[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Threat Assessment: North Korean Threat Groups

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 13 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Code to Cloud Platform icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Code to Cloud Platform](https://unit42.paloaltonetworks.com/product-category/code-to-cloud-platform/ "Code to Cloud Platform")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Prisma Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Prisma Cloud](https://unit42.paloaltonetworks.com/product-category/prisma-cloud/ "Prisma Cloud")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 9, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/)
  * [Alluring Pisces](https://unit42.paloaltonetworks.com/tag/alluring-pisces/)
  * [Andariel](https://unit42.paloaltonetworks.com/tag/andariel/)
  * [Bluenoroff](https://unit42.paloaltonetworks.com/tag/bluenoroff/)
  * [Citrine Sleet](https://unit42.paloaltonetworks.com/tag/citrine-sleet/)
  * [CollectionRAT](https://unit42.paloaltonetworks.com/tag/collectionrat/)
  * [Comebacker](https://unit42.paloaltonetworks.com/tag/comebacker/)
  * [Finance](https://unit42.paloaltonetworks.com/tag/finance/)
  * [Fullhouse](https://unit42.paloaltonetworks.com/tag/fullhouse/)
  * [Gleaming Pisces](https://unit42.paloaltonetworks.com/tag/gleaming-pisces/)
  * [Government](https://unit42.paloaltonetworks.com/tag/government/)
  * [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/)
  * [KANDYKORN](https://unit42.paloaltonetworks.com/tag/kandykorn/)
  * [Kimsuky](https://unit42.paloaltonetworks.com/tag/kimsuky/)
  * [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/)
  * [ObjCShellz](https://unit42.paloaltonetworks.com/tag/objcshellz/)
  * [OdicLoader](https://unit42.paloaltonetworks.com/tag/odicloader/)
  * [PondRAT](https://unit42.paloaltonetworks.com/tag/pondrat/)
  * [POOLRAT](https://unit42.paloaltonetworks.com/tag/poolrat/)
  * [Remote Access Trojan](https://unit42.paloaltonetworks.com/tag/remote-access-trojan/)
  * [RustBucket](https://unit42.paloaltonetworks.com/tag/rustbucket/)
  * [Selective Pisces](https://unit42.paloaltonetworks.com/tag/selective-pisces/)
  * [Slow Pisces](https://unit42.paloaltonetworks.com/tag/slow-pisces/)
  * [SmoothOperator](https://unit42.paloaltonetworks.com/tag/smoothoperator/)
  * [Sparkling Pisces](https://unit42.paloaltonetworks.com/tag/sparkling-pisces/)
  * [TEMP.Hermit](https://unit42.paloaltonetworks.com/tag/temp-hermit/)
  * [TraderTraitor](https://unit42.paloaltonetworks.com/tag/tradertraitor/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Threat%20Assessment:%20North%20Korean%20Threat%20Groups&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-north-korean-threat-groups-2024%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-north-korean-threat-groups-2024%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-north-korean-threat-groups-2024%2F&title=Threat%20Assessment:%20North%20Korean%20Threat%20Groups "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-north-korean-threat-groups-2024%2F&text=Threat%20Assessment:%20North%20Korean%20Threat%20Groups "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-north-korean-threat-groups-2024%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Threat%20Assessment:%20North%20Korean%20Threat%20Groups%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fthreat-assessment-north-korean-threat-groups-2024%2F "Share in Mastodon")

## **Executive Summary**

[Lazarus](https://attack.mitre.org/groups/G0032/) has been used in public reporting as an umbrella term for threat actors from the Democratic People's Republic of Korea (DPRK), commonly referred to as North Korea. However, many of these threat actors can be [classified into different groups under the Reconnaissance General Bureau (RGB)](https://cloud.google.com/blog/topics/threat-intelligence/mapping-dprk-groups-to-government/) of the Korean People's Army.

Over the years, the RGB has revealed at least six threat groups that we designate as:

* Alluring Pisces ([Bluenoroff \[PDF\]](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07180244/Lazarus_Under_The_Hood_PDF_final.pdf))
* Gleaming Pisces ([Citrine Sleet](https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/))
* Jumpy Pisces ([Andariel](https://www.justice.gov/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals))
* Selective Pisces ([TEMP.Hermit \[PDF\]](https://www.hhs.gov/sites/default/files/dprk-cyber-espionage.pdf))
* Slow Pisces ([TraderTraitor](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a))
* Sparkling Pisces ([Kimsuky](https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a))

These groups develop their own distinct set of malware that they have used to facilitate diverse types of operations, including:

* Intelligence gathering missions
* Asset recruitment
* Destructive attacks
* Financial crime

North Korean threat groups are a focus area in the [2024 MITRE ATT\&CK enterprise evaluation](https://attackevals.mitre-engenuity.org/enterprise/er6/).

This threat assessment reviews the different North Korean threat groups under the RGB that we track. We'll also review 10 malware families observed in recent attacks carried out by North Korean threat groups. This includes malware for all three major operating systems: Windows, macOS and Linux.

In addition to describing each type of malware's functionality and history, we will present their execution through the lens of Palo Alto Networks Cortex XDR. We will show how Cortex protects against known North Korean malware.

Palo Alto Networks customers receive better protections from the North Korean threat groups' arsenal and the techniques discussed in this blog through [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR). Cortex XDR provides a multi-layer defense that includes behavioral threat protection and exploit protection.

Our [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire) cloud-delivered malware analysis service accurately identifies samples related to these North Korean groups as malicious. [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions), including [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security), identify domains associated with this group as malicious. Prisma Cloud leverages the power of XSIAM through the [Cloud Security Agent (CSA)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Pairing-Prisma-Cloud-Compute-with-Cortex-XDR) to better protect against novel malware.

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**North Korea**](https://unit42.paloaltonetworks.com/tag/north-korea/), **[RATs](https://unit42.paloaltonetworks.com/tag/remote-access-trojan/), [Malware](https://unit42.paloaltonetworks.com/category/malware/)** |
|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## **North Korean Threat Groups Under the RGB**

North Korean threat group activity is often [referred to as Lazarus or the Lazarus Group](https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and) in public reports. However, most of this activity is [reportedly conducted by groups under the RGB](https://cloud.google.com/blog/topics/threat-intelligence/mapping-dprk-groups-to-government/), an organization that falls under the General Staff Bureau of the DPRK Korean People's Army.

These groups support the North Korean government through a combination of espionage, financial gain and geopolitical disruption. Some of the significant operations executed by these groups across the years include:

* The [Sony Pictures Hack in 2014 \[PDF\]](https://www.secureops.com/wp-content/uploads/2021/06/Sony-Breach-Analysis-v4.pdf)
* The [WannaCry ransomware attacks in 2017](https://www.csoonline.com/article/563017/wannacry-explained-a-perfect-ransomware-storm.html)
* [Operation Dream Job \[PDF\]](https://www.clearskysec.com/wp-content/uploads/2020/08/Dream-Job-Campaign.pdf)
* Numerous [cryptocurrency exchange attacks](https://www.elliptic.co/blog/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics)

These groups have been reportedly [active as early as 2007 \[PDF\]](https://www.usna.edu/CyberCenter/_files/documents/Operation-Blockbuster-Report.pdf). Activity under the RGB can be categorized into at least six threat groups:

* Alluring Pisces (aka [APT38 \[PDF\]](https://services.google.com/fh/files/misc/apt38-un-usual-suspects.pdf), [Bluenoroff](https://apt.securelist.com/apt/bluenoroff), [Sapphire Sleet](https://x.com/MsftSecIntel/status/1722316021841764414)): This group has targeted financial institutions, cryptocurrency businesses and ATMs. It has also conducted significant cyber heists.
* Gleaming Pisces (aka [Citrine Sleet](https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/)): This group performed attacks targeting the cryptocurrency industry and is known for its association with the [AppleJeus](https://www.cisa.gov/news-events/analysis-reports/ar21-048e) campaign.
* Jumpy Pisces (aka [Andariel](https://www.justice.gov/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals), [Hidden Cobra](https://www.justice.gov/opa/pr/three-north-korean-military-hackers-indicted-wide-ranging-scheme-commit-cyberattacks-and), [Onyx Sleet](https://www.microsoft.com/en-us/security/blog/2024/07/25/onyx-sleet-uses-array-of-malware-to-gather-intelligence-for-north-korea/)): This group has primarily conducted cyberespionage, but it has also conducted ransomware activity.
* Selective Pisces (aka [Diamond Sleet](https://www.microsoft.com/en-us/security/security-insider/diamond-sleet), [TEMP.Hermit \[PDF\]](https://www.mandiant.com/sites/default/files/2021-09/rpt-apt38-2018-web_v5-1.pdf), [ZINC](https://www.microsoft.com/en-us/security/blog/2022/09/29/zinc-weaponizing-open-source-software/)): This group has targeted media, defense and IT organizations. It focuses on espionage, financial gain and network destruction.
* Slow Pisces (aka [Jade Sleet](https://github.blog/security/vulnerability-research/security-alert-social-engineering-campaign-targets-technology-industry-employees/), [UNC4899](https://cloud.google.com/blog/topics/threat-intelligence/north-korea-supply-chain/)): This group has targeted blockchain and cryptocurrency companies. It was also involved in a supply chain attack targeting a U.S.-based software platform and is known for distributing a series of malicious applications called [TraderTraitor](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a).
* Sparkling Pisces (aka [APT43 \[PDF\]](https://services.google.com/fh/files/misc/apt43-report-en.pdf), [Emerald Sleet](https://www.microsoft.com/en-us/security/security-insider/intelligence-reports/digital-threats-from-east-asia-increase-in-breadth-and-effectiveness), [Kimsuky](https://thehackernews.com/2024/03/n-korea-linked-kimsuky-shifts-to.html), [THALLIUM](https://blogs.microsoft.com/on-the-issues/2019/12/30/microsoft-court-action-against-nation-state-cybercrime/)): This group conducts intelligence collection and has used cybercrime to fund espionage.

These groups have evolved over the years, and we often find overlaps in the tactics, techniques and tools. Figure 1 shows a simplified organizational chart for these groups under the RGB.
![An organizational chart titled 'Democratic People’s Republic of Korea (DPRK, also called North Korea): Threat Actors under the Reconnaissance General Bureau.' The chart illustrates the connection between the Reconnaissance General Bureau and various cyber threat groups such as Alluring Pisces, Gleaming Pisces, Jumpy Pisces, Selective Pisces, Slow Pisces, and Sparkling Pisces, each with associated aliases.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-564181-136656-1.png) Figure 1. Organizational chart for North Korean threat groups under the RGB, showing both Unit 42 names and other akas.

Figure 1 does not include all North Korean state-sponsored threat actors, only those under the RGB. Other threat groups that operate outside of the RGB also conduct malicious cyber activity for North Korea.

These North Korean threat groups use a wide arsenal of tools that span across the Windows, Linux and macOS platforms.

## **MITRE ATT\&CK Enterprise Evaluation**

MITRE chose North Korean threat groups as one of the focus areas for this [year's MITRE ATT\&CK enterprise evaluation](https://attackevals.mitre-engenuity.org/enterprise/er6/). In this threat assessment, we focus on North Korean threat groups due to their worldwide reach and the impact of their operation on multiple industries and across multiple regions.

We chose the top 10 most recently active types of malware from North Korean threat groups. This threat assessment includes a brief technical analysis for each type of malware, and it shows how Cortex XDR detects and prevents these threats.

## **Recent North Korean Malware Arsenal Analysis**

### MacOS Malware

#### **RustBucket**

**Malware type:** Backdoor

**Group affiliation:** Alluring Pisces

**First seen:** 2023

**OS type:** macOS

**Description:**

RustBucket is macOS malware [first reported in 2023](https://thehackernews.com/2023/07/beware-new-rustbucket-malware-variant.html). Since then, multiple variants of the malware have been observed in the wild. Most RustBucket infections are composed of three stages.

The first stage usually is an [AppleScript](https://developer.apple.com/library/archive/documentation/AppleScript/Conceptual/AppleScriptLangGuide/introduction/ASLR_intro.html) file contained inside an application or inside a ZIP archive masquerading as a legitimate file. This AppleScript file is responsible for retrieving the second stage downloader.

The second stage downloader masquerades as a PDF viewer application. Some variants of this second stage downloader are written in [Swift](https://developer.apple.com/swift/), while others are written in [Objective-C](https://developer.apple.com/library/archive/documentation/Cocoa/Conceptual/ProgrammingWithObjectiveC/Introduction/Introduction.html).

The third stage is the final payload retrieved by the second stage downloader. Figure 2 shows an alert from Cortex XDR that blocks a RustBucket sample from downloading the next stage of malware.
![A screenshot showing a user interface with two panels in Cortex XDR. The left panel displays technical information. The right panel presents the alert information. There is an overlaid screenshot of a section of code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-568322-136656-2-1920x469.png) Figure 2. Cortex XDR alert on preventing RustBucket download activity.

The third stage payloads are [Mach-O](https://developer.apple.com/library/archive/documentation/Performance/Conceptual/CodeFootprint/Articles/MachOOverview.html) binaries written in Rust, hence the name RustBucket. Later variants of stage three employ persistence via a [LaunchAgent](https://www.linkedin.com/pulse/maximizing-efficiency-macos-how-use-launchagents-run-scheduled/), a feature that did not exist in older variants. Stage three has two main commands:

* Download and execute a file
* Self-terminate the malware

#### **KANDYKORN**

**Malware type:** Backdoor

**Group affiliation:** Alluring Pisces

**First seen:** 2023

**OS type:** macOS

**Description:**

First discovered in 2023, KANDYKORN is the payload of a five-stage infection chain targeting macOS systems. Known infections of KANDYKORN start with social engineering, tricking the victim into downloading a malicious ZIP archive containing a malicious Python script. If the victim executes the Python file, it downloads stage two of the infection, which is a second Python script that is saved into a folder named \_log.

The second stage of the infection involves two additional Python scripts. The first Python script saved to the \_log directory downloads another script saved to the /Users/Shared/ directory, which in turn downloads a stage three file, saving it as /Users/shared/.sld.

Stage three of the infection is a downloader and loader dubbed SUGARLOADER. For persistence, SUGARLOADER saves itself as /Users/shared/.log.

Upon execution, SUGARLOADER checks for the existence of a configuration file at /Library/Caches/com.apple.safari.ck. If that configuration file is missing, SUGARLOADER downloads it using a default IP address provided in the command line.

The configuration file at /Library/Caches/com.apple.safari.ck contains the location to download the next stage from. In Figure 3, we see part of a Cortex XDR alert that reveals the installation of this configuration file.
![Cortex XDR logs. Screenshot showing two rows in a table. The first row is File Create and the second is File Write.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-571611-136656-3-786x231.png) Figure 3. Section of a Cortex XDR alert revealing SUGARLOADER installing its configuration file.

Cortex XDR detects SUGARLOADER installing its configuration file and alerts on staged malware activity as shown below in Figure 4.
![Security alert from Cortex XDR Agent indicating Staged Malware Activity with reference number, related to Sugarloader configuration file installation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-574905-136656-4-786x251.png) Figure 4. Staged malware activity alert in Cortex XDR for SUGARLOADER.

After installing its configuration file, SUGARLOADER downloads a malware binary for HLOADER.

HLOADER functions as the persistence mechanism for KANDYKORN. HLOADER attempts to masquerade as [Discord](https://discord.com/) by replacing the legitimate application and renaming itself Discord. Figure 5 shows the Cortex XDR preventing this name change by HLOADER.
![Graphic showing a high severity alert for malware in Cortex XDR. The alert action is 'Prevented (Blocked)' and is represented by a pink circle and a shield inside a triangle warning symbol.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-577962-136656-5.png) Figure 5. Alert from Cortex XDR preventing HLOADER from naming itself Discord for persistence.

If the legitimate Discord application already exists on the victim's host, HLOADER will rename the legitimate Discord file to a different name, so it can take over the Discord file name. Figure 6 shows two actions from a Cortex XDR alert where HLOADER renamed the legitimate Discord app to a new name (the bottom file event). It then renamed itself to take the place of the legitimate Discord file (the top file event).
![Screenshot of a file event log from Cortex XDR showing details of file events, including file name, description, and associated categories.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-581649-136656-6.png) Figure 6. File events from a Cortex XDR alert showing HLOADER renaming itself and the legitimate Discord file.

Because Discord usually boots with the operating system, if this file renaming is successful, HLOADER will run instead of the legitimate Discord application upon booting or rebooting. If Discord is already installed on the victim's system, HLOADER will also execute the newly renamed legitimate Discord application when booting or rebooting.

In the final stage of the attack, SUGARLOADER downloads KANDYKORN and loads it into memory by using [reflective loading](https://attack.mitre.org/techniques/T1620/). KANDYKORN is the final payload and possesses several capabilities, including information gathering, data exfiltration and arbitrary command execution.

#### **SmoothOperator**

\*\*Malware type:\*\*Backdoor

\*\*Group affiliation:\*\*Undetermined, under RGB

\*\*First seen:\*\*2023

\*\*OS type:\*\*macOS

**Description:**

In the beginning of 2023, multiple vendors discovered Trojanized macOS installers for the legitimate 3CX client application known as [3CXDesktopApp](https://www.3cx.com/user-manual/installation-windows/). These Trojanized installers contained multi-staged malware called [SmoothOperator](https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/).

SmoothOperator can execute payloads and extract data related to 3CX from infected hosts. It is written in Objective-C and targets 64-bit Intel-based macOS users.

The Trojanized component of SmoothOperator inside the 3CXDesktopApp application is a module called libffmpeg.dylib, which is a legitimate dependency that appears to have been altered or tampered with by the threat actors. The main purpose of this tampered libffmpeg.dylib file is to collect the infected device's environment information and to deliver additional payloads.

When downloading an additional payload, the module writes the payload into a file named UpdateAgent and executes it. Below, Figure 7 shows disassembled code from a tampered libffmpeg.dylib file related to saving the follow-up payload as UpdateAgent.
![Screenshot of computer code in an editor with syntax highlighting, featuring functions related to file operations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-584383-136656-7.png) Figure 7. Code snippet from libffmpeg.dylib showing how it writes data and changes permission for the UpdateAgent file.

UpdateAgent collects the victim's 3CX account information, then it removes itself. The relatively limited capabilities of UpdateAgent likely prevent it from deploying a wide variety of payloads, and we have only noted SmoothOperator as the final payload from this infection chain. Figure 8 shows a Cortex XDR alert detecting a 3CX desktop app for SmoothOperator.
![Screenshot showing a security alert titled 'Staged Malware Activity - 1698486237' with a source indicated as 'XDR Agent.' It details a Trojanized version of the 3CX Desktop App. Icons for security, stars for rating, investigative tools, and settings are visible.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-587585-136656-8.png) Figure 8. Alert from Cortex XDR detecting a Trojanized version of the 3CX desktop app.

#### **ObjCShellz**

**Malware type:** Backdoor

**Group affiliation:** Alluring Pisces

**First seen:** 2023

**OS type:** macOS

**Description:**

ObjCShellz is a relatively simple backdoor [Jamf Threat Labs discovered and named in November 2023](https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/). It serves as a remote shell and allows an attacker to execute arbitrary commands. Attackers reportedly deliver ObjCShellz as a second stage payload to an already compromised system.

Like other macOS malware, ObjCShellz is written in Objective-C. Jamf Threat Labs reported attackers using it as a part of the RustBucket campaign. Figure 9 below shows a Cortex XDR alert detecting a sample of ObjCShellz.
![A security alert interface in Cortex XDR showing a high severity malware activity detected. The central pink button labeled with 'ObjCShell' has the number 1, indicating one issue reported, and to the right, a smaller blue button labeled 'sh'.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-590223-136656-9.png) Figure 9. Cortex XDR alert detecting ObjCShellz activity.

#### **Fullhouse**

**Malware type:** Backdoor

**Group affiliation:** Slow Pisces

**First seen:** 2023

**OS type:** macOS

**Description:**

Reported by Mandiant in 2023, Fullhouse is an HTTP backdoor written in C/C++, and it was seen as a [part of a supply chain attack](https://cloud.google.com/blog/topics/threat-intelligence/north-korea-supply-chain/https://cloud.google.com/blog/topics/threat-intelligence/north-korea-supply-chain/). Delivered as a first-stage backdoor, Fullhouse supports the execution of arbitrary commands and in turn delivers other second-stage backdoors.

Disassembled code from a Fullhouse sample reveals some unimplemented functions, such as MyFunctionStealthCodeArea, shown in Figure 10. Parts of this code also retrieve the shell [environment variable](https://en.wikipedia.org/wiki/Environment_variable), noted in the line containing getenv("SHELL").
![Screenshot of computer code in a text editor with highlighted syntax. Specific functions like MyFunctionStealthCodeArea are displayed, along with system command execution for launching a shell.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-593634-136656-10.png) Figure 10. Fullhouse code snippet showing unimplemented functions.

Below, Figure 11 shows a Cortex XDR alert blocking Fullhouse activity.
![Alert message from Cortex XDR reporting a blocked malicious activity attempt, with details including OS version, file path, and source process information.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-597739-136656-11.png) Figure 11. Fullhouse malware prevented by Cortex XDR.

### Multi-Platform Malware

#### **POOLRAT**

**Malware type:** Backdoor

**Group affiliation:** Gleaming Pisces

**First seen:** 2021

**OS type:** macOS and Linux

**Description:**

POOLRAT is a macOS and Linux backdoor [first reported by CISA in 2021](https://www.cisa.gov/news-events/analysis-reports/ar21-048e) as a file named prtspool, likely the final payload in an AppleJeus attack. Mandiant named this malware family POOLRAT and identified a newer sample in [its analysis of the 2023 3CX supply chain attack](https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise/).

Cortex XDR detects and blocks POOLRAT as shown below in Figure 12.
![Interface of Cortex XDR with a warning icon triangle. Details, including the alert name "Category Blocked" and description "Malware," show that 'prtspool' was blocked. Various tabs like 'XDR Agent Source,' 'WildFire,' and others are visible.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-601104-136656-12.png) Figure 12. Alert showing Cortex XDR detecting and blocking a POOLRAT sample.

#### **PondRAT**

\*\*Malware type:\*\*Remote Administration Tool (RAT)

\*\*Group affiliation:\*\*Gleaming Pisces

\*\*First seen:\*\*2021

\*\*OS type:\*\*macOS and Linux

**Description:**

[PondRAT is the name we use](https://unit42.paloaltonetworks.com/gleaming-pisces-applejeus-poolrat-and-pondrat/) for a RAT family with variants for Linux and macOS. CISA reported the earliest sample we identify as PondRAT as part of a cryptocurrency-themed Kupay Wallet macOS malware package during an [AppleJeus campaign](https://www.cisa.gov/news-events/analysis-reports/ar21-048d) in 2021.

Analysis of malicious packages uploaded to the Python Package Index (PyPI) in February 2024 revealed another sample we identify as PondRAT. Since it first appeared in 2021, we have identified seven macOS or Linux samples as PondRAT. The Indicators of Compromise section of this article has further details.

Figure 13 depicts an alert from Cortex XDR detecting and blocking a PoolRAT sample.
![Alert details interface in Cortex XDR showing the prevention of malware threat 'PondRAT'. The visual includes a round pink icon with a triangular warning sign above it. Categories list out other identifying information.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-604252-136656-13.png) Figure 13. Cortex XDR Agent alerting to a blocked PondRAT Linux sample.

### Linux Malware

#### **OdicLoader**

**Malware type:** Downloader

**Group affiliation:** Selective Pisces

**First seen:** 2023

**OS type:** Linux

**Description:**

OdicLoader is an ELF downloader that masquerades as a PDF file by using the [U+2024 Unicode character](https://www.compart.com/en/unicode/U+2024) (hexadecimal 0xE2 0x80 0xA4) instead of a period (hexadecimal 0x2e) with a pdf file extension. [This technique](https://attack.mitre.org/techniques/T1204/002/) can deceive the file manager in a graphical Linux environment, causing the fake PDF file to execute as an ELF when double-clicked instead of opening with a PDF viewer.

When executed, OdicLoader opens a decoy PDF with the system's default PDF viewer using [xdg-open](https://linux.die.net/man/1/xdg-open), then it downloads and executes the next stage payload.

ESET reported OdicLoader as part of a North Korean threat campaign named [Operation DreamJob](https://www.welivesecurity.com/2023/04/20/linux-malware-strengthens-links-lazarus-3cx-supply-chain-attack/). Figure 14 below shows a Cortex XDR alert detecting OdicLoader.
![Screenshot of a Cortex XDR interface showing details of a potential malware file named 'odicloader.elf' with a visual warning symbol in pink and light grey colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-607373-136656-14.png) Figure 14. Cortex XDR alert on OdicLoader execution.

### Windows Malware

#### Comebacker

**Malware type:** Backdoor and downloader

**Group affiliation:** Selective Pisces

**First seen:** 2020

**OS type:** Windows

**Description:**

Attackers originally used Comebacker malware as part of a [campaign targeting security researchers in 2020](https://www.microsoft.com/en-us/security/blog/2021/01/28/zinc-attacks-against-security-researchers/). Like PondRAT, attackers have also distributed Comebacker [as malicious packages to PyPI](https://blogs.jpcert.or.jp/en/2024/02/lazarus_pypi.html).

Comebacker communicates with its command and control (C2) server by sending randomly generated parameter names through HTTP POST requests. During the initial connection, the client exchanges keys with the server and sends the current local time. The server then responds with multiple values, including the encrypted payload, execution instructions and an MD5 hash to verify the authenticity of the payload.

Figure 15 shows a prevention alert from Cortex XDR blocking a Comebacker sample.
![Alert window titled 'Cortex XDR Prevention Alert' stating that a malicious activity has been blocked. The alert is linked to an application called 'RunDll32' from Microsoft Corporation. Buttons for 'Hide details' and 'OK' are present, and the window includes additional details about the application and prevention description.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-610580-136656-15.png) Figure 15. Alert from Cortex XDR blocking Comebacker malware.

#### **CollectionRAT**

**Malware type:** Remote Administration Tool (RAT)

**Group affiliation:** Jumpy Pisces

**First seen:** 2023

**OS type:** Windows

**Description:**

CollectionRAT is a Windows-based RAT first announced by a [Cisco Talos report in 2023](https://blog.talosintelligence.com/lazarus-collectionrat/) that lists samples dating as early as 2021. This malware communicates with its C2 server over HTTP and uses the Microsoft Foundation Class (MFC) library as a wrapper to decrypt its malicious code.

When executed on a vulnerable host, CollectionRAT first collects system information to fingerprint the victim's environment and sends it to the C2 server. The server responds with commands for the malware that provide the attacker a wide range of capabilities.

These capabilities include:

* Manipulating processes and files
* Executing arbitrary commands
* Exfiltrating data
* Downloading and executing additional payloads
* Removing itself from an infected host upon instruction from the C2 server

Figure 16 below shows Cortex XDR blocking a CollectionRAT sample.
![Alert window titled "Cortex XDR Prevention Alert" displays a message that Cortex XDR has blocked a malicious activity. Buttons for "Show details" and "OK" are provided at the bottom. There is a reminder to contact the help desk for questions or additional information.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/09/word-image-613803-136656-16.png) Figure 16. Cortex XDR blocking a CollectionRAT sample.

## **Conclusion**

North Korean groups have been documented targeting various sectors worldwide, using a wide range of custom-built malware. In this article, we examined the top 10 malware families from North Korean threat groups and demonstrated how Palo Alto Networks Cortex XDR detects and prevents these threats.

Due to the severity of the risks posed by North Korean threat actors, we encourage organizations to prioritize comprehensive security strategies and invest in multi-layer security measurements. This helps safeguard against the growing threat from these types of state-sponsored threat groups.

### Protections and Mitigations

Palo Alto Networks customers receive better protections against the arsenal of malware related to the DPRK threat groups described in this article.

We have implemented prevention and detection alerts for each type of malware: RustBucket, KANDYKORN, SmoothOperator, ObjCShellz, Fullhouse, POOLRAT, PondRAT, OdicLoader, Comebacker and CollectionRAT.

For Palo Alto Networks customers, our products and services provide the following coverage associated with this group include [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM.](https://docs-cortex.paloaltonetworks.com/p/XSIAM) [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) detects user and credential-based threats by analyzing user activity from multiple data sources including the following:

* Endpoints
* Network firewalls
* Active Directory
* Identity and access management solutions
* Cloud workloads

Cortex XDR, Prisma Cloud and XSIAM build behavioral profiles of user activity over time with machine learning. By comparing new activity to past activity, peer activity and the expected behavior of the entity, we can detect anomalous activity indicative of credential-based attacks. Prisma Cloud leverages the power of XSIAM through the [Cloud Security Agent (CSA)](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Pairing-Prisma-Cloud-Compute-with-Cortex-XDR) ensuring that your cloud endpoints are better protected from novel malware.

This combination of services also offers the following protections related to the attacks discussed in this post:

* Prevents the execution of known malicious malware and also prevents the execution of unknown malware using [Behavioral Threat Protection](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) machine learning based on the Local Analysis module
* Protects against credential gathering tools and techniques using the new Credential Gathering Protection available from Cortex XDR
* Protects from threat actors dropping and executing commands from web shells using Anti-Webshell Protection, newly released in Cortex XDR
* Protects against exploitation of different vulnerabilities including ProxyShell and ProxyLogon using the Anti-Exploitation modules as well as Behavioral Threat Protection
* Cortex XDR Pro [detects post exploitation activity](https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/analytics-alerts-by-required-data-source), including credential-based attacks, with behavioral analytics

[Advanced WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) cloud-delivered malware analysis service accurately identifies the known samples as malicious. [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-basics/how-url-filtering-works) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security/administration/about-dns-security) identify known URLs and domains associated with this activity as malicious.

If you think you might have been impacted or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Additional Resources

* [Gleaming Pisces Poisoned Python Packages Campaign Delivers PondRAT Linux and MacOS Backdoors](https://unit42.paloaltonetworks.com/gleaming-pisces-applejeus-poolrat-and-pondrat/) -- Unit 42, Palo Alto Networks

## **Indicators of Compromise**

### RustBucket

SHA256 hashes:

* c9a7b42c7b29ca948160f95f017e9e9ae781f3b981ecf6edbac943e52c63ffc8
* c7f4aa77be7f7afe9d0665d3e705dbf7794bc479bb9c44488c7bf4169f8d14fe

### SUGARLOADER

SHA256 hash:

* 3ea2ead8f3cec030906dcbffe3efd5c5d77d5d375d4a54cca03bfe8a6cb59940

IP address:

* 23\.254.226\[.\]90

### HLOADER

SHA256 hashes:

* 2360a69e5fd7217e977123c81d3dbb60bf4763a9dae6949bc1900234f7762df1
* 689cfaa9319f3f7529a31472ecf6b2e0ca6891b736de009e0b6c2ebac958cc94
* c6a48365c3db9761bd60981bdcdd87aced23d8e60067caa30fee501bf4b47b84
* a03d13c9825e150810e6e6aaf053d71ec5a53b86581414dd982a74d4a8bc5475

### KANDYKORN

SHA256 hash:

* 927b3564c1cf884d2a05e1d7bd24362ce8563a1e9b85be776190ab7f8af192f6

### SmoothOperator

#### Malicious 3CX DMG

SHA256 hash:

* e6bbc33815b9f20b0cf832d7401dd893fbc467c800728b5891336706da0dbcec

#### libffmpeg.dy

SHA256 hashes:

* a64fa9f1c76457ecc58402142a8728ce34ccba378c17318b3340083eeb7acc67
* 479038eb12ed07893ee0dcc04fbdcf182489bbb271f5a4f90f83874881a80ce3
* 2546d239a262c24a6f8ea01d890cbc459a22db79b379b6ec3b24fbb56efb5381
* 5009c7d1590c1f8c05827122172583ddf924c53b55a46826abf66da46725505a
* 87c5d0c93b80acf61d24e7aaf0faae231ab507ca45483ad3d441b5d1acebc43c
* 99dbc6fe3c3e465052fcefa1642861747dc9e069eeb244589b605bd710b1e0d1
* fee4f9dabc094df24d83ec1a8c4e4ff573e5d9973caa676f58086c99561382d7
* 7667d1b8fcc4f712084e3e3f8b4ab505ab150c52aea7b219249ec508b4b0e224

#### UpdateAgent

SHA256 hash:

* 6c121f2b2efa6592c2c22b29218157ec9e63f385e7a1d7425857d603ddef8c59

Domains:

* msstorageazure\[.\]com
* officestoragebox\[.\]com
* visualstudiofactory\[.\]com
* azuredeploystore\[.\]com
* msstorageboxes\[.\]com
* officeaddons\[.\]com
* sourceslabs\[.\]com
* zacharryblogs\[.\]com
* pbxcloudeservices\[.\]com
* pbxphonenetwork\[.\]com
* akamaitechcloudservices\[.\]com
* azureonlinestorage\[.\]com
* msedgepackageinfo\[.\]com
* glcloudservice\[.\]com
* pbxsources\[.\]com
* sbmsa\[.\]wiki

### ObjCShellz

SHA256 hashes:

* 8bfa4fe0534c0062393b6a2597c3491f7df3bf2eabfe06544c53bdf1f38db6d4
* 15d53bb839e00405a34a8b690ec181f5555fc4f891b8248ae7fa72bad28315a9
* f1713afaf5958bdf3e975ebbab8245a98a84e03f8ce52175ef1568de208116e0

Domain:

* swissborg\[.\]blog

### Fullhouse Backdoor

SHA256 hash:

* 081804b491c70bfa63ecdbe9fd4618d3570706ad8b71dba13e234069648e5e48

Domains:

* contortonset\[.\]com
* relysudden\[.\]com
* primerosauxiliosperu\[.\]com
* rentedpushy\[.\]com
* basketsalute\[.\]com
* prontoposer\[.\]com

IP addresses:

* 146\.19.173\[.\]125
* 23\.227.202\[.\]54
* 38\.132.124\[.\]88
* 88\.119.174\[.\]148
* 198\.244.135\[.\]250

### POOLRAT

SHA256 hashes:

* f3b0da965a4050ab00fce727bb31e0f889a9c05d68d777a8068cfc15a71d3703
* 5c907b722c53a5be256dc5f96b755bc9e0b032cc30973a52d984d4174bace456
* 5e40d106977017b1ed235419b1e59ff090e1f43ac57da1bb5d80d66ae53b1df8

URLs:

* www.talesseries\[.\]com/write.php
* rgedist\[.\]com/sfxl.php

Domains:

* airbseeker\[.\]com
* globalkeystroke\[.\]com
* globalkeystroke\[.\]com

### PondRAT

SHA256 hashes:

* 973f7939ea03fd2c9663dafc21bb968f56ed1b9a56b0284acf73c3ee141c053c
* 0b5db31e47b0dccfdec46e74c0e70c6a1684768dbacc9eacbb4fd2ef851994c7
* 3c8dbfcbb4fccbaf924f9a650a04cb4715f4a58d51ef49cc75bfcef0ac258a3e
* bce1eb513aaac344b5b8f7a9ba9c9e36fc89926d327ee5cc095fb4a895a12f80
* bfd74b4a1b413fa785a49ca4a9c0594441a3e01983fc7f86125376fdbd4acf6b
* cbf4cfa2d3c3fb04fe349161e051a8cf9b6a29f8af0c3d93db953e5b5dc39c86
* 91eaf215be336eae983d069de16630cc3580e222c427f785e0da312d0692d0fd

Domains:

* jdkgradle\[.\]com
* rebelthumb\[.\]net
* levelframeblog\[.\]com

### OdicLoader

SHA256 hashes:

* c83c7b000a955f2b8cb92bb112ed606ffd9fbebbe3422f80d90d06b167f2f37b
* 492a643bd1efdaca4ca125ade1b606e7bbf00e995ac9115ac84d1c4c59cb66dd

### Comebacker

SHA256 hash:

* 63fb47c3b4693409ebadf8a5179141af5cf45a46d1e98e5f763ca0d7d64fb17c

### CollectionRAT

SHA256 hashes:

* db6a9934570fa98a93a979e7e0e218e0c9710e5a787b18c6948f2eedd9338984
* d8565d58ad8e4f5558b5cd70df0ad12be9cf44e32ad07aaac6f65b816edbf414

*Updated Sept. 11, 2024, at 11:55 a.m. PT for clarifying language on which threat groups this piece covers.*
Back to top

### Tags

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")
* [Alluring Pisces](https://unit42.paloaltonetworks.com/tag/alluring-pisces/ "Alluring Pisces")
* [Andariel](https://unit42.paloaltonetworks.com/tag/andariel/ "Andariel")
* [Bluenoroff](https://unit42.paloaltonetworks.com/tag/bluenoroff/ "Bluenoroff")
* [Citrine Sleet](https://unit42.paloaltonetworks.com/tag/citrine-sleet/ "Citrine Sleet")
* [CollectionRAT](https://unit42.paloaltonetworks.com/tag/collectionrat/ "CollectionRAT")
* [Comebacker](https://unit42.paloaltonetworks.com/tag/comebacker/ "Comebacker")
* [Finance](https://unit42.paloaltonetworks.com/tag/finance/ "Finance")
* [Fullhouse](https://unit42.paloaltonetworks.com/tag/fullhouse/ "Fullhouse")
* [Gleaming Pisces](https://unit42.paloaltonetworks.com/tag/gleaming-pisces/ "Gleaming Pisces")
* [Government](https://unit42.paloaltonetworks.com/tag/government/ "Government")
* [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/ "Jumpy Pisces")
* [KANDYKORN](https://unit42.paloaltonetworks.com/tag/kandykorn/ "KANDYKORN")
* [Kimsuky](https://unit42.paloaltonetworks.com/tag/kimsuky/ "Kimsuky")
* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")
* [ObjCShellz](https://unit42.paloaltonetworks.com/tag/objcshellz/ "ObjCShellz")
* [OdicLoader](https://unit42.paloaltonetworks.com/tag/odicloader/ "OdicLoader")
* [PondRAT](https://unit42.paloaltonetworks.com/tag/pondrat/ "PondRAT")
* [POOLRAT](https://unit42.paloaltonetworks.com/tag/poolrat/ "POOLRAT")
* [Remote Access Trojan](https://unit42.paloaltonetworks.com/tag/remote-access-trojan/ "Remote Access Trojan")
* [RustBucket](https://unit42.paloaltonetworks.com/tag/rustbucket/ "RustBucket")
* [Selective Pisces](https://unit42.paloaltonetworks.com/tag/selective-pisces/ "Selective Pisces")
* [Slow Pisces](https://unit42.paloaltonetworks.com/tag/slow-pisces/ "Slow Pisces")
* [SmoothOperator](https://unit42.paloaltonetworks.com/tag/smoothoperator/ "SmoothOperator")
* [Sparkling Pisces](https://unit42.paloaltonetworks.com/tag/sparkling-pisces/ "Sparkling Pisces")
* [TEMP.Hermit](https://unit42.paloaltonetworks.com/tag/temp-hermit/ "TEMP.Hermit")
* [TraderTraitor](https://unit42.paloaltonetworks.com/tag/tradertraitor/ "TraderTraitor")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Chinese APT Abuses VSCode to Target Government in Asia](https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/ "Chinese APT Abuses VSCode to Target Government in Asia")

### Table of Contents

* 

### Related Articles

* [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "article - table of contents")
* [Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns](https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/ "article - table of contents")
* [Tracking TamperedChef Clusters via Certificate and Code Reuse](https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/ "article - table of contents")

## Related Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
