[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/turla-pensive-ursa-threat-assessment/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/ "Nation-State Cyberattacks")  
  [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)

# Threat Group Assessment: Turla (aka Pensive Ursa)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Unit 42](https://unit42.paloaltonetworks.com/author/unit42/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 15, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Nation-State Cyberattacks](https://unit42.paloaltonetworks.com/category/nation-state-cyberattacks/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/)
  * [Capibar](https://unit42.paloaltonetworks.com/tag/capibar/)
  * [Carbon](https://unit42.paloaltonetworks.com/tag/carbon/)
  * [ComRAT](https://unit42.paloaltonetworks.com/tag/comrat/)
  * [Crutch](https://unit42.paloaltonetworks.com/tag/crutch/)
  * [HyperStack](https://unit42.paloaltonetworks.com/tag/hyperstack/)
  * [MITRE](https://unit42.paloaltonetworks.com/tag/mitre/)
  * [Pensive Ursa](https://unit42.paloaltonetworks.com/tag/pensive-ursa/)
  * [QUIETCANARY](https://unit42.paloaltonetworks.com/tag/quietcanary/)
  * [Snake](https://unit42.paloaltonetworks.com/tag/snake/)
  * [TinyTurla](https://unit42.paloaltonetworks.com/tag/tinyturla/)
  * [Tunnus](https://unit42.paloaltonetworks.com/tag/tunnus/)
  * [Turla](https://unit42.paloaltonetworks.com/tag/turla/)
  * [Uroburos](https://unit42.paloaltonetworks.com/tag/uroburos/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/?pdf=download&lg=en&_wpnonce=edee969a51 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/?pdf=print&lg=en&_wpnonce=edee969a51 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=Threat%20Group%20Assessment:%20Turla%20(aka%20Pensive%20Ursa)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fturla-pensive-ursa-threat-assessment%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fturla-pensive-ursa-threat-assessment%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fturla-pensive-ursa-threat-assessment%2F&title=Threat%20Group%20Assessment:%20Turla%20(aka%20Pensive%20Ursa)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fturla-pensive-ursa-threat-assessment%2F&text=Threat%20Group%20Assessment:%20Turla%20(aka%20Pensive%20Ursa)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fturla-pensive-ursa-threat-assessment%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=Threat%20Group%20Assessment:%20Turla%20(aka%20Pensive%20Ursa)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fturla-pensive-ursa-threat-assessment%2F> "Share in Mastodon")

## Executive Summary

Turla (aka Pensive Ursa, Uroburos, Snake) is a Russian-based threat group operating since at least 2004, which is [linked to the Russian Federal Security Service (FSB)](https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network). In this article, we will cover the top 10 most recently active types of malware in Pensive Ursa's arsenal: Capibar, Kazuar, Snake, Kopiluwak, QUIETCANARY/Tunnus, Crutch, ComRAT, Carbon, HyperStack and TinyTurla.

[Pensive Ursa](https://attackevals.mitre-engenuity.org/enterprise/turla/) was chosen to be the main focus for the 2023 MITRE ATT\&CK evaluation. MITRE has described Turla as being "known for their targeted intrusions and innovative stealth." The results of this evaluation, including Palo Alto Networks scoring, will be published in late September 2023.

In addition to describing each type of malware's functionality and history, we will present their execution through the lens of the Palo Alto Networks Cortex XDR product. We will show how Cortex protects against such malware, and the MITRE ATT\&CK mapping of such threats as shown in the Cortex XDR platform.

Palo Alto Networks customers receive protections from Pensive Ursa's arsenal and the techniques discussed in this blog through [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR), which provides a multilayer defense that includes behavioral threat protection and exploit protection.

The Advanced WildFire cloud-delivered malware analysis service accurately identifies samples related to Pensive Ursa as malicious. Cloud-Delivered Security Services, including Advanced URL Filtering and DNS Security, identify domains associated with this group as malicious.

|----------------------------|--------------------------------------------------------------------------------------------------------------------------------|
| **Related Unit 42 Topics** | [**APT**](https://unit42.paloaltonetworks.com/tag/apt/), **[Malware](https://unit42.paloaltonetworks.com/category/malware-2)** |
| **Pensive Ursa**           | Alternative names: Turla, Snake, Uroburos, Venomous Bear, Waterbug, Iron Hunter                                                |
| **Malware discussed**      | Capibar, Kazuar, Snake, QUIETCANARY, Kopiluwak, Crutch, ComRAT, Carbon, HyperStack, TinyTurla                                  |

## Pensive Ursa (aka Turla) Overview

Over the years, Pensive Ursa has become known as an advanced and elusive adversary. The group has demonstrated a high level of technical expertise, while orchestrating targeted and stealthy attacks.

[As described by MITRE](https://attack.mitre.org/groups/G0010/), Pensive Ursa targeted victims in over 45 countries as well as a wide range of sectors, including government entities, embassies, and military organizations, as well as education, research and pharmaceutical companies. In addition, this threat group had an active part in the Russian-Ukraine conflict that started in February 2022. [According to the Ukraine CERT](https://cert.gov.ua/article/5213167), Pensive Ursa leveraged espionage attacks against Ukrainian targets, specifically against [their defense sector](https://therecord.media/turla-hackers-targeting-ukraine-defense).

While Pensive Ursa mainly used their espionage arsenal to target Windows machines, the group also has tools that can attack macOS and Linux machines.

## MITRE ATT\&CK Evaluation

For the 2023 MITRE ATT\&CK evaluation, Pensive Ursa was chosen to be the main focus. [According to MITRE](https://attackevals.mitre-engenuity.org/enterprise/turla/), this threat group is particularly relevant as their actions have global impact.

Below are the top 10 most recently active types of malware in the team's arsenal. For each type of malware, we provided a short description and analysis, as well as how Cortex XDR detects and prevents the threat.

## Recent Pensive Ursa Arsenal Technical Analysis

### **Malware:** **Capibar**

**Aliases:** DeliveryCheck, GAMEDAY

**Malware Type:** Backdoor

**First Seen:** 2022

**Description:** Capibar (aka DeliveryCheck, GAMEDAY) is a Pensive Ursa backdoor that was first observed in 2022, and used for the purpose of espionage against defense forces in Ukraine. They distributed it via email as documents with malicious macros.

Capibar persists via a scheduled task that downloads and launches the payload in memory. The threat group installed Capibar on compromised MS Exchange servers as a Managed Object Format (MOF) file, granting the attacker full control of the server. Figure 1a below shows a snippet of the code responsible for loading XML received from its command and control (C2), and Figure 1b shows the alert triggered.
![Image 1a is a screenshot of many lines of code. It is responsible for loading an XML from the command and control. It loads Capibar.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-1.png) Figure 1a. Capibar code snippet loading XML received from its C2. ![Image 1b is a screenshot of text from the Cortex XDR application. WildFire malware. Source: XDR agent. Suspicious DLL detected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-2.png) Figure 1b. The alert triggered in Cortex XDR.

### Malware: Kazuar

**Malware Type:** Backdoor

**First Seen:** 2017

**Description:** [Kazuar is a .NET backdoor](https://unit42.paloaltonetworks.com/unit42-kazuar-multiplatform-espionage-backdoor-api-access/) that was discovered in 2017. Kazuar provides full access to the compromised systems targeted by its operator. Kazuar comes with a powerful command set that includes the ability to remotely load additional plugins to enhance the backdoor's capabilities.

In 2021, [researchers found interesting code overlaps](https://securelist.com/sunburst-backdoor-kazuar/99981/) and similarities between Kazuar and the notorious SUNBURST backdoor that a Russian threat group used in the [SolarWinds Operation](https://www.mandiant.com/resources/blog/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor). In July 2023, the [Ukrainian CERT uncovered](https://cert.gov.ua/article/5213167) an espionage operation where Pensive Ursa used Kazuar as one of the main backdoors. Figure 2 shows Cortex XDR preventing a Kazuar DLL from being injected into the explorer.exe process, and Figure 3 shows an alert being triggered for Kazuar prevention.
![Image 2 is a screenshot of the Cortex XDR application. Within a blue circle is a generic icon of an application window. Below it is the number 34. A red warning shield appears above it. Explorer.exe is listed below the 34. To the right of the icon is a description box that says a suspicious DLL has been detected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-3.png) Figure 2. Kazuar injected into explorer.exe and prevented by Cortex XDR. ![Image 3 is a screenshot of the Cortex XDR application. Within a blue circle is a generic icon of an application window. Below it is the number 34. A red warning shield appears above it. Explorer.exe is listed below the 34. To the right of the icon is a description box that says a suspicious DLL has been detected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-4.png) Figure 3. Kazuar execution prevention alert by Cortex XDR.

### Malware: Snake

\*\*Malware Type:\*\*Modular backdoor

\*\*First Seen:\*\*2003

**Description:** The infamous Snake malware is the most complex tool in Pensive Ursa's tool set, as [described by CISA](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a) in May 2023. The primary purpose of this tool is to achieve persistence for considerable periods of time and exfiltrate data from dedicated targets. It was in active development for 20 years, since 2003.

Snake was detected operating in more than 50 countries worldwide. The United States [Department of Justice](https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network) published a statement in which they announced Operation MEDUSA, where they disrupted the Snake malware activity and peer to peer (P2P) network. They did so by using a tool developed by the FBI dubbed PERSEUS, which they used as a kill switch for the Snake malware.

Based on previous analysis, the Snake malware implemented a maintainable code design, which showed that its authors had a high level of software development capability.

Snake implements features such as the following:

* A custom implementation of communication protocols over HTTP and TCP
* A kernel module for stealth
* Key logger functionality

More recent variants of Snake include an infection chain similar to the one depicted below.

**Example of Snake Malware Delivery**

Upon execution, Snake loads and executes Pensive Ursa's [PNG Dropper](https://research.nccgroup.com/2018/11/22/turla-png-dropper-is-back/) malware from its resources and creates a hard-coded mutex {E9B1E207-B513-4cfc-86BE-6D6004E5CB9C, as shown in Figure 4.
![Image 4 is a screenshot of the program Resource Hacker. It lists Snake loaders resources. On the left is a menu of the binary. The view in the screenshot is the binary view, and the user can also select an editor view.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-5.png) Figure 4. Snake loader's resources.

The PNG dropper then decodes and loads a vulnerable VM driver that is used for privilege escalation in order to write the main Snake payload to disk, and register it as a service.

The Snake loader variant shown in Figure 5 detects the multiple stages in the infection chain that lead to the deployment, service registration and execution of the main Snake payload. Figure 6 shows the execution prevention alert pop-up in Cortex XDR.
![Image 5 is a screenshot of a tree diagram in Cortex XDR. The tree has two branches. Various alert symbols shoe on the tree. There are two descriptions of separate commands that have been detected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-6.png) Figure 5. Snake execution detection shown in Cortex XDR in detect mode. ![Image 6 is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: snake.exe. Application publisher: Unknown. Prevention description: Suspicious executable detected. There are two buttons: Show details and OK.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-7.png) Figure 6. Snake execution prevention alert shown in Cortex XDR.

### Malware: QUIETCANARY

\*\*Aliases:\*\*Tunnus

\*\*Malware Type:\*\*Backdoor

\*\*First Seen:\*\*2017

**Description:** Pensive Ursa has been observed using QUIETCANARY since 2019, and the Tomiris group has used this backdoor even earlier. Pensive Ursa deployed QUIETCANARY against [targets in Ukraine in September 2022](https://www.mandiant.com/resources/blog/turla-galaxy-opportunity), together with the Kopiluwak malware. QUIETCANARY is a lightweight backdoor written in .NET, which is capable of executing various commands received from its C2 server, including downloading additional payloads and executing arbitrary commands. It also implements RC4 encryption to protect its C2 communication. Figure 7 shows QUIETCANARY's different classes that reveal its backdoor capabilities.
![Image 7 is a screenshot of many lines of code. These are the different classes in QUIETCANARY’s code. They include BrowserTelemetry and CommandDescriptor, CommandFactory, Executor, Processor, ClearCommand, DownloadCommand, KillCommand, and many others.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-8.png) Figure 7. Code snippet of the different classes in QUIETCANARY's code.

Figure 8 shows the Cortex XDR multilayered protection-based alerts that QUIETCANARY triggered. Figure 9 shows the execution prevention alert.
![Image 8 is a screenshot of Cortex XDR’s alerts for QUIETCANARY. The column on the left is for alerts and lists malware, execution, execution. The column on the right is for the alert name. These are WildFire Malware, identity analytics and identity analytics. The details include that the first analytics is a rare process execution in organization. The second analytics is a rare process execution by user.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-9.png) Figure 8. QUIETCANARY's alerts shown in Cortex XDR. ![Image 9 is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: BrowserTelemetry. Application publisher: Unknown. Prevention description: Suspicious executable detected. There are two buttons: Show details and OK.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-10.png) Figure 9. QUIETCANARY/Tunnus execution prevention alert shown in Cortex XDR.

### Malware: Kopiluwak

\*\*Malware Type:\*\*Spreader/Downloader

\*\*First Seen:\*\*2016

**Description:** Kopiluwak malware was discovered in [late 2016](https://securelist.com/kopiluwak-a-new-javascript-payload-from-turla/77429/), and it was delivered as a multilayered JavaScript payload by various types of droppers.

Pensive Ursa dropped the Kopiluwak malware using an MSIL dropper in 2017 in a [G20-themed attack](https://www.proofpoint.com/us/threat-insight/post/turla-apt-actor-refreshes-kopiluwak-javascript-backdoor-use-g20-themed-attack), and [as an SFX executable in late 2022](https://www.mandiant.com/resources/blog/turla-galaxy-opportunity).

Kopiluwak's JavaScript file is depicted in Figure 10 and the code snippet below, dropped under the C:\\Windows\\Temp\\ path. Its purpose is gathering valuable initial profiling information on the infected machine, such as the following:

* Listing files in strategic locations
* Retrieving the current running processes
* Displaying active network connections

The threat actor accomplished this activity by running reconnaissance commands such as systeminfo, tasklist, net, ipconfig, and dir. The results are saved in a file named result2.dat.
![Image 10 is a screenshot of a diagram in Cortex XDR. It demonstrates the Kopiluwak execution detection. Several icons within red or blue circles show the separate stages. Two have alerts. From left to right they are fopiluwak.exe, wsscropt.exe, and cmd.exe.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-11.png) Figure 10. Kopiluwak execution detection as shown in Cortex XDR in detect mode.

Listed in Figure 11 are the reconnaissance commands executed by Kopiluwak, and detected by Cortex XDR.
![Image 11 is a screenshot of many lines of code. These are the reconnaissance commands for Kopiluwak.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-12.png) Figure 11. Kopiluwak's reconnaissance commands.

Figure 12 shows Cortex XDR raising an execution prevention alert for Kopiluwak.
![Image 12 is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: Kopiluwak.exe. Application publisher: Unknown. Prevention description: Suspicious executable detected. There are two buttons: Show details and OK.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-13.png) Figure 12. Kopiluwak execution prevention alert as shown in Cortex XDR.

In 2019, Pensive Ursa began to deliver Kopiluwak using the [Topinambour](https://www.kaspersky.com/about/press-releases/2019_taste-of-topinambour) dropper. The group bundled Topinambour into a legitimate software installer.

Upon installation, Topinambour is dropped as a small .NET file in the %localappdata% folder and written as a scheduled task, as shown in Figure 13. The malware then communicates with its hard-coded C2 virtual private server (VPS) to deliver the Kopiluwak malware.
![Image 13 is a screenshot of a tree diagram in Cortex XDR. It demonstrates the Topinambour execution detection. Several icons within red or blue circles show the separate stages. Two have alerts. There is an inset description that includes a breakdown of the different commands and the file path.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-14.png) Figure 13. Topinambour execution detection shown in Cortex XDR in detect mode.

Figure 14 shows the prevention alert pop-up raised by Cortex XDR.
![Image 14 is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: topinambour.exe. Application publisher: Unknown. Prevention description: Suspicious executable detected. There are two buttons: Show details and OK.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-15.png) Figure 14. Topinambour execution prevention alert shown in Cortex XDR.

### Malware: Crutch

\*\*Malware Type:\*\*Backdoor

\*\*First Seen:\*\*2015

**Description:** In December 2020, [ESET researchers discovered](https://www.welivesecurity.com/2020/12/02/turla-crutch-keeping-back-door-open/) the Crutch backdoor. In line with Pensive Ursa's tactics, techniques and procedures (TTPs), the threat actor used the backdoor to attack a handful of targets in Europe, including the Ministry of Foreign Affairs of an EU member.

The main purpose of this backdoor was to eventually steal sensitive files and exfiltrate the data to a Dropbox account controlled by Pensive Ursa operators. Using commercial services such as Dropbox for C2 communication is a known (yet effective) technique due to it being a legitimate service, and blending in with other network communication.

This backdoor was attributed to Pensive Ursa due to strong similarities in code and TTPs with another backdoor from Pensive Ursa's arsenal called Gazer. Crutch is considered to be a second-stage backdoor, and its persistence is achieved using DLL hijacking.

Figures 15 and 16 show the detection and prevention of Crutch respectively, in Cortex XDR.
![Image 15 is a screenshot of a diagram in Cortex XDR. It demonstrates the Crutch execution detection. Several icons within blue circles show the separate stages. Two have alerts. There is an inset description that includes a breakdown of the different commands and the file path.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-16.png) Figure 15. Crutch execution detection shown in Cortex XDR in detect mode. ![Image 16 is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: Windows host process (Rundll32). Application publisher: Microsoft Corporation. Prevention description: Suspicious DLL detected. Show details has been selected and the information included is: application name, application version, application publisher, process ID, application location, command line and file origin.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-17.png) Figure 16. Crutch execution prevention alert shown in Cortex XDR.

### Malware: ComRAT

\*\*Aliases:\*\*Agent.btz

\*\*Malware Type:\*\*Backdoor

\*\*First Seen:\*\*2007
![Image 17 is a screenshot of a diagram in Cortex XDR. It demonstrates the PowerShell dropper as it drops ComRAT. Several icons within blue circles show the separate stages. Three have alerts. There are inset descriptions that includes a breakdown of the different commands and the file path.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-18.png) Figure 17. PowerShell dropper drops ComRAT to disk shown in Cortex XDR in detect mode.

**Description:** ComRAT is one of Pensive Ursa's oldest backdoors, which they named Agent.btz in earlier iterations of the malware. ComRAT was reportedly first [discovered in 2007](https://www.welivesecurity.com/2020/05/26/agentbtz-comratv4-ten-year-journey/). Since then it has had many upgrades. As of 2020, the latest iteration of ComRAT is version 4. This threat is developed in C++ and the threat actor has deployed it using PowerShell implants, such as PowerStallion. Figure 17 shows the PowerShell dropper mechanism. The threat actor's main purpose of operations when using ComRAT was to steal and exfiltrate confidential documents from high value targets.
![Image 18a is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: Windows PowerShell. Application publisher: Microsoft Corporation. Prevention description: Behavioral threat detected. Show details has been selected and the information included is: application name, application version, application publisher, process ID, application location, command line, file origin and user name.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-19.png) Figure 18a. ComRAT PowerShell dropper execution prevention alert shown in Cortex XDR.

Figures 18a and 18b depict the PowerShell and DLL executions preventions respectively, in Cortex XDR.
![Image 18b is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: Windows host process (Rundll32). Application publisher: Microsoft Corporation. Prevention description: Suspicious DLL detected. Also listed is the application version, process ID, application location, the command line and the file origin.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-20.png) Figure 18b. ComRAT DLL execution prevention alerts shown in Cortex XDR.

### Malware: Carbon

\*\*Malware Type:\*\*Backdoor

\*\*First Seen:\*\*2014

**Description:** [Carbon is a modular backdoor framework](https://www.welivesecurity.com/2017/03/30/carbon-paper-peering-turlas-second-stage-backdoor/) that has been used by Pensive Ursa for several years. The Carbon framework includes an installer, an orchestrator component, a communication module and a configuration file.

Carbon also has P2P communication capabilities, which the threat actor uses to send commands to other infected machines on an affected network. Carbon receives commands from the C2 through the use of legitimate web services providers like Pastebin.

Figure 19 and Figure 20 show Carbon's execution detection and prevention in Cortex XDR.
![Image 19 is a screenshot of a diagram in Cortex XDR. It demonstrates Carbon creating a service that loads additional components. Several icons within blue and red circles show the separate stages. Two have alerts. Some information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-21.png) Figure 19. Carbon creates a service that loads the additional components, which is shown in Cortex XDR in detect mode. ![Image 20 is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: carbon.exe. Application publisher: Unknown. Prevention description: Suspicious executable detected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-22.png) Figure 20. Carbon execution prevention alert shown in Cortex XDR.

### Malware: HyperStack

\*\*Malware Type:\*\*Backdoor

\*\*First Seen:\*\*2018

**Description:** HyperStack (aka SilentMoo, BigBoss) is an [RPC backdoor](https://www.bleepingcomputer.com/news/security/russian-turla-hackers-breach-european-government-organization/) that was first observed in 2018, which the threat actor used in operations targeting government entities in Europe. HyperStack operates with a controller that uses named pipes to communicate over RPC with other machines in a compromised environment that are infected with HyperStack. This communication method enables the attacker to control machines on a local network.

HyperStack shows several similarities with Pensive Ursa's Carbon backdoor, such as the encryption scheme, configuration file format and logging convention.

Figure 21 and Figure 22 show HyperStack's detection and prevention respectively, in Cortex XDR.
![Image 21 is a screenshot of a diagram in Cortex XDR. It demonstrates HyperStack creating a service for persistence. Several icons within blue and red circles show the separate stages. Three have alerts. Some information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-23.png) Figure 21. HyperStack creates a service for persistence shown in Cortex XDR in detect mode. ![Image 22 is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: HyperStack. Application publisher: Unknown. Prevention description: Suspicious executable detected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-24.png) Figure 22. HyperStack execution prevention alert shown in Cortex XDR.

### Malware: TinyTurla

\*\*Malware Type:\*\*Backdoor

\*\*First Seen:\*\*2021

**Description:** The TinyTurla malware was first [discovered by Talos](https://blog.talosintelligence.com/tinyturla/) in 2021. They assumed it was a second stage backdoor, and it has been seen on targets in the US, EU and later in Asia.

TinyTurla's main features include the following:

* Downloading additional payloads
* Uploading files to the attacker's C2 server
* Executing other processes

As shown in Figure 23, threat actors install the backdoor via a batch script as a service called Windows Time Service. The batch script is also in charge of writing the C2 server's data to the registry. Once the backdoor is executed, it reads these values to communicate with its C2. It masquerades as a DLL called w64time.dll, under the system32 folder.
![Figure 23 is a screenshot of 10 lines of code. It is the badge script that writes the command and control server’s data to the registry.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-25.png) Figure 23. Content of the batch script described above.

Although w32time.dll is a legitimate DLL, and other legitimate DLLs do have both 32- and 64-bit variants, a legitimate w64time.dll does not exist. This naming convention is intended to further distract victims from suspecting anything is amiss.

Figure 24 and Figure 25 show Cortex XDR detecting the writing and execution of the batch script, the W64Time service and the TinyTurla DLL execution.
![Image 24 is a screenshot of a diagram in Cortex XDR. It demonstrates TinyTurla prevention. Several icons within blue circles show the separate stages. One has an alert. Two inset descriptions implied the CMD and the information that a Suspicious DLL was detected. Some information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-26.png) Figure 24. TinyTurla prevention shown in Cortex XDR in detect mode. ![Image 25 is a screenshot of the Cortex XDR Prevention Alert window. Cortex XDR has blocked a malicious activity! Application name: Windows host process (Rundll32). Application publisher: Microsoft Corporation. Prevention description: Suspicious DLL detected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-27.png) Figure 25. TinyTurla execution prevention alert shown in Cortex XDR.

## Tactics, Techniques and Procedures (TTPs)

Cortex XDR alerts are mapped to the [MITRE ATT\&CK](https://attack.mitre.org/) framework and present information about the tactic and the technique associated with the threat, as shown in Figure 26 below.
![A screenshot of what MITRE ATT\&CK mapping looks like in Cortex XDR.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-28.png) Figure 26. Mitre ATT\&CK mapping in Cortex XDR.

Pensive Ursa-related activities and arsenal raised multiple alerts in Cortex XDR, which were mapped to the MITRE ATT\&CK tactics and techniques referenced in Table 1.

|--------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **MITRE ATT\&CK tactic** | **MITRE ATT\&CK technique**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Resource Development     | [Acquire Infrastructure](https://attack.mitre.org/techniques/T1583/), [Compromise Infrastructure](https://attack.mitre.org/techniques/T1584/), [Develop Capabilities](https://attack.mitre.org/techniques/T1587/), [Obtain Capabilities](https://attack.mitre.org/techniques/T1588/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Execution                | [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059/), [Native API](https://attack.mitre.org/techniques/T1106/), [User Execution](https://attack.mitre.org/techniques/T1204/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Initial Access           | [Drive-by Compromise](https://attack.mitre.org/techniques/T1189/), [Phishing](https://attack.mitre.org/techniques/T1566/), [Valid Accounts](https://attack.mitre.org/techniques/T1078/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Persistence              | [Boot or Logon Autostart Execution](https://attack.mitre.org/techniques/T1547/), [Event Triggered Execution](https://attack.mitre.org/techniques/T1546/), [Valid Accounts](https://attack.mitre.org/techniques/T1078/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Privilege Escalation     | [Access Token Manipulation](https://attack.mitre.org/techniques/T1134/), [Boot or Logon Autostart Execution](https://attack.mitre.org/techniques/T1547/), [Event Triggered Execution](https://attack.mitre.org/techniques/T1546/), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068/), [Process Injection](https://attack.mitre.org/techniques/T1055/), [Valid Accounts](https://attack.mitre.org/techniques/T1078/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Defense Evasion          | [Access Token Manipulation](https://attack.mitre.org/techniques/T1134/), [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140/), [Impair Defenses](https://attack.mitre.org/techniques/T1562/), [Modify Registry](https://attack.mitre.org/techniques/T1112/), [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027/), [Process Injection](https://attack.mitre.org/techniques/T1055/), [Subvert Trust Controls](https://attack.mitre.org/techniques/T1553/), [Valid Accounts](https://attack.mitre.org/techniques/T1078/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Credential Access        | [Brute Force](https://attack.mitre.org/techniques/T1110/), [Credentials from Password Stores](https://attack.mitre.org/techniques/T1555/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Discovery                | [Account Discovery](https://attack.mitre.org/techniques/T1087/), [File and Directory Discovery](https://attack.mitre.org/techniques/T1083/), [Group Policy Discovery](https://attack.mitre.org/techniques/T1615/), [Password Policy Discovery](https://attack.mitre.org/techniques/T1201/), [Peripheral Device Discovery](https://attack.mitre.org/techniques/T1120/), [Permission Groups Discovery](https://attack.mitre.org/techniques/T1069/), [Process Discovery](https://attack.mitre.org/techniques/T1057/), [Query Registry](https://attack.mitre.org/techniques/T1012/), [Remote System Discovery](https://attack.mitre.org/techniques/T1018/), [Software Discovery](https://attack.mitre.org/techniques/T1518/), [System Information Discovery](https://attack.mitre.org/techniques/T1082/), [System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016/), [System Network Connections Discovery](https://attack.mitre.org/techniques/T1049/), [System Service Discovery](https://attack.mitre.org/techniques/T1007/) |
| Lateral Movement         | [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570/), [Remote Services](https://attack.mitre.org/techniques/T1021/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Collection               | [Archive Collected Data](https://attack.mitre.org/techniques/T1560/), [Data from Information Repositories](https://attack.mitre.org/techniques/T1213/), [Data from Local System](https://attack.mitre.org/techniques/T1005/), [Data from Removable Media](https://attack.mitre.org/techniques/T1025/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Command and Control      | [Application Layer Protocol](https://attack.mitre.org/techniques/T1071/), [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105/), [Proxy](https://attack.mitre.org/techniques/T1090/), [Web Service](https://attack.mitre.org/techniques/T1102/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Exfiltration             | [Exfiltration Over Web Service](https://attack.mitre.org/techniques/T1567/)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

*Table 1. MITRE ATT\&CK tactics and techniques.*

## Conclusion

The Pensive Ursa advanced persistent threat (APT) group is known to be a significant and persistent adversary. With their advanced techniques, this Russian-FSB operated group has demonstrated an evasive modus operandi while targeting a wide range of sectors across the globe.

We explored the top 10 types of malware in Pensive Ursa's arsenal and witnessed their execution through the lens of Palo Alto Networks Cortex XDR product. This demonstrated the importance of using a multilayered protection model against an advanced threat.

The potential damage of falling victim to a Pensive Ursa APT attack can be significant. The consequences extend beyond financial losses and data breaches to the possibility of them reaching critical infrastructure, which could have national security and geopolitical ramifications. Thus, every organization, regardless of its size or industry, must prioritize comprehensive security strategies and invest in multilayer security measurements to safeguard against the growing threat of APT groups like Pensive Ursa.

## Protections and Mitigations

Palo Alto Networks [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) customers receive protections against Pensive Ursa's arsenal of malware described in this blog post.

Prevention and detection alerts were raised for each malware: Capibar, Kazua, Snake, Kopiluwak, QUIETCANARY/Tunnus, Crutch, ComRAT, Carbon, HyperStack and TinyTurla.

[SmartScore](https://www.paloaltonetworks.com/blog/security-operations/beating-alert-fatigue-with-cortex-xdr-smartscore-technology/) is a unique ML-driven scoring engine that translates security investigation methods and their associated data into a hybrid scoring system. It scored an incident involving a combination of known Pensive Ursa tools and techniques a 91 score, which is a very high level of risk, as shown below in Figure 26.
![Image 26 is a screenshot of the program SmartScore. It lists incident information with a rating and why the incident was rated the severity it was.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129929-29.png) Figure 27. SmartScore information about the incident.

For Palo Alto Networks customers, our products and services provide the following coverage associated with this group:

[Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?_gl=1*13pmp8e*_ga*NzQyNjM2NzkuMTY2NjY3OTczNw..*_ga_KS2MELEEFC*MTY2OTczNjA2MS4zMS4wLjE2Njk3MzYwNjEuNjAuMC4w) detects user and credential-based threats by analyzing user activity from multiple data sources including the following:

* Endpoints
* Network firewalls
* Active Directory
* Identity and access management solutions
* Cloud workloads

Cortex XDR builds behavioral profiles of user activity over time with machine learning. By comparing new activity to past activity, peer activity and the expected behavior of the entity, Cortex XDR detects anomalous activity indicative of credential-based attacks.

It also offers the following protections related to the attacks discussed in this post:

* Prevents the execution of known malicious malware and also prevents the execution of unknown malware using [Behavioral Threat Protection and](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention?_gl=1*13pmp8e*_ga*NzQyNjM2NzkuMTY2NjY3OTczNw..*_ga_KS2MELEEFC*MTY2OTczNjA2MS4zMS4wLjE2Njk3MzYwNjEuNjAuMC4w) machine learning based on the Local Analysis module
* Protects against credential gathering tools and techniques using the new Credential Gathering Protection available from Cortex XDR 3.4
* Protects from threat actors dropping and executing commands from web shells using Anti-Webshell Protection, newly released in Cortex XDR 3.4
* Protects against exploitation of different vulnerabilities including ProxyShell and ProxyLogon using the Anti-Exploitation modules as well as Behavioral Threat Protection
* Cortex XDR Pro [detects post-exploit activity](https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/analytics-alerts-by-required-data-source), including credential-based attacks, with behavioral analytics

If you think you might have been impacted or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html?_gl=1*13pmp8e*_ga*NzQyNjM2NzkuMTY2NjY3OTczNw..*_ga_KS2MELEEFC*MTY2OTczNjA2MS4zMS4wLjE2Njk3MzYwNjEuNjAuMC4w) or call:

North America Toll-Free: 866.486.4842 (866.4.UNIT42)

* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

**Capibar**

Hashes (SHA-256):

* ba2c8df04bcba5c3cfd343a59d8b59b76779e6c27eb27b7ac73ded97e08f0f39
* 64e8744b39e15b76311733014327311acd77330f8a135132f020eac78199ac8a

Domains:

* hxxps://mail.numina\[.\]md/owa/scripts/logon.aspx
* hxxps://mail.aet.in\[.\]ua/outlook/api/logoff.aspx
* hxxps://mail.arlingtonhousing\[.\]us/outlook/api/logoff.aspx
* hxxps://mail.kzp\[.\]bg/outlook/api/logoff.aspx
* hxxps://mail.lechateaudelatour\[.\]fr/MICROSOFT.EXCHANGE.MAILBOXREPLICATIONSERVICE.PROXYSERVICE/RPCWITCHERT/SYNC
* hxxps://mail.lebsack\[.\]de/MICROSOFT.EXCHANGE.MAILBOXREPLICATIONSERVICE.PROXYSERVICE/RPCWITCHERT/SYNC

**Kazuar**

Hashes (SHA-256):

* 8490daab736aa638b500b27c962a8250bbb8615ae1c68ef77494875ac9d2ada2
* b51105c56d1bf8f98b7e924aa5caded8322d037745a128781fa0bc23841d1e70
* Bf6f30673cf771d52d589865675a293dc5c3668a956d0c2fc0d9403424d429b2
* cd4c2e85213c96f79ddda564242efec3b970eded8c59f1f6f4d9a420eb8f1858

Domains:

* Gaismustudija\[.\]lv
* Hcdh-tunisie\[.\]org
* www.gallen\[.\]fi
* hxxps://www.bombheros\[.\]com/wp-content/languages/index\[.\]php
* hxxps://www.simplifiedhomesales\[.\]com/wp-includes/images/index.php
* hxxp://mtsoft.hol\[.\]es/wp-content/gallery/
* hxxp://www.polishpod101\[.\]com/forum/language/en/sign/
* hxxps://www.pierreagencement\[.\]fr/wp-content/languages/index.php
* hxxps://sansaispa\[.\]com/wp-includes/images/gallery/
* hxxps://octoberoctopus.co\[.\]za/wp-includes/sitemaps/web/

**Snake**

Hashes (SHA-256):

* fc68026b83392aa227e9adf9c71289cb51ba03427f6de67a73ae872e19ef6ff9
* 1950d2e706fbc6263d376c0c4f16bd5acfd543248ee072657ba3dd62da8427eb
* cf3a7d4285d65bf8688215407bce1b51d7c6b22497f09021f0fce31cbeb78986
* b262292e049ee75d235164df98fa8ed09a9e2a30c5432623856bafd4bd44d801

**Kopiluwak**

Hashes (SHA-256):

* 6536b6b50aa1f6899ffa90aaf4b1b67c0ae0f6c0441016f5308b37c12141c61d
* 8d9bb878a18b2b7ef558504e78a59eb644f83a63679658533ff8accf0b85fda3

Domains:

* manager.surro\[.\]am

IPs:

* 194\.67.209\[.\]186

**Topinambour**

Hashes (SHA-256):

* 009406c1c7c0b289a25d44dfaa8364633d9b71df5f3c7a65deec1ef00a8c2ebb
* 7a7d11adbcb740323eb52b097f535cfa5c281bf07a4d5c4afb0c5182fa4ffd1b
* d4ba16db7c26622d2d402cb9714331abfee891b6276d16e6c2f2132e8944cc71
* 046f11a6c561e46e6bf199ab7f50e74a4d2aaead68cdbd6ce44b37b5b4964758

IPs:

* 197\.168.0\[.\]247

**QUIETCANARY/Tunnus**

Hashes (SHA-256):

* 0fc624aa9656a8bc21731bfc47fd7780da38a7e8ad7baf1529ccd70a5bb07852
* 3f94b20cb7f4ff55207660649ebbb02679c991fe03efbcb0bd3840fc7f0bd527
* 29314f3cd73b81eda7bd90c66f659235e6bb900e499c9cc7057d10a9083a0b94
* 87663affd147065d08d4fe76d9a18b0d7d85fab68cf9f5ac96cfdfff3f27ffd2

Domains:

* lakihelppi\[.\]com

IPs:

* 46\.101.209\[.\]249
* 210\.48.231\[.\]182

**Crutch**

Hashes (SHA-256):

* 0010ccb822538d1881c61be874af49382c44b6c9cb665081cf0f672cbed5b6a5
* 29b1da7b17a7ba3e730e6927058d0554a8bc81bdef88e364097fab0bb1950edc
* 16860fc685ea0dee91e65e253062153ac6c886fdd73a3020c266601f58038a61
* 10c0e2afb37a24ac7732a402a4c9d854b35a382f1651d4aa2ece429b154aecb2

**ComRAT**

Hashes (SHA-256):

* 00352afc7e7863530e4d68be35ae8b60261fc57560167645697b7bfc0ac0e93d
* 134919151466c9292bdcb7c24c32c841a5183d880072b0ad5e8b3a3a830afef8
* 166b1fb3d34b32f1807c710aaa435d181aedbded1e7b4539ffa931c2b2cdd405
* 44d6d67b5328a4d73f72d8a0f9d39fe4bb6539609f90f169483936a8b3b88316
* A3170c32c09fc85cdda778a5c20a3dab144b6d1dd9996ba8340866e0081c7642
* 187bf95439da038c1bc291619507ff5e426d250709fa5e3eda7fda99e1c9854c
* b93484683014aca8e909c9b5648d8f0ac21a45d0c193f6ca40f0b01d2464c1c4

Domains:

* branter\[.\]tk
* wekanda\[.\]tk
* sanitar\[.\]ml
* duke6\[.\]tk
* bronerg\[.\]tk
* Crusider\[.\]tk

**Carbon**

Hashes (SHA-256):

* 493e5fae191950b901764868b065ddddffa4f4c9b497022ee2f998b4a94f0fc2
* f3aaa091fdbc8772fb7bd3a81665f4d33c3b62bf98caad6fee4424654ba26429
* 2b969111dd1968d47b02d6390c92fb622cd03570b02ecf9215031ff03611a2b7
* 7d5794ad91351c7c5d7fbad8e83e3b71a09baac65fb09ca75d8d18339d24a46f

Domains:

* www.berlinguas\[.\]com
* www.balletmaniacs\[.\]com

**HyperStack**

Hashes (SHA-256):

* 6ca0b4efe077fe05b2ae871bf50133c706c7090a54d2c3536a6c86ff454caa9a
* 20691ff3c9474cfd7bf6fa3f8720eb7326e6f87f64a1f190861589c1e7397fa5
* e33580ae3df9d27d7cfb7b8f518a2704e55c92dd74cbbab8ef58ddfd36524cc8

**TinyTurla**

Hashes (SHA-256):

* 030cbd1a51f8583ccfc3fa38a28a5550dc1c84c05d6c0f5eb887d13dedf1da01

# Additional References

* [Turla](https://attack.mitre.org/groups/G0010/) --- MITRE ATT\&CK
* [Turla](https://attackevals.mitre-engenuity.org/enterprise/turla/) --- MITRE Ingenuity
* [Hunting Russian Intelligence "Snake" Malware](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a) --- CISA
* [Justice Department Announces Court-Authorized Disruption of the Snake Malware Network Controlled by Russia's Federal Security Service](https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network) --- US Department of Justice
* [Threat Coverage: Hunting for Snake malware with FortiEDR](https://community.fortinet.com/t5/FortiEDR/Threat-Coverage-Hunting-for-Snake-malware-with-FortiEDR/ta-p/258038) --- Fortinet
* [APT Profile: Turla](https://socradar.io/apt-profile-turla/) --- SOCRadar
* [TinyTurla - Turla deploys new malware to keep a secret backdoor on victim machines](https://blog.talosintelligence.com/tinyturla/) --- Talos
* [KopiLuwak: A New JavaScript Payload from Turla](https://securelist.com/kopiluwak-a-new-javascript-payload-from-turla/77429/) --- Securelist, Kaspersky
* [Turla APT actor refreshes KopiLuwak JavaScript backdoor for use in G20-themed attack](https://www.proofpoint.com/us/threat-insight/post/turla-apt-actor-refreshes-kopiluwak-javascript-backdoor-use-g20-themed-attack) --- Proofpoint
* [Turla: A Galaxy of Opportunity](https://www.mandiant.com/resources/blog/turla-galaxy-opportunity) --- Mandiant
* [Carbon Paper: Peering into Turla's second stage backdoor](https://www.welivesecurity.com/2017/03/30/carbon-paper-peering-turlas-second-stage-backdoor/) WeLiveSecurity, ESET
* [From Agent.BTZ to ComRAT v4: A ten-year journey](https://www.welivesecurity.com/2020/05/26/agentbtz-comratv4-ten-year-journey/) --- WeLiveSecurity, ESET
* [Turla Crutch: Keeping the "back door" open](https://www.welivesecurity.com/2020/12/02/turla-crutch-keeping-back-door-open/) --- WeLiveSecurity, ESET
* [Tomiris called, they want their Turla malware back](https://securelist.com/tomiris-called-they-want-their-turla-malware-back/109552/) --- Securelist, Kaspersky
* [Turla PNG Dropper is back](https://research.nccgroup.com/2018/11/22/turla-png-dropper-is-back/) --- NCC Group
* [Taste of Topinambour: Turla hacking group hides malware in anti-internet censorship software](https://www.kaspersky.com/about/press-releases/2019_taste-of-topinambour) --- Kaspersky
* [Cyber Threats 2020: A Year in Retrospect](https://www.pwc.co.uk/issues/cyber-security-services/insights/cyber-threats-2020-report-on-global-landscape.html) --- PwC
  Back to top

### Tags

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")
* [Capibar](https://unit42.paloaltonetworks.com/tag/capibar/ "Capibar")
* [Carbon](https://unit42.paloaltonetworks.com/tag/carbon/ "Carbon")
* [ComRAT](https://unit42.paloaltonetworks.com/tag/comrat/ "ComRAT")
* [Crutch](https://unit42.paloaltonetworks.com/tag/crutch/ "Crutch")
* [HyperStack](https://unit42.paloaltonetworks.com/tag/hyperstack/ "HyperStack")
* [MITRE](https://unit42.paloaltonetworks.com/tag/mitre/ "MITRE")
* [Pensive Ursa](https://unit42.paloaltonetworks.com/tag/pensive-ursa/ "Pensive Ursa")
* [QUIETCANARY](https://unit42.paloaltonetworks.com/tag/quietcanary/ "QUIETCANARY")
* [Snake](https://unit42.paloaltonetworks.com/tag/snake/ "Snake")
* [TinyTurla](https://unit42.paloaltonetworks.com/tag/tinyturla/ "TinyTurla")
* [Tunnus](https://unit42.paloaltonetworks.com/tag/tunnus/ "Tunnus")
* [Turla](https://unit42.paloaltonetworks.com/tag/turla/ "Turla")
* [Uroburos](https://unit42.paloaltonetworks.com/tag/uroburos/ "Uroburos")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Unit 42 Attack Surface Threat Research: Constant Change in Cloud Contributes to 45% of New High/Critical Exposures Per Month](https://unit42.paloaltonetworks.com/unit-42-2023-attack-surface-threat-report/ "Unit 42 Attack Surface Threat Research: Constant Change in Cloud Contributes to 45% of New High/Critical Exposures Per Month")

### Table of Contents

* 

### Related Articles

* [Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns](https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/ "article - table of contents")
* [Paved With Intent: ROADtools and Nation-State Tactics in the Cloud](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/ "article - table of contents")
* [Boggy Serpens Threat Assessment](https://unit42.paloaltonetworks.com/boggy-serpens-threat-assessment/ "article - table of contents")

## Related Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
