command Execution Vulnerability**

We observed this malicious traffic on July 4, 2022. This remote command execution vulnerability is due to a failure to sanitize the value of the var:lang parameter in the cgi-bin/webcm interface of the FRITZ!Box Webcam.
![A few lines of code showing the CVE-2014-9727 exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-14.png) Figure 13. CVE-2014-9727 exploit in the wild.

[**Mitel AWC Remote Command Execution Vulnerability**](https://www.exploit-db.com/exploits/15807)

This exploit traffic was detected on July 4, 2022. The exploit targets a remote command execution vulnerability in the Mitel audio, web and video conferencing (AWC) product. The server fails to adequately sanitize the user-supplied input data, which leads to remote command execution.
![A few lines of code showing the Mitel AWC exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-15.png) Figure 14. Mitel AWC exploit in the wild.

[**CVE-2017-5173**](https://nvd.nist.gov/vuln/detail/CVE-2017-5173)**: Geutebruck IP Cameras Remote Command Execution Vulnerability**

We detected this exploit traffic on July 4, 2022. The user input to Geutebruck IP Cameras' testaction.cgi component is not correctly sanitized, allowing the attacker to run shell commands with root privilege.
![A few lines of code showing the CVE-2017-5173 exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-16.png) Figure 15. CVE-2017-5173 exploit in the wild.

[**CVE-2019-15107**](https://nvd.nist.gov/vuln/detail/cve-2019-15107)**: Webmin Command Injection Vulnerability**

This malicious traffic was detected on July 4, 2022. The exploit targets a command injection vulnerability in the password\_change.cgi component within the Webmin product. The component does not successfully sanitize the parameters, which in turn can lead to arbitrary command execution.
![A few lines of code showing the CVE-2019-15107 exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-17.png) Figure 16. CVE-2019-15107 exploit in the wild.

[**Spree Commerce Arbitrary Command Execution Vulnerability**](https://web.archive.org/web/20110726024546/http://www.spreecommerce.com/blog/2011/04/19/security-fixes/)

We observed this exploit traffic on July 4, 2022. The exploit targets the Spree Commerce product's insufficient input validation, the attacker can exploit the vulnerability to launch a remote command execution attack.
![A few lines of code showing the Spree Commerce exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-18.png) Figure 17. Spree Commerce exploit in the wild.

[**FLIR Thermal Camera Remote Command Execution Vulnerability**](https://www.exploit-db.com/exploits/42788)

This exploit traffic was captured on July 4, 2022. The exploit works due to the FLIR Thermal Camera failing to sanitize user input, which in turn could lead to remote command execution.
![A few lines of code showing the FLIR Thermal Camera exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-19.png) Figure 18. FLIR Thermal Camera exploit in the wild.

[**CVE-2020-8515**](https://nvd.nist.gov/vuln/detail/CVE-2020-8515)**: DrayTek Vigor Remote Command Execution Vulnerability**

We captured this exploit traffic on Sep. 13, 2022. The exploit targets the cgi-bin/mainfunction.cgi component of DrayTek Vigor. The component does not successfully sanitize the value of the HTTP parameter keyPath, which leads to remote command execution.
![A few lines of code showing the CVE-2020-8515 exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-20.png) Figure 19. CVE-2020-8515 exploit in the wild.

[**CVE-2020-15415**](https://nvd.nist.gov/vuln/detail/CVE-2020-15415)**: DrayTek Vigor Remote Command Injection Vulnerability**

This malicious traffic was captured on Sep. 13, 2022. The exploit works due to the /cgi-bin/mainfunction.cgi/cvmcfgupload endpoint of DrayTek Vigor failing to sanitize the value of the HTTP parameter filename.
![A few lines of code showing the CVE-2020-15415 exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-21.png) Figure 20. CVE-2020-15415 exploit in the wild.

[**CVE-2022-36267**](https://nvd.nist.gov/vuln/detail/CVE-2022-36267)**: Airspan AirSpot Remote Command Execution Vulnerability**

We detected this exploit traffic on Sep. 14, 2022. The exploit targets a remote command execution vulnerability in the Airspan AirSpot cgi-bin/diagnostics.cgi component. The component does not successfully sanitize the value of the HTTP parameter targetIP in the pingDiagnostic command.
![A few lines of code showing the CVE-2022-36267 exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-22.png) Figure 21. CVE-2022-36267 exploit in the wild.

[**CVE-2022-26134**](https://nvd.nist.gov/vuln/detail/CVE-2022-26134)**: Atlassian Confluence Remote Code Execution Vulnerability**

This exploit traffic was captured on Sep. 12, 2022. An Object-Graph Navigation Language (OGNL) injection vulnerability exists in the Confluence Server and Data Center that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.
![A few lines of code showing the CVE-2022-26134 exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-23.png) Figure 22. CVE-2022-26134 exploit in the wild.

[**CVE-2022-4257**](https://nvd.nist.gov/vuln/detail/CVE-2022-4257)**: C-Data Web Management System Command Injection Vulnerability**

We observed this malicious traffic on Dec. 25, 2022. The exploit targets a remote code execution vulnerability in the diagnosis\_config\_save.php component of the C-Data Web management system. The component does not properly sanitize the values of the HTTP parameters iface and hostname, which in turn can lead to arbitrary command execution.
![A few lines of code showing the C-Data RCE vulnerability exploit in the wild.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/02/word-image-126924-24.png) Figure 23. C-Data RCE vulnerability exploits traffic.
Back to top

### Tags

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")
* [IoT Vulnerability](https://unit42.paloaltonetworks.com/tag/iot-vulnerability/ "IoT Vulnerability")
* [Mirai variant](https://unit42.paloaltonetworks.com/tag/mirai-variant/ "Mirai variant")
* [V3G4](https://unit42.paloaltonetworks.com/tag/v3g4/ "V3G4")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Machine Learning Versus Memory Resident Evil](https://unit42.paloaltonetworks.com/malware-detection-accuracy/ "Machine Learning Versus Memory Resident Evil")

### Table of Contents

* 

### Related Articles

* [A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "article - table of contents")
* [TOTOLINK X6000R: Three New Vulnerabilities Uncovered](https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/ "article - table of contents")
* [Resurgence of the Prometei Botnet](https://unit42.paloaltonetworks.com/prometei-botnet-2025-activity/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
