[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/pensive-ursa-uses-upgraded-kazuar-backdoor/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/ "Threat Actor Groups")
* [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/ "Nation-State Cyberattacks")  
  [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)

# Over the Kazuar's Nest: Cracking Down on a Freshly Hatched Backdoor Used by Pensive Ursa (Aka Turla)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 20 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Daniel Frank](https://unit42.paloaltonetworks.com/author/daniel-frank/)
  * [Tom Fakterman](https://unit42.paloaltonetworks.com/author/tom-fakterman/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:October 31, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/)
  * [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/)
  * [Kazuar](https://unit42.paloaltonetworks.com/tag/kazuar/)
  * [Pensive Ursa](https://unit42.paloaltonetworks.com/tag/pensive-ursa/)
  * [Turla](https://unit42.paloaltonetworks.com/tag/turla/)
  * [Uroburos](https://unit42.paloaltonetworks.com/tag/uroburos/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/?pdf=download&lg=en&_wpnonce=edee969a51 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/?pdf=print&lg=en&_wpnonce=edee969a51 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=Over%20the%20Kazuar’s%20Nest:%20Cracking%20Down%20on%20a%20Freshly%20Hatched%20Backdoor%20Used%20by%20Pensive%20Ursa%20(Aka%20Turla)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fpensive-ursa-uses-upgraded-kazuar-backdoor%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpensive-ursa-uses-upgraded-kazuar-backdoor%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpensive-ursa-uses-upgraded-kazuar-backdoor%2F&title=Over%20the%20Kazuar’s%20Nest:%20Cracking%20Down%20on%20a%20Freshly%20Hatched%20Backdoor%20Used%20by%20Pensive%20Ursa%20(Aka%20Turla)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpensive-ursa-uses-upgraded-kazuar-backdoor%2F&text=Over%20the%20Kazuar’s%20Nest:%20Cracking%20Down%20on%20a%20Freshly%20Hatched%20Backdoor%20Used%20by%20Pensive%20Ursa%20(Aka%20Turla)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpensive-ursa-uses-upgraded-kazuar-backdoor%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=Over%20the%20Kazuar’s%20Nest:%20Cracking%20Down%20on%20a%20Freshly%20Hatched%20Backdoor%20Used%20by%20Pensive%20Ursa%20(Aka%20Turla)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fpensive-ursa-uses-upgraded-kazuar-backdoor%2F> "Share in Mastodon")

## Executive Summary

While tracking the evolution of Pensive Ursa (aka Turla, Uroburos), Unit 42 researchers came across a new, upgraded variant of Kazuar. Not only is Kazuar another name for the enormous and dangerous cassowary bird, Kazuar is an advanced and stealthy .NET backdoor that Pensive Ursa usually uses as a second stage payload.

[Pensive Ursa](https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/) is a Russian-based threat group operating since at least 2004, which is linked to the [Russian Federal Security Service (FSB)](https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network).

The [Ukrainian CERT](https://cert.gov.ua/article/5213167) reported in July 2023 that this version of Kazuar was targeting the Ukrainian defense sector. The threat group behind this variant was going after sensitive assets such as those found in Signal messages, source control and cloud platforms data.

Since [Unit 42](https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/)'s discovery of Kazuar in 2017, we have seen it in the wild only a handful of times, targeting mostly organizations in the European government and military sectors. [The Sunburst backdoor](https://thehackernews.com/2021/01/researchers-find-links-between-sunburst.html) has been tied to Kazuar by code resemblance, which demonstrates its complexity level. Since late 2020, we had not seen new Kazuar samples in the wild -- yet reports suggested Kazuar was under constant development.

As the code of the upgraded revision of Kazuar reveals, the authors put special emphasis on Kazuar's ability to operate in stealth, evade detection and thwart analysis efforts. They do so using a variety of advanced anti-analysis techniques and by protecting the malware code with effective encryption and obfuscation practices.

This article provides a deep technical analysis of Kazuar's capabilities. We are sharing this research to provide detection, prevention and hunting recommendations to help organizations strengthen their overall security posture. An additional list of artifacts will be provided in an [appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md) linked to [our GitHub](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information) page.

Palo Alto Networks customers receive protections from and mitigations for the threats mentioned in this article in the following ways:

* Next-Generation Firewall with the Advanced Threat Prevention security subscription can help block the malware C2 traffic
* Organizations can engage the [Unit 42 Incident Response](https://start.paloaltonetworks.com/contact-unit42.html) team for specific assistance with this threat and others
* The Cortex XDR and XSIAM platform detects and prevents the threats mentioned in this article
* The [Advanced WildFire](https://www.paloaltonetworks.com/resources/datasheets/advanced-wildfire) machine-learning models and analysis techniques have been reviewed and updated in light of this new Kazuar variant.

| **Related Unit 42 Topics** | [**Backdoors**](https://unit42.paloaltonetworks.com/tag/backdoor/), **[Pensive Ursa](https://unit42.paloaltonetworks.com/tag/pensive-ursa/)** |
|----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------|

## Kazuar Overview

Kazuar is known for being an advanced and stealthy .NET backdoor that Pensive Ursa usually uses as a second stage payload, delivered together with other tools that the threat group commonly uses.

The recent campaign that the [Ukrainian CERT](https://cert.gov.ua/article/5213167) reported unveiled the multi-staged delivery mechanism of Kazuar, together with other tools such as the new Capibar first-stage backdoor. Our technical analysis of this recent variant -- seen in the wild after years of hiatus -- showed significant improvements to its code structure and functionality.

This post will detail previously undocumented features, including:

* [Comprehensive system profiling](#post-130890-_lz74dc7im8ye) - Extensive data collection.
* [Credential theft of cloud and other sensitive applications](#post-130890-_5higatyq4hy) - Theft of cloud application accounts, source control and Signal messaging application.
* [Extended set of commands](#post-130890-_tf1renih7nn9) - A total of 45 supported commands to execute, received from another Kazuar node or the command and control (C2) server.
* [Enhanced task automation](#post-130890-_9pmase4f3klc) - A range of automated tasks that the attacker could turn on/off.
* [Variable encryption schemes](#post-130890-_iyihiznxpnx1) - Implementation of different encryption algorithms and schemes.
* [Injection modes](#post-130890-_epngo2omwiwz) \*\*-\*\*Multiple injection modes, allowing Kazuar to run from different processes and execute different features.

Since at least 2018, variants of Kazuar changed their obfuscation methods and methodically modified its compilation timestamps. Some variants used the ConfuserEx obfuscator to encrypt strings, and others used a custom method. In the Kazuar variant analyzed in this blog, the authors went a step further, implementing multiple custom methods for string encryption.

Unlike with previous variants, the authors only focused on targeting the Windows operating system.

Clarification note: While analyzing Kazuar's code, we used [dnSpy](https://github.com/dnSpy/dnSpy) to export the code into an integrated development environment (IDE) and decrypted the strings using a custom script. This allowed us to edit separate .cs files and edit some of the method names into meaningful ones. We have interpreted the method names that appear in the screenshots.

## Latest Kazuar Variant Detailed Technical Analysis

### Metadata

[Reports from other research organizations](https://securelist.com/sunburst-backdoor-kazuar/99981/) have shown that the authors of Kazuar have [manipulated their samples' timestamps](https://attack.mitre.org/techniques/T1070/006/) since at least 2018. This new variant's compilation timestamp is Thursday, November 20, 2008 10:11:18 AM GMT. Unlike other publicly available variants, this is the first time the authors went back as far as 2008 when faking the timestamp.

Kazuar also contains hard-coded, hashed identifiers for the Agent version and BuildID as well as an Agent label. These can be used as variant identifiers, as shown in Figure 1.
![Image 1 is the configuration information for a Kazuar sample. It includes the agent configuration information in two separate columns. There is the configuration column and the value column. Some of the information has been redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-1.png) Figure 1. Kazuar's sample basic configuration information.

### Initialization

#### Executing Assembly Check

When executing Kazuar, it uses the [Assembly.Location](https://learn.microsoft.com/en-us/dotnet/api/system.reflection.assembly.location?view=net-7.0) property to receive its own file path and check its name. Kazuar will continue execution only if the returned value is an empty string, as shown in Figure 2. The Assembly.Location property returns an empty string when loading the file from a byte array.

This check appears to be a simple form of an anti-analysis mechanism, to ensure that the execution of the malware was done by the intended loader and not by other means or software.

Kazuar will execute if its filename matches a specific hard-coded hashed name (using the FNV algorithm). This behavior is probably meant for debugging purposes, letting the authors avoid using the loader each time they debug the malware.
![Image 2 is a screenshot of several lines of code whereby the Kazuar variant’s assembly name is checked.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-2.png) Figure 2. Checking the Kazuar variant's assembly name.

#### Operational Root Directory Creation

Kazuar creates a new directory to store its configuration and log data. It uses %localappdata% as the main storage path and determines its root directory from a list of hard-coded paths (See [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md)).

Kazuar chooses which root directory, folder names, filenames and file extensions to use based on the machine globally unique identifier ([GUID](https://learn.microsoft.com/en-us/dotnet/api/system.guid?view=net-7.0)), as shown in Figure 3. Although these names might seem randomly generated at a first glance, the usage of the GUID means they will keep the same name for each execution of the malware on the same infected machine.
![Image 3 is a screenshot of several lines of code. The use of GUID allows Kazuar to choose root directories and the like to use.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-3.png) Figure 3. The method in charge of returning an index for the paths array.

Like in previous variants, Kazuar uses a structured directory scheme to save its log files and other data such as individual configuration files and keylogger data. Directory naming is pseudorandom and chosen based on hashing. Examples include the custom implementation of the FNV hashing algorithm seen in previous variants, and other manipulations on the GUID value. You can find a list of the directories in their plaintext names in the [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md).

It is also worth mentioning that there is a currently unreferenced option to create a file called wordlist in the code. This file could give us a clue about a feature not yet implemented, perhaps using a wordlist for directories, filenames or password brute forcing.

#### Configuration Files

The malware creates a separate main configuration file that includes data including the following:

* C2 servers
* Injection mode
* Other operational configuration data

Figure 4 shows a snippet from this file below. You can find the encryption methods for Kazuar's configuration files in the [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md).
![Image 4 is the configuration file for the Kazuar sample. Some information has been redacted. The information includes the agent information, last contact, transport information, log information, etc.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-4.png) Figure 4. Snippet of the configuration file.

#### Mutex Name Generation

Kazuar is using a mutex to check its injection into another process. Kazuar generates its mutex name by XORing the current process ID with the hard-coded value 0x4ac882d887106b7d and then XORing it with the machine's GUID, as depicted in Figure 5. This means that several Kazuars can operate in tandem on the same device, just not injected into the same process.
![Image 5 is a screenshot of the mutex name generator.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-5.png) Figure 5. Mutex name generation.

### Architecture

#### Setting Kazuar's Injection Modes

The new version of Kazuar uses what it describes in the configuration as "injection modes" as shown in Table 1. The default mode is inject.

|----------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------|----------------------|---------------------------------------------------------------------------|
| **Configuration file mode name** | **Description**                                                                                                                                                 | **Inbound traffic** | **Outbound traffic** | **Additional functionality threads**                                      |
| inject                           | \* Default mode, injects into explorer.exe \* Creates a pipe communication channel and serves as a proxy for other Kazuar instances                               | Named pipe          | Named pipe           | \* Event Log Monitor \* Keylogging \* Peeps \* Automated tasks \* Anti-Dumping |
| zombify                          | \* Injects into the user's default browser or svchost.exe \* Creates a named pipe communication channel and serves as a proxy for other Kazuar instances          | Named pipe          | HTTP                 | \* Anti-Dumping                                                            |
| combined                         | In case the default inject method fails, it executes via the same method as zombify                                                                             | N/A                 | N/A                  | N/A                                                                       |
| remote                           | Creates a named pipe communication channel and serves as a proxy for other Kazuar instances, no C2 communication                                                | Named pipe          | Named pipe           | \* Event Log Monitor \* Automated tasks                                     |
| single                           | \* Creates a named pipe communication channel and serves as a proxy for other Kazuar instances \* This mode enables C2 communication to receive commands via HTTP | Named pipe or HTTP  | Named pipe or HTTP   | \* Event Log Monitor \* Keylogging \* Peeps \* Automated tasks                |
| Not in User Interactive Mode     | In case Kazuar's execution is in a user interactive mode, which could occur when executing Kazuar as a service or on a machine with no GUI such as a server.    | Named pipe          | Named pipe           | \* Automated tasks \* WMI consumer \* Anti-Dumping                           |

*Table 1. Kazuar injection modes and descriptions.*

In zombify mode, Kazuar is injected into the user's default browser and has a fallback mechanism to inject itself to svchost.exe in case the query for the default browser fails. Figure 6 shows that the term zombify addresses process injection in general by Kazuar's authors.
![Image 6 is a screenshot of many lines of code. Using zombify mode, Kazuar performs code injection.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-6.png) Figure 6. A snippet of Kazuars' code injection in zombify mode.

#### Multithreading Model

Kazuar operates in a multithreading model, while each of Kazuar's main functionalities operates as its own thread. In other words, one thread handles receiving commands or tasks from its C2, while a solver thread handles execution of these commands. This multithreading model enables Kazuar's authors to establish an asynchronous and modular flow control. Figure 7 shows the task solver flow.
![Image 7 is a diagram of Kazuar’s task-solving mechanism. Enclosed in the encrypted result file is the delimiter, result identifier, encrypted GUID length, RSA encrypted HMACMD5 hash and IV and AES key and the AES encrypted task BLOB. The results file is read and sent to C2. The send thread writes tasks in the task file and and the task file is read by a task resolver thread.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-7.png) Figure 7. Kazuar's task-solving mechanism diagram.

#### The Task Solver Component - Kazuar's Puppeteer

Kazuar receives new tasks, solves them and writes the output into result files. A solver thread is handling new tasks received from the C2 servers or another Kazuar node. The task content is then encrypted and written to disk into a task file.

Each task file implements a hybrid encryption scheme:

1. Using [RNGCryptoServiceProvider](https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.rngcryptoserviceprovider?view=net-7.0) to generate two byte-arrays containing random numbers, which are 16 and 32 bytes long respectively.
   * Using the first array as an [AES (Rijndael)](https://www.tutorialspoint.com/cryptography/advanced_encryption_standard.htm) initialization vector (IV).
   * Using the second array as an AES key.
2. Generating an [HMACMD5](https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.hmacmd5?view=net-7.0) hash based on the result's content from memory, prior to its encryption and writing to disk, using the array described in the first bullet above as the key.
3. Encrypting the HMACMD5 hash, AES key and IV with the hard-coded RSA key, and writing the encrypted BLOB to the beginning of the file. By using the fast AES algorithm to encrypt larger objects such as the result's contents, and using the slower RSA encryption to conceal the AES key and IV, Kazuar improves its performance. This also disables the option of recovering infected files only from disk, since the symmetric key is encrypted using an asymmetric key.
4. Using the AES encryption to encrypt the result file's contents.

As shown in Figure 8, once a task is complete, the generated result file will be saved to disk.
![Image 8 is a screenshot of many lines of mode. Kazuar uses this code to encrypt and then write a result file.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-8.png) Figure 8. A snippet of Kazuar's method to encrypt and write a result file.

In addition to the aforementioned encrypted data, Kazuar writes the following fields to the beginning of the result file:

1. Four zero bytes (we believe this serves as a sort of a delimiter)
2. Generated result identifier
3. Length of the encrypted GUID, using the same XOR algorithm as in the initialization part (the encrypted message here is "System info at \[datetime\] (-07)")
4. The encrypted GUID itself
5. RSA encrypted HMACMD5 hash + IV + AES key
6. The AES encrypted task content

Figure 9 shows the encrypted result file content from disk.
![Image 9 is a screenshot of an encrypted result file. Highlighted in red are the Delimiter, generated result identifier, encrypted UUID length, the encrypted GUID content, the RSA encrypted HMACDM5 hash + IV \_ AES key and the AES encrypted task content.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-9.png) Figure 9. An encrypted result file content from disk.

#### Strings Encryption

Kazuar's code includes a high volume of strings that are related to functionality and debugging. When revealed in plain text, they shed light on the inner workings and functionality of Kazuar. To avoid the scenario of researchers creating strings-based indicative YARA and hunting rules, Kazuar's strings are encrypted. It decrypts each string at runtime.

Kazuar uses a variation of a [Caesar Cipher](https://en.wikipedia.org/wiki/Caesar_cipher) for the string encryption/decryption algorithm. In this algorithm, Kazuar implements a dictionary that simply swaps the key and value of each member. Recent Kazuar variants implemented only one dictionary, while the new variant implements multiple dictionaries, each containing 80 pairs of characters as shown in Figure 10.
![Image 10 is a screenshot of many lines of code. It is contains the dictionary information used for the string decryption.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-10.png) Figure 10. One of the classes containing the dictionary used for string decryption.

Figure 11 shows a loop iterating over a given string, and checking if the ordinal value of a given character is in the dictionary keys of the relevant class. If it is, Kazuar swaps the key and value and appends it to the crafted string. Otherwise, it keeps the original character.

In addition to the string obfuscation, the authors have given unmeaningful names to the classes and methods in the code, to make analysis more difficult.
![Image 11 is a screenshot of many lines of code. This loop creates a deobfuscated string.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-11.png) Figure 11. The loop that creates the deobfuscated string.

One of the strings decoded by Kazuar returns the value "Invalid pong responce" as shown in Figure 12. It seems that one of the malware coders forgot to switch the Russian C for an English S.
![Image 12 is a screenshot of a table. The two columns are Name and Value. In the name column are JJ, stringBuilder and i. The corresponding values are listed next to them.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-12.png) Figure 12. The typo in the "response" string.

### Core Functionality

[In a fashion typical to Pensive Ursa](https://www.recordedfuture.com/turla-apt-infrastructure), to avoid takedowns, Kazuar uses hijacked legitimate websites for its C2 infrastructure. In addition, as mentioned in the [Injection Modes](#post-130890-_epngo2omwiwz) section, Kazuar also supports communication over named pipes. It uses both mechanisms to receive remote commands, or tasks (as described in the code).

#### Supported C2 Commands

Kazuar supports 45 different tasks it can receive from its C2, as shown in Table 2. This is yet another development in Kazuar's code, as previous research hadn't documented some of these tasks. By comparison, Kazuar's first variant analyzed back in 2017 supported only 26 C2 commands.

We have grouped Kazuar's commands into the following categories:

* Host data collection
* Extended forensic data collection
* File manipulation
* Arbitrary command execution
* Interaction with Kazuar's configuration
* Registry querying and manipulation
* Scripts execution (VBS, PowerShell, JavaScript)
* Custom network requests
* Credentials and sensitive information stealing

|-------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command** | **Description**                                                                                                                                                                                                                                                                                                          |
| sindex      | Searches for properties of files with the following extensions: .txt, .ini, .config, .vbs, .js, .ps1, .doc, .docx, .xls, .xlsx, .ppt, .pptx under folders in the C:\\Users\\ path.                                                                                                                                       |
| scrshot     | Takes a screenshot of the window of a specified process                                                                                                                                                                                                                                                                  |
| move        | Moves a file from a source path to a destination path                                                                                                                                                                                                                                                                    |
| info        | Gets system information about one or multiple of the fields (described in [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md))                                                                                 |
| steal       | Steals data from various browsers and applications (full list ID in [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md))                                                                                       |
| run         | Executes a specified executable with supplied arguments, save the output to a temporary file, and upload the file to the C2 server.                                                                                                                                                                                      |
| schlist     | Gets data about scheduled tasks using the Schedule.Service COM object                                                                                                                                                                                                                                                    |
| config      | Updates Kazuar's configuration file                                                                                                                                                                                                                                                                                      |
| netuse      | Connects or removes network resources from the machine using the [WNetAddConnection2](https://learn.microsoft.com/en-us/windows/win32/api/winnetwk/nf-winnetwk-wnetaddconnection2a) and [WNetCancelConnection2](https://learn.microsoft.com/en-us/windows/win32/api/winnetwk/nf-winnetwk-wnetcancelconnection2a) WinAPIs |
| log         | Adds a custom log to the log file                                                                                                                                                                                                                                                                                        |
| delegate    | Sends a command to another Kazuar implant on a remote system using a PIPE                                                                                                                                                                                                                                                |
| eventlog    | Gets Windows Event log entries                                                                                                                                                                                                                                                                                           |
| get         | Uploads files from a specified directory to Kazuar's C2 servers, choosing which files to upload based on their modified, accessed and created timestamps.                                                                                                                                                                |
| autoruns    | Checks various possibilities for software to have persistence in the infected machine (checks described in [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md))                                                |
| put         | Writes received data to a specified file on the system.                                                                                                                                                                                                                                                                  |
| regwrite    | Sets a registry key/value.                                                                                                                                                                                                                                                                                               |
| autoslist   | Lists the number of files that were created under the Autos functionality                                                                                                                                                                                                                                                |
| vbs         | Executes a VBScript                                                                                                                                                                                                                                                                                                      |
| psh         | Executes a PowerShell Script                                                                                                                                                                                                                                                                                             |
| sleep       | Sets Kazuar to sleep for a specified amount of time                                                                                                                                                                                                                                                                      |
| regdelete   | Deletes a registry key/value                                                                                                                                                                                                                                                                                             |
| timelimit   | Sets a time limit for a task from the server                                                                                                                                                                                                                                                                             |
| dlllist     | Gets all loaded modules of a specified process                                                                                                                                                                                                                                                                           |
| autosget    | Sends files created by the Autos functionality to the C2                                                                                                                                                                                                                                                                 |
| wmiquery    | Executes a WMI Query                                                                                                                                                                                                                                                                                                     |
| dotnet      | Executes a .NET method received from the C2                                                                                                                                                                                                                                                                              |
| tasklist    | Gets a list of running processes                                                                                                                                                                                                                                                                                         |
| find        | Finds a specified directory and lists its files. It appears the actor can specify which files to list based on their modified, accessed and created timestamps as well.                                                                                                                                                  |
| peep        | Executes a command related to the peeps functionality, which we have described in the peeps section.                                                                                                                                                                                                                     |
| forensic    | Checks the system for multiple forensic artifacts (see [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md))                                                                                                    |
| kill        | Kills a process by name or by process identifier (PID)                                                                                                                                                                                                                                                                   |
| regquery    | Queries a registry key                                                                                                                                                                                                                                                                                                   |
| chakra      | Executes Javascript using [ChakraCore](https://github.com/chakra-core/ChakraCore)                                                                                                                                                                                                                                        |
| http        | Creates a crafted HTTP request                                                                                                                                                                                                                                                                                           |
| pipelist    | Gets open pipe list for a specific machine                                                                                                                                                                                                                                                                               |
| jsc         | Executes JavaScript                                                                                                                                                                                                                                                                                                      |
| wmicall     | Calls a WMI method                                                                                                                                                                                                                                                                                                       |
| autosdel    | Deletes files created by the Autos functionality                                                                                                                                                                                                                                                                         |
| del         | Deletes a specified file OR folder. Allows the attacker to supply a flag to securely delete a file by overwriting the file with random data before deleting it.                                                                                                                                                          |
| nbts        | Crafts a NetBIOS request                                                                                                                                                                                                                                                                                                 |
| copy        | Copies a specified file to a specified location. The attacker is able to overwrite the destination file if it already exists.                                                                                                                                                                                            |
| upgrade     | Downloads an upgrade to the malware                                                                                                                                                                                                                                                                                      |
| cmd         | Executes a command via cmd.exe                                                                                                                                                                                                                                                                                           |
| unattend    | Steals files related to various windows configuration or cloud applications credentials (full list of files is included in [Appendix)](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md)                                |
| autosclear  | Clears the Autos log list of files                                                                                                                                                                                                                                                                                       |

*Table 2. Kazuar's supported C2 commands.*

#### Cloud, Source Control and Messaging Apps Credential Theft

Kazuar has the capability to attempt to steal credentials from many artifacts in the infected computer, by receiving the commands steal or unattend from the C2.

These artifacts include multiple well-known cloud applications.

Kazuar can attempt to steal sensitive files that contain credentials for these applications. Artifacts targeted by Kazuar include Git SCM (a source control system that is popular among developers), as shown in Figure 13, and Signal (an encrypted messaging service for private instant messaging). We have included the full description of the artifacts in the [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md).
![Image 13 is a screenshot of many lines of code. This is an example of Git SCM credentials Kazuar could steal.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-13.png) Figure 13. Code snippet of Git SCM credentials Kazuar may attempt to steal.

#### Comprehensive System Profiling

When Kazuar is initially spawning a unique solver thread, the first task it automatically executes is the extensive collection and profiling of the targeted system, named by Kazuar's authors as first\_systeminfo\_do. As part of this task, Kazuar will collect extensive information about the infected machine and will send it to the C2. This includes information on the operating system, hardware and network. The [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md) includes the entirety of what the attackers collected.

Kazuar saves this data into an info.txt file and saves the execution logs to a logs.txt file. As mentioned in the [Task Solver](#post-130890-_iyihiznxpnx1) section, we can see the result in memory. In this case, it's an archive, as depicted in Figure 14.
![Image 14 is a screenshot of the result of the first\_systeminfo\_do archive in memory. Highlighted in red is the zip header 0x50, 0x4B, 0x03, 0x04.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-14.png) Figure 14. The result of the first\_systeminfo\_do archive in memory.

Besides the two aforementioned text files, as part of this task, the malware takes a screenshot of the user's screen. Figure 15 shows the zipping of all of these files into one archive before being encrypted and sent to the C2.
![Image 15 is a 7zip folder. The path has been redacted. The contents of the folder are scrshot000.jpg, info.txt and logs.txt. The folder also includes the Size, Packed Size, Attributes, Encrypted and Comment information.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-15.png) Figure 15. The result of the first\_systeminfo\_do archive extracted memory, prior to encryption.

#### Creating Automated Tasks (Autos)

Kazuar has the ability to set up automated tasks that will run at specified intervals to gather information from the infected machines. Figure 16 shows an example of this functionality as documented in Kazuar's configuration.

These automated tasks include the following:

* Gathering system information (described in the section on Comprehensive System Profiling)
* Taking screenshots
* Stealing credentials (listed in full in the [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md))
* Getting forensics data (see [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md))
* Getting auto-runs data (see [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md))
* Getting files from specified folders.
* Getting a list of LNK files
* Stealing emails using [MAPI](https://en.wikipedia.org/wiki/MAPI)

![Image 16 is a screenshot of the configuration of the Autos function by Kazuar. it includes information such as the maximal storage count, result size, collect with system, do deleted files and similar commands.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-16.png) Figure 16. A snippet of Kazuar's configuration of the Autos function.

#### Monitoring Active Windows (Peeps)

Kazuar has the ability to let attackers set up what they called "peep rules" in the configuration. Although Kazuar does not come with these rules set out of the box, according to the malware's code, it appears that this functionality enables the attacker to monitor the windows of specified processes. This allows the attacker to track user activity of interest on the compromised machine.

### Communication With the Command and Control

#### HTTP

Prior to establishing a communication channel with a C2 server, and in addition to the aforementioned anti-analysis checks, Kazuar checks the configuration data-sending time intervals. This check includes determining whether it should send data over the weekend or not.

Upon first communication, Kazuar sends the collected data (described in the Comprehensive System Profiling section) in an XML format and expects to get an XML structured response back with a new task. Figure 17 shows the HTTP request.

Kazuar uses a hard-coded value 169739e7-2112-9514-6a61-d300c0fef02d casted to a string and Base64 encoded as the cookie.
![Image 17 is a screenshot of the HTTP POST command. Highlighted in red are the hardcoded cookie value in base64 and the generated XML tags.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-17.jpeg) Figure 17. HTTP POST command with an XML in the body sent to the C2.

Kazuar generates key names for the XML and Base64 encrypts the content prior to sending it to the C2. The content of the XML contains:

* Encrypted content of the result file
* Result identifier
* Pseudorandom 4-byte numbers, probably another type of identifier
* An array with values pseudorandomly generated based on the machine's GUID
* The hard-coded GUID connection string 169739e7-2112-9514-6a61-d300c0fef02d
* The machine's unique GUID

#### Communication Using Named Pipes

In addition to direct HTTP communication with the C2, Kazuar has the ability to function as a proxy, to receive and send commands to other Kazuar agents in the infected network. It is doing this proxy communication via [named pipes](https://learn.microsoft.com/en-us/windows/win32/ipc/named-pipes), generating their names based on the machine's GUID.

Kazuar uses these pipes to establish peer-to-peer communication between different Kazuar instances, configuring each as a server or a client. The named pipe communication supports the remote requests shown in Table 3.

|--------------------|-----------------------|----------------------------------------------------------------|
| **Remote Request** | **Kazuar's Response** | **Description**                                                |
| PING               | PONG                  | Return a message with the current instance process information |
| TASK               | RESULT                | Start a received task and return a result                      |
| LOGS               | ERROR                 | Retrieve error logs                                            |

*Table 3. Kazuar requests and responses using named pipes.*

### Anti-Analysis Checks

Kazuar uses multiple anti-analysis techniques based on a series of elaborate checks, to ensure it is not being analyzed. The authors programmed Kazuar to either continue if the coast is clear, or to remain idle and cease all C2 communication if it is being debugged or analyzed. We can group these checks into three main categories: honeypot, analysis tools and sandbox.

#### Anti-Dumping

Because Kazuar is not designed to run as a standalone process but rather lives injected within another process, dumping its code is possible from memory of the injected process. To prevent that from happening, Kazuar uses a powerful feature of .NET, which is the [System.Reflection Namespace](https://learn.microsoft.com/en-us/dotnet/api/system.reflection?view=net-7.0). This gives Kazuar the ability to gather real-time metadata about its assembly, methods and more.

Kazuar checks if it has set the antidump\_methods setting to true, then overrides the pointers to its custom methods, while ignoring generic .NET methods, essentially wiping them from memory (as Kazuar's logged message states). This ultimately prevents researchers from dumping an intact version of the malware.

#### Honeypot Check

One of the first things Kazuar specifically searches for is the existence of Kaspersky honeypot artifacts on the machine. It uses a hard-coded list of specific process names and filenames to do this.

If Kazuar finds more than five of these files or processes, it will log that it found a Kaspersky honeypot. Figure 18 shows these filenames.
![Image 18 is a screenshot of many lines of code. Using these dictionary items, Kazuar checks the filenames to find the Kaspersky honeypot.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-18.png) Figure 18. Filenames that Kazuar checks to find Kaspersky honeypot.

#### Analysis Tools Check

Kazuar has a list of hard-coded names of different popular analysis tools such as the following:

* Process Monitor
* X32dbg
* DnSpy
* Wireshark

It goes over the list of running processes, and if one of these tools is running, Kazuar will log that it found analysis tools (see [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md)).

#### Sandbox Check

Kazuar has a list of hard-coded known sandbox libraries. It checks for the presence of certain DLLs that belong to different sandbox services. If the malware finds these files, it determines that it is being executed in a lab (see [Appendix](https://github.com/PaloAltoNetworks/Unti42-Threat-Intelligence-Article-Information/blob/main/Appendix-for-article-on-Pensive-Ursa-using-Kazuar.md)).

#### Event Log Monitor

Kazuar collects and parses events from the Windows event logs. Figure 19 shows Kazuar specifically looking for events from the following antivirus/security vendors:

* Kaspersky Endpoint Security
* Symantec Endpoint Protection Client
* Microsoft Windows Defender
* Doctor Web

Same as with checking for Kaspersky's honeypot, a plausible explanation would be that these security products are popular with their victims.
![Image 19 is a screenshot of many lines of code. Using these dictionary items, Kazuar collects event logs from specific security products suck as Kaspersky, Symantec, Defender and others.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-19.png) Figure 19. Event logs that Kazuar collects from specific security products.

## Strengthening Kazuar's Connection to Pensive Ursa

[As mentioned above](#post-130890-_v56xgfp87lmn), when composing its initial HTTP POST request to its C2, Kazuar uses the machines GUID or a hard-coded GUID 169739e7-2112-9514-6a61-d300c0fef02d as a cookie, which is then type casted to string and Base64 encoded.

Searching the latter value in its string format (169739e7211295146a61d300c0fef02d) yields a [report \[PDF\] by the Swiss CERT](https://www.govcert.ch/downloads/whitepapers/Report_Ruag-Espionage-Case.pdf), which analyzes an attack carried out by Pensive Ursa against [RUAG](https://www.ruag.com/en). RUAG Holding is a Swiss company from the aerospace and defense sector.

In addition, Kazuar's tasks and results architecture, including the hybrid AES + RSA encryption scheme and other clear similarities in functionality, are the very image of Carbon's modus operandi. It is mentioned both in the Swiss's CERT report and another [report by ESET](https://www.welivesecurity.com/2017/03/30/carbon-paper-peering-turlas-second-stage-backdoor/). Carbon is another second stage backdoor that was attributed multiple times to Pensive Ursa, whose code was a fork of Snake, as mentioned by CISA.

These findings, along with the reports by multiple CERTs, further support the [previous Unit 42 assumptions](https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/) proposing that Kazuar might be Carbon's successor. Most importantly, these findings strengthen the attribution of Kazuar to Pensive Ursa.

## Conclusion

We examined the newest Kazuar malware variant that we detected in the wild. Notable features include the following:

* Robust code and string obfuscation techniques
* A multithreaded model for enhanced performance
* A range of encryption schemes implemented to safeguard Kazuar's code from analysis and to conceal its data whether in memory, during transmission or on disk

All the aforementioned features are designed to provide the Kazuar backdoor a high level of stealth. Other noteworthy characteristics of this malware are:

* Its anti-analysis functionalities
* Extensive system profiling capabilities
* The specific targeting of cloud applications

This version of Kazuar also supports an array of over 40 distinct commands, half of which were previously undocumented.

We encourage security practitioners and defenders to study this report and use the information provided to enhance current detection, prevention and hunting practices to overall strengthen their security posture.

## Cortex XDR Detection and Prevention

Figure 20 shows Cortex XDR detected and prevented the execution of Kazuar. As detailed in the [technical analysis](#post-130890-_epngo2omwiwz) section, by default Kazuar injects its code into explorer.exe. When configured to operate on detect mode, Cortex XDR detects the malicious activity originating from the injected explorer.exe, as depicted in Figure 20 below.
![Image 20 is a screenshot of Cortex XDR’s detection of malicious activity from explorer.exe. The severity is rated high and the description is “Suspicious execution of native code.”](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-20.png) Figure 20. Kazuar's detection, shown in Cortex XDR in detect mode.

Execution of native code by Kazuar for process injection and WMI execution triggered several alerts, as well as other suspicious and uncharacteristic activity carried out by explorer.exe. We detailed the alerts, including the alert shown in Figure 20, in Figure 21 below.
![Image 21 is a screenshot of an alert table from Cortex XDR. Three alerts are listed in total. The descriptions of the alerts are also included. Some information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-21.png) Figure 21. Kazuar's execution alerts, shown in Cortex XDR in detect mode.

In addition, Figure 22 documents and details the [directory and files](#post-130890-_kftpeznwvieo) that the malware created to store its configuration and logs.
![Image 22 is a screenshot of an alert table from Cortex XDR. Six alerts are listed in total. Five are file writes and the sixth is Create Directory Event. The file path is also listed, and some information is redacted from each row.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-22.png) Figure 22. Kazuar's execution alerts as seen in Cortex XDR on detect mode.

Finally, Figure 23 shows that when in prevent mode, Cortex XDR prevents the Kazuar malware executable and triggers the alert pop-up accordingly.
![Image 23 is an alert window in Cortex XDR. Cortex XDR has blocked a malicious activity! Application name: Senatorial.exe. Application publisher: Unknown. Prevention description: Suspicious executable detected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-23.png) Figure 23. Kazuar's execution prevention alert as seen in Cortex XDR on prevent mode.

## Protections and Mitigations

The Cortex XDR platform detects and prevents the execution flow described in the screenshots included in the previous section.

In addition to the classic detection, the unique [SmartScore](https://www.paloaltonetworks.com/blog/security-operations/beating-alert-fatigue-with-cortex-xdr-smartscore-technology/) engine translates security investigation methods and their associated data into a ML-driven hybrid risk scoring system. Figure 24 shows that the Kazuar variant and its related incident detailed in this blog scored 97 out of 100 by SmartScore.
![Image 24 is a screenshot of the SmartScore for Kazuar. The score is 97. There is a list of reasons for the score, as well as a list of insights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/10/word-image-130890-24.png) Figure 24. The score given to Kazuar in SmartScore.

For Palo Alto Networks customers, our products and services provide the following coverage associated with this group.

[Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?_gl=1*13pmp8e*_ga*NzQyNjM2NzkuMTY2NjY3OTczNw..*_ga_KS2MELEEFC*MTY2OTczNjA2MS4zMS4wLjE2Njk3MzYwNjEuNjAuMC4w) and [XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam) detect user and credential-based threats by analyzing user activity from multiple data sources including the following:

* Endpoints
* Network firewalls
* Active Directory
* Identity and access management solutions
* Cloud workloads

Cortex XDR and XSIAM build behavioral profiles of user activity over time with machine learning. By comparing new activity to past activity, peer activity and the expected behavior of the entity, Cortex XDR and XSIAM detect anomalous activity indicative of credential-based attacks.

It also offers the following protections related to the attacks discussed in this post:

* Prevents the execution of known malicious malware and also prevents the execution of unknown malware using [Behavioral Threat Protection and](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention?_gl=1*13pmp8e*_ga*NzQyNjM2NzkuMTY2NjY3OTczNw..*_ga_KS2MELEEFC*MTY2OTczNjA2MS4zMS4wLjE2Njk3MzYwNjEuNjAuMC4w) machine learning based on the Local Analysis module
* Protects against credential gathering tools and techniques using the new Credential Gathering Protection available from Cortex XDR 3.4
* Protects against exploitation of different vulnerabilities including ProxyShell and ProxyLogon using the Anti-Exploitation modules as well as Behavioral Threat Protection
* Cortex XDR Pro and XSIAM [detect postexploit activity](https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/analytics-alerts-by-required-data-source), including credential-based attacks, with behavioral analytics
* [Next-Generation Firewall](https://docs.paloaltonetworks.com/ngfw) with the [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration) security subscription can help block the malware C2 traffic via the following Threat Prevention signature: [86805](https://threatvault.paloaltonetworks.com/?query=86805).
* The [Advanced WildFire](https://www.paloaltonetworks.com/resources/datasheets/advanced-wildfire) machine-learning models and analysis techniques have been reviewed and updated in light of this new Kazuar variant. Multiple products in the Palo Alto Networks portfolio leverage Advanced WildFire to provide coverage against Kazuar variants and other threats.

If you think you might have been impacted or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html?_gl=1*13pmp8e*_ga*NzQyNjM2NzkuMTY2NjY3OTczNw..*_ga_KS2MELEEFC*MTY2OTczNjA2MS4zMS4wLjE2Njk3MzYwNjEuNjAuMC4w) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

**Kazuar SHA256**

* 91dc8593ee573f3a07e9356e65e06aed58d8e74258313e3414a7de278b3b5233

**Command and Control Servers**

* hxxps://www.pierreagencement\[.\]fr/wp-content/languages/index.php
* hxxps://sansaispa\[.\]com/wp-includes/images/gallery/
* hxxps://octoberoctopus.co\[.\]za/wp-includes/sitemaps/web/

**RSA Keys**

* \<RSAKeyValue\>\<Modulus\>7ondEZo8ZjYh+FP4h3PgJBU/yTlO+g8ZbCF0wx8eocnqxLS4YWI9hG3SI2hlEBz6J4vvxPCrs/jazekolaZLQnbyOCyH53I+We+x32d2lUlXrtZA/0oJa39tW2t2NsUG/xPqsY3rBCuhi28hl30XH8Arn2/u9Jxl1G9dNxFDdVxk9ePjlHecdAtWCa9vmC4HY0Wlqyhd0+hJfvKCoKLsHuCyl4b/c343VVVTFubYNSFJMQnpIKsYQDRKtRszQuS1Ls+obyOr+0cbAmnKb8twTsq862pA6MzxRr16/4/1nyrNKuDS+OvPfv3tgvssybtGwN8D8Qac7O1FM722Nft16iis9WaoFuXCwP/LCkaetQMjEKN07H6ESHMnUc+JDvINIspAAKK8fRwtTcWKrG2bh/Dwtneq/9L1Pv2cKtpQAUlxVfQX5I/mtATEHIMcPOvNWRUqmSssDHEJiZDFKS45SjoG4qXs536xwbZ4k6lmHUUOVzkmCc71HooxRdSYx1M7Vqvou1Mi39O6vJouL2aTO6ymbGdnerKavDsgBSa2HKRbP2Nym6Ud4WAhiaqnPCWGnJz7l+4Hs++OcG2p+Ct1oXRecLK6Zy/n9moTZeijLdqJwUh90Bht8V8STz/vNtrhz++Do6DsDssENkOHXeUeRCqCmDdS3sqkxQnGAG3tGvc=\</Modulus\>\<Exponent\>AQAB\</Exponent\>\</RSAKeyValue\>
* \<RSAKeyValue\>\<Modulus\>pyR0/srVS0gOZbNdK3iK+GvekQVkBq8brOVCuN/XcCz4WLJod9GhivDYrDtMXF6ZMGHKa2zAcQ+v2vltYW3X2BYCZ1sblEznfIk+oHs+lesblfHVyPPXDcTLLf5IUuGE/dzeSpLhlWiFT/4MyeMLzU8QexpRkBn0qJkk5xWU0D09DN0SaNzA8E4grU61aaul5iNRYMO+qLXmtIJhrjUrnHNu7ZnZ+AQtc19Dhne1hciH4aj00HRLXsofWGWsELEhZv92cnQ0Rf9n00EGB591zDR8gAt3T5sSTQvjMGWOBHusfGV4ytmchmQWZ8QY7Fp4EPgn8vM48OR2z13qo4YSediAt9Af+YKGoPu2PU3szx08UwBZRz4cyYZB3zcFB8NxCx7Gki2rS5bYx1Z1cG/kU+Ri2gXYoCHgOz8umr+PDB+21V1pnmStxzWAdR7mK0e663LMxxAcZWjEArbt/BcIiZAkFsyoq+NJbuKTR2RYAW+4DXbxFQeGKnFBgle3u9ktcYXWqgJ8/rvs920rGf9k3br3I+2MtzrWglhRi/WkAmTrEIL4i1id0M0askl0YBHlzU9+Bgv2y/VsLH2UKQlp+owxGm1jequxwGpZfwxmWAMATe8L2qctVdXEOfT7Ue67AsVjkP/VmhbhGDO8zt38trylUhWnpUeYdkigg9Nxs1k=\</Modulus\>\<Exponent\>AQAB\</Exponent\>\</RSAKeyValue\>

## Additional References

* [Targeted Turla attacks (UAC-0024, UAC-0003) using CAPIBAR and KAZUAR malware](https://cert.gov.ua/article/5213167) \[English version\] -- CERT-UA (Ukraine)
* [Kazuar: Multiplatform Espionage Backdoor with API Access](https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/) -- Unit 42, Palo Alto Networks
* [Researchers Find Links Between Sunburst and Russian Kazuar Malware](https://thehackernews.com/2021/01/researchers-find-links-between-sunburst.html) -- The Hacker News
* [Nation-state Turla resurfaces with a Sophisticated RAT](https://e.cyberint.com/hubfs/CyberInt_Russian%20Backed%20Turla%20Resourfaces%20with%20a%20Sophisticated%20RAT_Report.pdf) -- Cyberint (PDF)
* [Guid Struct (System)](https://learn.microsoft.com/en-us/dotnet/api/system.guid?view=net-7.0) -- Microsoft Learn
* [Technical Report about the Malware used in the Cyberespionage against RUAG](https://www.govcert.ch/whitepapers/apt-case-ruag-technical-report-govcert-ch/) -- Swiss GovCERT
* [Turla renews its arsenal with Topinambour](https://securelist.com/turla-renews-its-arsenal-with-topinambour/91687/) -- Securelist, Kaspersky
* [Hunting Russian Intelligence "Snake" Malware](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a) -- Cybersecurity Advisory, CISA
* [Indicator Removal: Timestomp, Sub-technique T1070.006 - Enterprise](https://attack.mitre.org/techniques/T1070/006/) -- MITRE ATT\&CK
* [Swallowing the Snake's Tail: Tracking Turla Infrastructure](https://www.recordedfuture.com/turla-apt-infrastructure) -- Recorded Future
* [Carbon Paper: Peering into Turla's second stage backdoor](https://www.welivesecurity.com/2017/03/30/carbon-paper-peering-turlas-second-stage-backdoor/) -- WeLiveSecurity, ESET
* [Carbon, Software S0335](https://attack.mitre.org/software/S0335/) -- MITRE ATT\&CK
* [Threat Group Assessment: Turla (aka Pensive Ursa)](https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/) -- Unit 42, Palo Alto Networks

Back to top

### Tags

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")
* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")
* [Kazuar](https://unit42.paloaltonetworks.com/tag/kazuar/ "Kazuar")
* [Pensive Ursa](https://unit42.paloaltonetworks.com/tag/pensive-ursa/ "Pensive Ursa")
* [Turla](https://unit42.paloaltonetworks.com/tag/turla/ "Turla")
* [Uroburos](https://unit42.paloaltonetworks.com/tag/uroburos/ "Uroburos")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: CloudKeys in the Air: Tracking Malicious Operations of Exposed IAM Keys](https://unit42.paloaltonetworks.com/malicious-operations-of-exposed-iam-keys-cryptojacking/ "CloudKeys in the Air: Tracking Malicious Operations of Exposed IAM Keys")

### Table of Contents

* 

### Related Articles

* [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "article - table of contents")
* [CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure](https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/ "article - table of contents")
* [Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns](https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/ "article - table of contents")

## Related Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
