[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/popping-eagle-malware/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/popping-eagle-malware/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Popping Eagle: How We Leveraged Global Analytics to Discover a Sophisticated Threat Actor

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 11 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Yuval Zan](https://unit42.paloaltonetworks.com/author/yuval-zan/)
  * [Chen Evgi](https://unit42.paloaltonetworks.com/author/chen-evgi/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 2, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/)
  * [C2](https://unit42.paloaltonetworks.com/tag/c2/)
  * [DLL](https://unit42.paloaltonetworks.com/tag/dll/)
  * [DLL Sideloading](https://unit42.paloaltonetworks.com/tag/dll-sideloading/)
  * [Going Eagle](https://unit42.paloaltonetworks.com/tag/going-eagle/)
  * [Popping Eagle](https://unit42.paloaltonetworks.com/tag/popping-eagle/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/popping-eagle-malware/?pdf=download&lg=en&_wpnonce=7570bbad6f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/popping-eagle-malware/?pdf=print&lg=en&_wpnonce=7570bbad6f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Popping%20Eagle:%20How%20We%20Leveraged%20Global%20Analytics%20to%20Discover%20a%20Sophisticated%20Threat%20Actor&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fpopping-eagle-malware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpopping-eagle-malware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpopping-eagle-malware%2F&title=Popping%20Eagle:%20How%20We%20Leveraged%20Global%20Analytics%20to%20Discover%20a%20Sophisticated%20Threat%20Actor "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpopping-eagle-malware%2F&text=Popping%20Eagle:%20How%20We%20Leveraged%20Global%20Analytics%20to%20Discover%20a%20Sophisticated%20Threat%20Actor "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fpopping-eagle-malware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Popping%20Eagle:%20How%20We%20Leveraged%20Global%20Analytics%20to%20Discover%20a%20Sophisticated%20Threat%20Actor%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fpopping-eagle-malware%2F "Share in Mastodon")

## Executive Summary

To better detect attacks that affect the actions of signed applications -- such as supply-chain attacks, [dynamic-link libraries (DLL) hijacking](https://attack.mitre.org/techniques/T1574/001/), exploitation and malicious thread injection -- we have devised a suite of analytics detectors that are able to detect global statistical anomalies.

Using these new detectors, we found what seems to be an industrial espionage attack. The observed activity includes performing a specially crafted DLL hijacking attack used by a previously unknown piece of malware that we dubbed "Popping Eagle" due to several artifacts found in the samples. It also includes a second stage malicious tool written in [Go](https://go.dev/) dubbed "Going Eagle." In this particular case, we observed the attacker following this by performing several network scans and lateral movement steps.

Discovering Popping Eagle using this new suite of analytics detectors underscores the following key points:

* These analytical and statistical methods have capabilities that allow for the identification of malware that might otherwise have been missed.
* Though the malware loaded itself into a signed process with the goal of remaining undetected, these detectors found it due to the attempted obfuscation.

In this blog post, we discuss the hunting method, analyze the tools used in the attack and detail the actions performed by the attacker in the victim's environment.

Palo Alto Networks customers are protected from this kind of attack by Cortex XDR, as well as the WildFire cloud-delivered security subscription for the Next-Generation Firewall. (Please see the [Conclusion](#post-123243-_y2vks12rn6r1) section for more detail.)

|-------------------|----------------------------|
| Malware Discussed | Popping Eagle, Going Eagle |

## Hunting for Statistical Irregularities in Signed Applications

### Motivation

Over the last couple of years, the number of supply-chain attacks has increased dramatically. Examples include [SolarStorm](https://unit42.paloaltonetworks.com/solarstorm-supply-chain-attack-timeline/), [NotPetya](https://unit42.paloaltonetworks.com/unit42-threat-brief-petya-ransomware/), [Kaseya](https://unit42.paloaltonetworks.com/threat-brief-kaseya-vsa-ransomware-attacks/), [KeRanger](https://unit42.paloaltonetworks.com/new-os-x-ransomware-keranger-infected-transmission-bittorrent-client-installer/) and others.

From previous events, we learned that even though threat actors leveraging supply-chain attacks usually run code on a large number of organizations, they tend to focus the attack's "second stage" on a small number of high-value targets.

Leveraging a large Cortex XDR dataset, we built a global baseline of "normal" application behavior and hunted for anomalies.

Identifying these anomalies detects several kinds of techniques -- examples include supply chain attacks, DLL side-loading or malicious thread injections -- and any attack that may cause a legitimate signed application to behave differently.

### Implementation

Each application can perform several different types of actions. Actions that are shared across multiple environments are more likely to be benign, [so we leverage them to create a global baseline for each application](https://www.paloaltonetworks.com/blog/security-operations/how-cortex-xdr-global-analytics-protects-against-supply-chain-attacks/).

In addition, some actions are unique to each organization, even when performed by the same application (for example, connecting to the domain of the organization itself). Recognizing this, we also build a local baseline for each organization and for each application.

Using these baselines, we compare actions performed by each application and flag anomalous activities.

Once we have a set of suspicious cases, we further analyze them to validate if these are actual attacks.

### Finding Popping Eagle

After filtering out cases with known malicious indicators of compromise (IoCs), we came across the following case:

The application [clicksharelauncher.exe, signed by "Barco N.V.,"](https://www.barco.com/en/clickshare/apps-accessories/clickshare-extension-pack) had been seen in a few hundred different environments, indicating we have a good baseline on its behavior, but it performed unique domain resolutions in only one environment. Furthermore, the domain it contacted, dnszonetransfer\[.\]com, was only seen in that environment, and only on three unique agents out of thousands.

In the course of the research, we found two types of tools left on the hosts that sparked our curiosity as they were unknown not only by hash but also by all other IoCs found during the research (see "[Searching for Related IoCs](#post-123243-_tfneqquju6td)" for further elaboration).

## Analyzing Popping Eagle's First Stage

### Loading Method -- DLL Proxy

Looking into the causality chain of clicksharelauncher.exe, we saw that before it contacted the dnszonetransfer\[.\]com domain, it loaded an unsigned DLL from the same directory as the executable named uxtheme.dll.

This DLL name also belongs to a known Microsoft signed DLL that's usually located at %windir%\\SysWOW64\\UxTheme.dll, and the DLL name is also in the import table of clicksharelauncher.exe.
![The first stage of Popping Eagle includes a DLL proxy. The screenshot shows the import table of clicksharelauncher.exe, which is being used for DLL Search Order Hijacking.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image.png) Figure 1. Partial import table of clicksharelauncher.exe

This is a classic example of [DLL Search Order Hijacking](https://attack.mitre.org/techniques/T1574/001/); clicksharelauncher.exe tries to load uxtheme.dll from the current directory before %windir%\\SysWOW64\\, so it loads the attacker's DLL instead of Microsoft's DLL.

Comparing the export table of the unsigned uxtheme.dll with the original one also shows the same functions, with the addition of one additional exported function: popo.
![Comparing the export table of the malicious proxied DLL (left) and the original DLL (right) reveals that same functions, with the addition of one additional exported function on the malicious side: popo (outlined in red in the screenshot).](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-1.png) Figure 2. Partial export table of the malicious proxied DLL (left) and original DLL (right).

### Analyzing the uxtheme.dll Sample

This executable was written as a 32-bit DLL in C++. The original compiled name from the DLL metadata is CoL\_Final\_Lib.dll, and its compile timestamp records the same day we first saw it. In conjunction with the fact that each of the three hosts we saw it on had a different SHA256 hash, this may indicate that it was compiled "on the spot."

The use of the Barco software as a loader also indicates that the sample was tailor-made to this victim's environment -- its use as a loader is rather unique.

Checking the memory locations of its entry point and exports shows mostly strings, while only one is an actual function. This further indicates that this DLL doesn't implement actual logic for these functions and they only exist to better mimic the proxied DLL.

To run its functionality right away on load (avoiding the need to wait to be called explicitly), the malware runs its main code on the main DLL entry point and in a new thread (to not block the rest of the DLL load flow).
![To run its functionality right away on load (avoiding the need to wait to be called explicitly), the malware runs its main code on the main DLL entry point and in a new thread (to not block the rest of the DLL load flow). This main function decodes the C2 URL (using a simple one-byte XOR) and connects to it using a Win32API function. From strings found in the code, it seems that the malware authors used the open-source C++ project WinHttpClient to perform the network logic. The image shows three screenshots, with arrows flowing from one to the next. Key lines are highlighted in yellow and/or outlined in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-2.png) Figure 3. The malware's main function in the DLL. This function is also called from the popo entry point.

This main function decodes the C2 URL (using a simple one-byte XOR) and connects to it using a Win32API function. From strings found in the code, it seems that the malware authors used the open-source C++ project [WinHttpClient](https://github.com/Goblenus/WinHttpClient/blob/master/WinHttpClient/WinHttpClient.h) to perform the network logic. The malware then enters its main event loop, which performs these actions:

* Sends a POST request to the URL with a hardcoded old Linux user agent and message.
* Verifies that the response starts with Unicode 726563697074 -- "recipt" (may suggest a non-native English-speaking author).
* Parses a struct with several different commands including:
  * Saving files on the remote host.
  * Loading and running DLLs from a specific folder.
* Sleeps for one hour + a randomly generated timeframe.

![The first request sent to the server by the Popping Eagle malware. Note the use of a hardcoded old Linux user agent and message.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-3.png) Figure 4. The first request sent to the server by the malware.

## Going Eagle Second Stage Analysis

Most of the time this DLL was observed, it didn't seem to receive any commands from the malicious actor. But on one occasion the IP resolved by dnszonetransfer\[.\]com temporarily changed to 51.38.89\[.\]53 for a few days when the attacker was active. This is a common tactic attempting to avoid detection where the C2 domain only points to the attacker's infrastructure when the malware needs to be controlled. This attacker-controlled IP used the first-stage malware to load a second stage DLL that we call "Going Eagle."

### Analyzing ClickRuntime-amd86.dll

This executable was written as a 32-bit DLL in [Go](https://go.dev/). The original "compiled name" from the DLL metadata is iphlpapi.dll. Somewhat interestingly, this DLL proxies a different Microsoft DLL by the same name (and mimics all the relevant named export functions). This isn't necessary as the first stage loads it with LoadLibrary and not by the DLL-hijacking technique.
![Comparison of the export tables of the malicious proxied DLL (left) and original DLL (right). Again, we see popo in the malicious proxied DLL - outlined in red in the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-4.png) Figure 5. Partial export table of the malicious proxied DLL (left) and original DLL (right).

There are more similarities between the DLLs although they were written in different languages (C++, Go)

* Compile timestamp -- created and dropped on the same day.
* Created as a proxy DLL.
* Has an export function named popo
* The DllMain and popo functions call a function that invokes the malware's inner logic in another thread (so the malware logic will run right on the DLL load or on another popo invocation).

This tool was created for one task only -- to create a reverse SOCKS proxy to get the attacker control over the machine (as described in the "[Lateral Movement](#post-123243-_bnl0wiknyi4k)" section later on).

Since the malware is written in Go, we can extract extra data from its plaintext strings:

* Original package name Eagle2.5-Client-Dll (outlined in red in Figure 6).
* Original function names (like main.StartEagle).
* Packages from Go standard and extended library (like bufio, log, x/net).
* Packages from other resources like GitHub repositories (outlined in yellow and green in Figure 6).

![The figure shows the original package name outlined in red. Packages from other resources like GitHub repositories are outlined in yellow and green.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-5.png) Figure 6. Strings found in the malware sample. ![Outlined in red is the popo inner call to StartEagle function with the C2 as a parameter.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-6.png) Figure 7. popo inner call to StartEagle function with the C2 as a parameter. ![From clicksharelauncher.exe to DLL search order hijacking, to uxtheme.dll (proxy), to write and load DLL, to ClickRuntime-amd86.dll. Uxtheme.dll communicates with dnszonetransfer\[.\]com, which leads to the first C2, 51.38.89\[.\]53. ClickRuntime communicates with reporterror\[.\]net, which leads to the second C2, 51.75.57\[.\]245](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-7.png) Figure 8. Illustration of the attack flow.

### Lateral Movement

Using the second-stage SOCKS binary, Going Eagle, the attackers tunneled their machine to perform several network-based attacks.

At first, they scanned multiple hosts for open [Remote Desktop Protocol](https://en.wikipedia.org/wiki/Remote_Desktop_Protocol) (RDP) and [Server Message Block](https://en.wikipedia.org/wiki/Server_Message_Block) (SMB) ports, in order to find targets toward which to move laterally. Leveraging password reuse of the local administrator account on several different hosts, the attackers used [Impacket's wmiexec](https://github.com/SecureAuthCorp/impacket/blob/master/examples/wmiexec.py) to run discovery commands on multiple machines.

This caused the following detectors to be raised:
![Cortex XDR Analytics BIOC - Remote WMI process execution; Cortex XDR Analytics BIOC - Uncommon IP Configuration Listing via ipconfig.exe; Cortex XDR Analytics BIOC - Rare NTLM Access by user to host; Cortex XDR Analytics - Multiple Discovery Commands; Cortex XDR Analytics - Failed Connections; Cortex XDR BIOC - Command execution via wmiexec; Cortex XDR Analytics BIOC - Uncommon ARP cache listing via arp.exe; Cortex XDR Analytics BIOC - Uncommon user management via net.exe; Cortex XDR Agent - Behavioral Threat Protection (suspicious remote service); Cortex XDR Agent - Behavioral Threat Protection (impacket\_cmd)](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/Table-1.png) Table 1. Detectors raised in Cortex XDR by the activity of Going Eagle. ![Cortex XDR grouped several lateral-movement related alerts observed in relation to Popping Eagle activity into an Incident.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-9.png) Figure 9. Cortex XDR grouped several lateral-movement related alerts into an Incident.

In addition to wmiexec, the attackers used RDP to move laterally through the network. They uploaded [PsExec](https://attack.mitre.org/software/S0029/) and used it to run taskmgr.exe as SYSTEM to gather credentials by [dumping lsass memory](https://car.mitre.org/analytics/CAR-2019-08-001/#:~:text=The%20Windows%20Task%20Manager%20may,clicking%20%E2%80%9CCreate%20dump%20file%E2%80%9D.).

This was blocked by the Cortex XDR agent as well and raised several other alerts from Cortex XDR Analytics and Cortex XDR BIOCs:
![Cortex XDR Agent - Behavioral Threat Protection, Cortex XDR Analytics BIOC - Suspicious process executed with a high integrity level, Cortex XDR BIOC - PsExec execution EulaAccepted flag added to the Registry; Cortex XDR BIOC - PsExec runs with System privileges](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/Table-2.png) Table 2. Alerts raised from Cortex XDR Analytics and Cortex XDR BIOCs.

At a certain point, the attackers managed to acquire a privileged domain account and tried using it to steal secrets from the domain controller using [Impacket's secretsdump](https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py). But their attempts were blocked by the Cortex XDR agent.![](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-11.png)
![Cortex XDR Agent - heuristic.b.save\_sam\_or\_security\_remote (SYNC - Credential Gathering - 3406296443)](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/Table-3.png) Table 3. Table showing how the Cortex XDR Agent blocked an attempt to steal secrets from the domain controller.

It seems that the attacker failed to reach their goals and stopped trying to move laterally due to the multiple protections in place.

### Second-Stage Timeline

| **Time (UTC)** |                                 **MITRE Technique**                                  |                                                              **Action**                                                              |                                   **Detection**                                    |
|----------------|--------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------|
| Day 1 17:28    | [Dynamic Resolution](https://attack.mitre.org/techniques/T1568/)                     | The attacker changed IP resolution for dnszonetransfer\[.\]com to 51.38.89\[.\]53                                                    |                                                                                    |
| Day 2 20:19    | [Application Layer Protocol](https://attack.mitre.org/techniques/T1071/)             | The infected host got the first command from 51.38.89\[.\]53                                                                         |                                                                                    |
| Day 2 20:19    | [Signed Binary Proxy Execution](https://attack.mitre.org/techniques/T1218/)          | Loaded the second-stage DLL, Going Eagle (ClickRuntime-amd86.dll)                                                                    | Globally uncommon image load from a signed process (Added after the fact)          |
| Day 2 20:19    | [Application Layer Protocol](https://attack.mitre.org/techniques/T1071/)             | First transmission to reporterror\[.\]net                                                                                            | Globally uncommon root domain from a signed process (Added after the fact)         |
| Day 2 20:19    | [Proxy](https://attack.mitre.org/techniques/T1090/)                                  | Attacker machine was tunneled using the SOCKS proxy                                                                                  |                                                                                    |
| Day 2 20:29    | [Network Service Scanning](https://attack.mitre.org/techniques/T1046/)               | Scanned multiple hosts for open RDP, SMB and [Remote Procedure Call](https://en.wikipedia.org/wiki/Remote_procedure_call)(RPC) ports | Failed Connections                                                                 |
| Day 2 20:35    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the first host using wmiexec                                                                                            | Remote WMI process execution                                                       |
| Day 2 20:35    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the first host using wmiexec                                                                                            | Rare NTLM Access By User To Host                                                   |
| Day 2 20:35    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the first host using wmiexec                                                                                            | Command execution via wmiexec                                                      |
| Day 2 20:35    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the first host using wmiexec                                                                                            | Behavioral Threat Protection (suspicious\_remote\_service)                           |
| Day 2 20:35    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the first host using wmiexec                                                                                            | Behavioral Threat Protection (impacket\_cmd)                                        |
| Day 2 20:35    | [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016/) | Run discovery commands                                                                                                               | Uncommon IP Configuration Listing via ipconfig.exe                                 |
| Day 2 20:35    | [Account Discovery](https://attack.mitre.org/techniques/T1087/)                      | Run discovery commands                                                                                                               | Uncommon user management via net.exe                                               |
| Day 2 20:35    | [Account Discovery](https://attack.mitre.org/techniques/T1087/)                      | Run discovery commands                                                                                                               | Uncommon ARP cache listing via arp.exe                                             |
| Day 2 20:35    | [Account Discovery](https://attack.mitre.org/techniques/T1087/)                      | Run discovery commands                                                                                                               | Multiple Discovery Commands                                                        |
| Day 2 20:50    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the second host using wmiexec                                                                                           | Remote WMI process execution                                                       |
| Day 2 20:50    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the second host using wmiexec                                                                                           | Rare NTLM Access By User To Host                                                   |
| Day 2 20:50    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the second host using wmiexec                                                                                           | Command execution via wmiexec                                                      |
| Day 2 20:50    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the second host using wmiexec                                                                                           | Behavioral Threat Protection (suspicious\_remote\_service)                           |
| Day 2 20:50    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the second host using wmiexec                                                                                           | Behavioral Threat Protection (impacket\_cmd)                                        |
| Day 2 20:50    | [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016/) | Run discovery commands                                                                                                               | Uncommon IP Configuration Listing via ipconfig.exe                                 |
| Day 2 20:50    | [Account Discovery](https://attack.mitre.org/techniques/T1087/)                      | Run discovery commands                                                                                                               | Uncommon user management via net.exe                                               |
| Day 2 20:50    | [Account Discovery](https://attack.mitre.org/techniques/T1087/)                      | Run discovery commands                                                                                                               | Uncommon ARP cache listing via arp.exe                                             |
| Day 2 20:50    | [Account Discovery](https://attack.mitre.org/techniques/T1087/)                      | Run discovery commands                                                                                                               | Multiple Discovery Commands                                                        |
| Day 2 20:53    | [Network Service Scanning](https://attack.mitre.org/techniques/T1046/)               | Scanned multiple hosts for open RDP, SMB and RPC ports                                                                               | Failed Connections                                                                 |
| Day 2 20:54    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the third host using wmiexec                                                                                            | Remote WMI process execution                                                       |
| Day 2 20:54    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the third host using wmiexec                                                                                            | Rare NTLM Access By User To Host                                                   |
| Day 2 20:54    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the third host using wmiexec                                                                                            | Command execution via wmiexec                                                      |
| Day 2 20:54    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the third host using wmiexec                                                                                            | Behavioral Threat Protection (suspicious\_remote\_service)                           |
| Day 2 20:54    | [Remote Services](https://attack.mitre.org/techniques/T1021/)                        | Connected to the third host using wmiexec                                                                                            | Behavioral Threat Protection (impacket\_cmd)                                        |
| Day 2 20:54    | [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016/) | Run discovery commands                                                                                                               | Uncommon IP Configuration Listing via ipconfig.exe                                 |
| Day 2 20:54    | [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016/) | Run discovery commands                                                                                                               | Uncommon user management via net.exe                                               |
| Day 2 20:54    | [Account Discovery](https://attack.mitre.org/techniques/T1087/)                      | Run discovery commands                                                                                                               | Uncommon ARP cache listing via arp.exe                                             |
| Day 2 20:54    | [Account Discovery](https://attack.mitre.org/techniques/T1087/)                      | Run discovery commands                                                                                                               | Multiple Discovery Commands                                                        |
| Day 2 21:40    | [Network Service Scanning](https://attack.mitre.org/techniques/T1046/)               | Scanned multiple hosts for open RDP, SMB and RPC ports                                                                               | Failed Connections                                                                 |
| Day 2 21:54    | [Remote Desktop Protocol](https://attack.mitre.org/techniques/T1021/001/)            | Laterally moved using RDP to the fourth host                                                                                         |                                                                                    |
| Day 2 21:56    | [LSASS Memory](https://attack.mitre.org/techniques/T1003/001/)                       | Tried to dump lsass using taskmgr                                                                                                    | Behavioral Threat Protection (minidumpwritedump\_handle\_terminate)                  |
| Day 2 22:01    | [LSASS Memory](https://attack.mitre.org/techniques/T1003/001/)                       | Tried to dump lsass using taskmgr running as SYSTEM                                                                                  | Behavioral Threat Protection (minidumpwritedump\_handle\_terminate)                  |
| Day 2 22:01    | [LSASS Memory](https://attack.mitre.org/techniques/T1003/001/)                       | Tried to dump lsass using taskmgr running as SYSTEM                                                                                  | Suspicious process executed with a high integrity level                            |
| Day 2 22:01    | [LSASS Memory](https://attack.mitre.org/techniques/T1003/001/)                       | Tried to dump lsass using taskmgr running as SYSTEM                                                                                  | PsExec execution EulaAccepted flag added to the Registry                           |
| Day 2 22:01    | [LSASS Memory](https://attack.mitre.org/techniques/T1003/001/)                       | Tried to dump lsass using taskmgr running as SYSTEM                                                                                  | PsExec runs with System privileges                                                 |
| Day 3 01:10    | [NTDS](https://attack.mitre.org/techniques/T1003/003/)                               | Run secretsdump on the first DC and was blocked                                                                                      | heuristic.b.save\_sam\_or\_security\_remote (SYNC - Credential Gathering - 3406296443) |
| Day 3 01:36    | [NTDS](https://attack.mitre.org/techniques/T1003/003/)                               | Run secretsdump on the second DC and was blocked                                                                                     | heuristic.b.save\_sam\_or\_security\_remote (SYNC - Credential Gathering - 3406296443) |
| Day 8 11:16    | [Dynamic Resolution](https://attack.mitre.org/techniques/T1568/)                     | The attacker changed dnszonetransfer\[.\]com IP resolution to a benign IP                                                            |                                                                                    |

*Table 4. Timeline of activities, attack techniques and detections involved in the Popping Eagle attack.*

## Searching for Related IoCs

After we finished analyzing the malware's behavior, we set our goals to find related samples by the same actor.

### Hypothesis

Observing the facts:

* The first stage downloads and loads the second stage DLL and invokes the function popo from it. Both DLLs export the popo function.
* The second stage unnecessarily proxies the DLL.

Also, both of the DLLs contain possible indicator strings for a version or a development ready status

* CoL\_**Final\_Lib**.dll
* Eagle**2.5-Client-Dll**

This data can sum up to a possible modus operandi of an adversary:

* Create and use multiple small-effort tools written using known public projects and libraries.
* It is feasible to assume that they have a framework to easily create proxy DLLs with a single export function (in our case: popo).
* Developer(s) knowledgeable in several programming languages (C++, Go, Python).

### Hunting and Searching Methodology

At first we searched for the initial indicators (hash, domain, IP, URL) on AutoFocus and common public threat intel platforms, but nothing new was found.

Additionally, while analyzing the malware, we created generic "hunting" and specific "adversary" Yara rules to search for related samples. The generic rules yielded surprisingly good results by finding additional "Go socks" samples unrelated to this actor, most of which are malware.

The specific adversary rules did not find any additional samples.

## Conclusion

As seen in the case above, attackers are using open-source code to develop custom malware that's designed to evade security detection. In order to combat more advanced actors, we must leverage more sophisticated detection techniques. Hunting for anomalous actions done by signed applications has proven itself successful in finding previously unknown attacks and "dormant" backdoors.

Due to the malware's apparently being tailor-made for the attacked network and the use of common attack tools, we couldn't attribute it to a specific actor.

Palo Alto Networks customers are protected from this kind of attack by the following:

1. [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)'s Global Analytics BIOC alerts, implementing, among many things, the statistical techniques described earlier.
   ![Cortex XDR Analytics BIOC - globally uncommon root domain from a signed process; Cortex XDR Analytics BIOC - Globally uncommon injection from a signed process; Cortex XDR Analytics BIOC - Globally uncommon image load from a signed process](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/Table-5.png) Table 5. Cortex XDR Global Analytics BIOC alerts that can help protect against Popping Eagle.

2. Cortex XDR Agent Behavioral Threat Protection blocks the DLL hijacking attack on the vulnerable application, preventing future malware from using the same loading method.

3. [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire), a cloud-delivered security subscription for the Next-Generation Firewall, and Cortex XDR identify and block all IoCs mentioned as well as all future IoCs identified by the Yara rules

## Appendix

### Indicators of Compromise

|------------------------------------------------------------------|------------------------|
| **SHA256**                                                       | **File Name**          |
| e5e89d8db12c7dacddff5c2a76b1f3b52c955c2e86af8f0b3e36c8a5d954b5e8 | uxtheme.dll            |
| 95676c8eeaab93396597e05bb4df3ff8cc5780ad166e4ee54484387b97f381df | uxtheme.dll            |
| 59d12f26cbc3e49e28be13f0306f5a9b1a9fd62909df706e58768d2f0ccca189 | uxtheme.dll            |
| 0dc8f17b053d9bfab45aed21340a1f85325f79e0925caf21b9eaf9fbdc34a47a | ClickRuntime-amd86.dll |

|-------------------------|
| **Domain**              |
| dnszonetransfer\[.\]com |
| reporterror\[.\]net     |

|------------------|
| **IP**           |
| 51.38.89\[.\]53  |
| 51.75.57\[.\]245 |

|-------------------------------------------------------------|
| **URL**                                                     |
| hxxps\[:\]//dnszonetransfer\[.\]com/Protocol/extensions.php |

|-----------------------------------------------------------------------------------------------------------|
| **User agent**                                                                                            |
| Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36 |

### Hunting Yara Rules

#### Suspicious Go Executables

rule general\_win\_golang\_socks { meta: author = "paloaltonetworks" date = "2022-03-13" description = "potentially unwanted GO application with proxy communication capabilities" strings: $go\_name\_1 = "main.go" nocase ascii // default go name for the "func main(){...}" in "package main" $go\_name\_2 = "eagle" nocase ascii $go\_name\_3 = "popo" nocase ascii $go\_name\_4 = "-Client-Dll/" nocase ascii $go\_pkg\_1 = "github.com/armon/go-socks5" nocase wide ascii $go\_pkg\_2 = "github.com/hashicorp/yamux" nocase wide ascii $go\_pkg\_3 = "github.com/fatedier/frp/vendor" wide ascii $go\_pkg\_4 = "github.com/rofl0r/rocksocks5" wide ascii condition: uint16(0) == 0x5a4d and filesize \< 7MB and ( 1 of ($go\_name\_\*) and 2 of ($go\_pkg\_\*) ) } rule general\_win\_dll\_golang\_socks { meta: author = "paloaltonetworks" date = "2022-03-13" description = "Highly suspicious GO DLL with proxy communication capabilities" condition: general\_win\_golang\_socks and (pe.characteristics \& pe.DLL) and pe.is\_dll() }

|----------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 | rule general\_win\_golang\_socks { meta: author = "paloaltonetworks" date = "2022-03-13" description = "potentially unwanted GO application with proxy communication capabilities" strings: $go\_name\_1 = "main.go" nocase ascii // default go name for the "func main(){...}" in "package main" $go\_name\_2 = "eagle" nocase ascii $go\_name\_3 = "popo" nocase ascii $go\_name\_4 = "-Client-Dll/" nocase ascii $go\_pkg\_1 = "github.com/armon/go-socks5" nocase wide ascii $go\_pkg\_2 = "github.com/hashicorp/yamux" nocase wide ascii $go\_pkg\_3 = "github.com/fatedier/frp/vendor" wide ascii $go\_pkg\_4 = "github.com/rofl0r/rocksocks5" wide ascii condition: uint16(0) == 0x5a4d and filesize \< 7MB and ( 1 of ($go\_name\_\*) and 2 of ($go\_pkg\_\*) ) } rule general\_win\_dll\_golang\_socks { meta: author = "paloaltonetworks" date = "2022-03-13" description = "Highly suspicious GO DLL with proxy communication capabilities" condition: general\_win\_golang\_socks and (pe.characteristics \& pe.DLL) and pe.is\_dll() } |

#### Possible Tools From This Adversary

rule general\_win\_faked\_dlls\_export\_popo { meta: author = "paloaltonetworks" date = "2022-03-13" description = "Detects DLL files with an export function named 'popo'" hash0 = "e5e89d8db12c7dacddff5c2a76b1f3b52c955c2e86af8f0b3e36c8a5d954b5e8" // fake uxtheme.dll hash1 = "95676c8eeaab93396597e05bb4df3ff8cc5780ad166e4ee54484387b97f381df" // fake uxtheme.dll hash2 = "59d12f26cbc3e49e28be13f0306f5a9b1a9fd62909df706e58768d2f0ccca189" // fake uxtheme.dll hash3 = "0dc8f17b053d9bfab45aed21340a1f85325f79e0925caf21b9eaf9fbdc34a47a" // ClickRuntime-amd86.dll condition: (pe.characteristics \& pe.DLL) and pe.is\_dll() and filesize \< 20MB and ( pe.exports("popo") or pe.exports("Popo") ) }

|-------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | rule general\_win\_faked\_dlls\_export\_popo { meta: author = "paloaltonetworks" date = "2022-03-13" description = "Detects DLL files with an export function named 'popo'" hash0 = "e5e89d8db12c7dacddff5c2a76b1f3b52c955c2e86af8f0b3e36c8a5d954b5e8" // fake uxtheme.dll hash1 = "95676c8eeaab93396597e05bb4df3ff8cc5780ad166e4ee54484387b97f381df" // fake uxtheme.dll hash2 = "59d12f26cbc3e49e28be13f0306f5a9b1a9fd62909df706e58768d2f0ccca189" // fake uxtheme.dll hash3 = "0dc8f17b053d9bfab45aed21340a1f85325f79e0925caf21b9eaf9fbdc34a47a" // ClickRuntime-amd86.dll condition: (pe.characteristics \& pe.DLL) and pe.is\_dll() and filesize \< 20MB and ( pe.exports("popo") or pe.exports("Popo") ) } |

Back to top

### Tags

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")
* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")
* [DLL](https://unit42.paloaltonetworks.com/tag/dll/ "DLL")
* [DLL Sideloading](https://unit42.paloaltonetworks.com/tag/dll-sideloading/ "DLL Sideloading")
* [Going Eagle](https://unit42.paloaltonetworks.com/tag/going-eagle/ "Going Eagle")
* [Popping Eagle](https://unit42.paloaltonetworks.com/tag/popping-eagle/ "Popping Eagle")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Brief: CVE-2022-30190 -- MSDT Code Execution Vulnerability](https://unit42.paloaltonetworks.com/cve-2022-30190-msdt-code-execution-vulnerability/ "Threat Brief: CVE-2022-30190 – MSDT Code Execution Vulnerability")

### Table of Contents

* 

### Related Articles

* [Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "article - table of contents")
* [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "article - table of contents")
* [TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development](https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
