[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/ukraine-cyber-conflict-cve-2021-32648-whispergate/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Threat Brief: Ongoing Russia and Ukraine Cyber Activity

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 8 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Mike Harbison](https://unit42.paloaltonetworks.com/author/mike-harbison/)
  * [Robert Falcone](https://unit42.paloaltonetworks.com/author/robert-falcone/)
  * [Josh Grunzweig](https://unit42.paloaltonetworks.com/author/josh-grunzweig/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:January 20, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CVE-2021-32648](https://unit42.paloaltonetworks.com/tag/cve-2021-32648/)
  * [OctoberCMS](https://unit42.paloaltonetworks.com/tag/octobercms/)
  * [Russia](https://unit42.paloaltonetworks.com/tag/russia/)
  * [Ukraine](https://unit42.paloaltonetworks.com/tag/ukraine/)
  * [WhisperGate](https://unit42.paloaltonetworks.com/tag/whispergate/)
  * [Windows](https://unit42.paloaltonetworks.com/tag/windows/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/?pdf=download&lg=en&_wpnonce=a266be986b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/?pdf=print&lg=en&_wpnonce=a266be986b "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Threat%20Brief:%20Ongoing%20Russia%20and%20Ukraine%20Cyber%20Activity&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fukraine-cyber-conflict-cve-2021-32648-whispergate%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fukraine-cyber-conflict-cve-2021-32648-whispergate%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fukraine-cyber-conflict-cve-2021-32648-whispergate%2F&title=Threat%20Brief:%20Ongoing%20Russia%20and%20Ukraine%20Cyber%20Activity "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fukraine-cyber-conflict-cve-2021-32648-whispergate%2F&text=Threat%20Brief:%20Ongoing%20Russia%20and%20Ukraine%20Cyber%20Activity "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fukraine-cyber-conflict-cve-2021-32648-whispergate%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Threat%20Brief:%20Ongoing%20Russia%20and%20Ukraine%20Cyber%20Activity%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fukraine-cyber-conflict-cve-2021-32648-whispergate%2F "Share in Mastodon")

## Executive Summary

Beginning on Jan. 14, 2022, reports began emerging about a series of attacks targeting numerous Ukrainian government websites. As a result of these attacks, numerous government websites were found to be either defaced or inaccessible. As a result of this, the government of Ukraine [formally accused Russia](https://thehackernews.com/2022/01/ukrainian-government-officially-accuses.html) of masterminding these attacks against their websites.

A day later, public reporting outlined new malware called [WhisperGate](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) that originally was observed on Jan. 13, 2022. This malware disables Windows Defender Threat Protection, is destructive in nature and was discovered to have targeted multiple organizations in Ukraine. Microsoft has publicly attributed the use of this custom malware to a threat actor they refer to as DEV-0586.

Though both attacks have targeted Ukrainian organizations, the two threats have so far been implemented in separate situations.

As a result of these events, Palo Alto Networks researchers took immediate action to ensure that customers anywhere in the world can be appropriately protected against these reported threats, however they may be exploited. These attacks ultimately resulted in the investigation of the following two threats:

1. [CVE-2021-32648](https://nvd.nist.gov/vuln/detail/CVE-2021-32648), a vulnerability in the OctoberCMS content management system (CMS) platform, which is believed to be behind the attacks against Ukrainian government websites.
2. The WhisperGate malware, attributed to the DEV-0586 threat actor.

Palo Alto Networks customers can use [Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) or [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) for the Next-Generation Firewall to identify vulnerable and/or internet-facing instances of OctoberCMS. Protections against WhisperGate malware have been included in [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr), as well as in the WildFire and Advanced URL Filtering [subscriptions for the Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/security-subscriptions). There is a [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar) pack available to assist with detecting and mitigating both threats.

|---------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Threats targeting Ukraine discussed**           | **Relevant CVEs/malware/affected software**                                                                                                                                    |
| Attacks against Ukrainian government websites     | [CVE-2021-32648](https://nvd.nist.gov/vuln/detail/CVE-2021-32648), affecting OctoberCMS                                                                                        |
| Attacks against multiple organizations in Ukraine | [WhisperGate](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) malware, disabling Windows Defender Threat Protection |

## CVE-2021-32648 Vulnerability

The CVE-2021-32648 vulnerability lies within the OctoberCMS platform prior to version 1.0.472 and results in an attacker gaining access to any account via a specially crafted account password reset request. This vulnerability is believed to have allowed threat actors to gain access to the underlying websites leveraged by the Ukraine government.

Once the vulnerability was discovered, Palo Alto Networks threat researchers quickly began reverse-engineering the patch that remediated this vulnerability and were able to produce a working proof of concept (PoC) in a very short time. Later that day, a [public PoC surfaced](https://github.com/Immersive-Labs-Sec/CVE-2021-32648/blob/main/cve-2021-32648.py), allowing organizations to better understand this vulnerability and how it is exploited. Using our PoC, we created the following demonstration video of how a malicious actor would exploit the CVE-2021-32648 vulnerability, log into the compromised OctoberCMS account and to deface a web page hosted by the server:

To determine how this vulnerability was exploited, we analyzed the patch that developers added to OctoberCMS version 1.0.472 to mitigate the CVE-2021-32648 vulnerability. We discovered that the vulnerable code existed in the [Auth/Models/User.php](https://github.com/octobercms/library/blob/v1.0.471/src/Auth/Models/User.php) file within the [October Rain library](https://github.com/octobercms/library) of OctoberCMS. The code that exposes this vulnerability is within a function named checkResetPasswordCode, specifically, line 281 in [User.php](https://github.com/octobercms/library/blob/v1.0.471/src/Auth/Models/User.php#L281). The following line of code attempts to validate the inbound password reset request by comparing the reset code submitted within the HTTP request with the reset code generated by OctoberCMS during a legitimate reset process:

![This line of code exploits CVE-2021-32648 by attempting to validate the inbound password reset request by comparing the reset code submitted within the HTTP request with the reset code generated by OctoberCMS during a legitimate reset process.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/01/word-image-63.png)

To exploit this vulnerability, the actor would simply supply a boolean true value as the reset code within a custom-crafted HTTP request to reset the password of an account. By supplying the boolean true, the comparison between boolean true and the reset code string results in a boolean true, even though the two variables have different types. This effectively validates the actor's inbound password reset request, which allows the actor to then change the password

To fix this vulnerability in version 1.0.472, the OctoberCMS developer changed the line of code above to use === instead of == when comparing the values of the reset code provided by the user via an HTTP POST request. The difference between === and == involves the === comparing the value and type of value of the variable, not just the value, as happens when using ==. To demonstrate the difference, the following two commands run PHP code to show that a comparison of the string code with boolean true using == results in a boolean true, while the same comparison using === results in a boolean false:

![To demonstrate the difference between the version of OctoberCMS vulnerable to CVE-2021-32648 and the fixed version, the following two commands run PHP code to show that a comparison of the string code with boolean true using == results in a boolean true, while the same comparison using === results in a boolean false](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/01/word-image-64.png)

As a result of the analysis of the CVE-2021-32648 vulnerability, various product protections were created or enhanced. More information about these protections can be found within the [Mitigation Actions](#mitigation-actions) section of the briefing.

## WhisperGate Malware

First observed by Microsoft on Jan. 13, 2022, [WhisperGate](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) malware is computer network attack (CNA) malware aimed at deleting Microsoft Windows Defender and corrupting files on the target. It consists of two samples: One appears as ransomware while the other is a beaconing implant used to deliver an in-memory Microsoft Intermediate Language (MSIL) payload. The in-memory code uses Living Off the Land Binaries (LOLBINs) to evade detection and also performs anti-analysis techniques, as it will fail to detonate when certain monitoring tools exist. At the time of writing, there are two known samples identified as WhisperGate: Stage1.exe and Stage2.exe. Stage1.exe purports to be ransomware, as it overwrites the target's master boot record with 512 bytes and upon reboot displays the following ransom note:
![A ransom note dropped by a sample of WhisperGate malware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/01/word-image-65.png) Figure 1. Stage 1 ransom note.

Stage2.exe is a beaconing implant that performs an HTTPS connection to download a JPG file hosted on Discord's content delivery network (CDN). Discord's CDN is a user-created service that allows users to host attachments and is not malicious. The hosted file is retrieved from the following URL:

hxxps://cdn.discordapp\[.\]com/attachments/928503440139771947/930108637681184768/Tbopbh.jpg

File Tbopbh.jpg is the malicious payload that is in-memory loaded and kicks off the destructive capabilities. The following patterns of activities are associated with this payload:

1. File InstallUtil.exe is copied to the host's %TEMP% directory, e.g. C:\\Users\\\[USERNAME\]\\AppData\\Local\\Temp. This file is a legitimate Microsoft Windows binary.

2. Two instances of PowerShell are spawned with an encoded command to sleep for 10 seconds, e.g. C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwAA==

3. A Visual Basic Script (VBS) is created in C:\\Users\\\[USERNAME\]\\AppData\\Local\\Temp named: Nmddfrqqrbyjeygggda.vbs

4. Process wscript.exe is used to execute the VBS script in step 3. The VBS script is used to call PowerShell to set Windows Defender exclusion path to C:\\ e.g. C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" Set-MpPreference -ExclusionPath 'C:\\'

5. [AdvancedRun.exe](https://www.nirsoft.net/utils/advanced_run.html) is created and written to the C:\\Users\\\[USERNAME\]\\AppData\\Local\\Temp directory.

6. AdvancedRun.exe is used to execute PowerShell.exe to delete and stop Windows Defender. The following command parameters are passed to AdvancedRun:

"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe" /WindowState 0 /CommandLine "rmdir 'C:\\ProgramData\\Microsoft\\Windows Defender' -Recurse" /StartDirectory "" /RunAs 8 /Run

"C:\\Users\\USERNAME\]AppData\\Local\\Temp\\AdvancedRun.exe" /EXEFilename "C:\\Windows\\System32\\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run

7. PowerShell process used to delete Windows Defender, e.g. C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe rmdir 'C:\\ProgramData\\Microsoft\\Windows Defender' -Recurse

8. File InstallUtil.exe running from C:\\Users\\\[USERNAME\]\\AppData\\Local\\Temp directory. The in-memory payload (Tbopbh.jpg) is running within the context of the InstallUtil.exe process

9. Multiple instances of cmd.exe calling Ping.exe to delete file InstallUtil.exe, e.g. cmd.exe /min /C ping 111.111.111\[.\]111 -n 5 -w 10 \> Nul \& Del /f /q %TEMP%\\InstallUtil.exe

10. File AdvancedRun.exe is deleted from the C:\\Users\\\[USERNAME\]\\AppData\\Local\\Temp directory by the stage2.exe binary.

11. ICMP traffic to host: 111.111.111\[.\]111

12. All files and directories, including those on mounted USB drives, excluding the floppy drive (A:) are targeted. The following file extensions are overwritten with a one-byte value of 0xCC.
    ![A list of file extensions targeted by WhisperGate malware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/01/word-image-66.png) Figure 2. Targeted file extensions.

13. Targeted files greater than one megabyte are truncated to one megabyte when overwritten.

14. Virus \& Threat protection is no longer available from Windows Security.
    ![A screenshot showing how WhisperGate malware removes Virus \& Threat Protection from Windows Security.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/01/word-image-67.png) Figure 3. Virus \& Threat Protection removed.

## Mitigation Actions

Organizations running OctoberCMS prior to Build 472 and v1.1.5 are encouraged to update to the latest version. Additionally, in order for this vulnerability to be exploited, the web server must be running PHP below 7.4.

Palo Alto Networks customers receive protections against the OctoberCMS vulnerability in the following ways:

* Threat ID [92199](https://threatvault.paloaltonetworks.com/?query=92199) was released to identify this vulnerability
* Xpanse has a policy that customers can enable to detect internet-facing instances of OctoberCMS

Palo Alto Networks customers receive protections against WhisperGate malware in the following ways:

* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) appropriately identifies WhisperGate samples as malicious.
* All observed malicious Discord URLs have been flagged as malicious.
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) prevents this malware from executing using machine learning-based local analysis, the Behavioral Threat Protection module and the ransomware protection module.

The Cortex XSOAR "WhisperGate \& CVE-2021-32648'' pack can help automatically detect and mitigate the two threats. Read more on the [XSOAR marketplace](https://xsoar.pan.dev/marketplace/details/WhisperGateCVE202132648).

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call North America Toll-Free: 866.486.4842 (866.4.UNIT42), EMEA: +31.20.299.3130, APAC: +65.6983.8730, or Japan: +81.50.1790.0200.

## Hunting for WhisperGate

Palo Alto Networks Cortex XDR customers may leverage the following XQL queries, written by the Cortex Managed Threat Hunting service experts, to hunt their datasets for indicators related to WhisperGate malware:  
// Description: WhisperGate - Self Delete config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START |filter (action\_process\_image\_name = "cmd.exe" OR action\_process\_image\_name = "ping.exe") and action\_process\_image\_command\_line contains "111.111.111.111 -n 5 -w 10" |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_path, actor\_process\_image\_sha256,action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256 // Description: WhisperGate - PowerShell Sleep config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START |filter action\_process\_image\_name = "powershell.exe" and action\_process\_image\_command\_line contains "UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwAA==" |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_path, actor\_process\_image\_sha256,action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256 // Description: WhisperGate - InstallUtil (Wiper) config case\_sensitive = false |dataset = xdr\_data |filter (event\_type = FILE and (event\_sub\_type = ENUM.FILE\_WRITE or event\_sub\_type = ENUM.FILE\_CREATE\_NEW) and (action\_file\_name = "installutil.exe" AND action\_file\_path contains "\\appdata\\local\\temp\\installutil.exe")) or ((event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START) and action\_process\_image\_name = "installutil.exe" and action\_process\_image\_path contains "\\appdata\\local\\temp\\installutil.exe") |dedup agent\_id, actor\_process\_image\_command\_line, actor\_process\_image\_sha256, action\_file\_path, action\_file\_sha256, action\_process\_image\_sha256, action\_process\_image\_command\_line |fields \_time, agent\_id,agent\_hostname, actor\_effective\_username, action\_file\_name, action\_file\_path, action\_file\_sha256, actor\_process\_image\_path, actor\_process\_image\_command\_line, actor\_process\_image\_sha256, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256 // Description: WhisperGate - Disable Defender config case\_sensitive = false |dataset = xdr\_data |filter ((event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START) and (action\_process\_image\_name = "advancedrun.exe" and (action\_process\_image\_command\_line contains "stop windefend" OR action\_process\_image\_command\_line contains "mdir 'c:\\programdata\\microsoft\\windows defender")) or (action\_process\_image\_name = "wscript.exe" and action\_process\_image\_command\_line contains "nmddfrqqrbyjeygggda.vbs")) or (event\_type = FILE and (event\_sub\_type = ENUM.FILE\_WRITE or event\_sub\_type = ENUM.FILE\_CREATE\_NEW) and (action\_file\_name = "nmddfrqqrbyjeygggda.vbs")) |dedup agent\_id, actor\_process\_image\_command\_line, actor\_process\_image\_sha256, action\_file\_path, action\_file\_sha256, action\_process\_image\_sha256, action\_process\_image\_command\_line |fields \_time, agent\_id,agent\_hostname, actor\_effective\_username, action\_file\_name, action\_file\_path, action\_file\_sha256, actor\_process\_image\_path, actor\_process\_image\_command\_line, actor\_process\_image\_sha256, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256

|-------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 | // Description: WhisperGate - Self Delete config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START |filter (action\_process\_image\_name = "cmd.exe" OR action\_process\_image\_name = "ping.exe") and action\_process\_image\_command\_line contains "111.111.111.111 -n 5 -w 10" |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_path, actor\_process\_image\_sha256,action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256 // Description: WhisperGate - PowerShell Sleep config case\_sensitive = false |dataset = xdr\_data |filter event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START |filter action\_process\_image\_name = "powershell.exe" and action\_process\_image\_command\_line contains "UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwAA==" |fields \_time, agent\_hostname, actor\_effective\_username, actor\_process\_image\_path, actor\_process\_image\_sha256,action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256 // Description: WhisperGate - InstallUtil (Wiper) config case\_sensitive = false |dataset = xdr\_data |filter (event\_type = FILE and (event\_sub\_type = ENUM.FILE\_WRITE or event\_sub\_type = ENUM.FILE\_CREATE\_NEW) and (action\_file\_name = "installutil.exe" AND action\_file\_path contains "\\appdata\\local\\temp\\installutil.exe")) or ((event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START) and action\_process\_image\_name = "installutil.exe" and action\_process\_image\_path contains "\\appdata\\local\\temp\\installutil.exe") |dedup agent\_id, actor\_process\_image\_command\_line, actor\_process\_image\_sha256, action\_file\_path, action\_file\_sha256, action\_process\_image\_sha256, action\_process\_image\_command\_line |fields \_time, agent\_id,agent\_hostname, actor\_effective\_username, action\_file\_name, action\_file\_path, action\_file\_sha256, actor\_process\_image\_path, actor\_process\_image\_command\_line, actor\_process\_image\_sha256, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256 // Description: WhisperGate - Disable Defender config case\_sensitive = false |dataset = xdr\_data |filter ((event\_type = ENUM.PROCESS and event\_sub\_type = ENUM.PROCESS\_START) and (action\_process\_image\_name = "advancedrun.exe" and (action\_process\_image\_command\_line contains "stop windefend" OR action\_process\_image\_command\_line contains "mdir 'c:\\programdata\\microsoft\\windows defender")) or (action\_process\_image\_name = "wscript.exe" and action\_process\_image\_command\_line contains "nmddfrqqrbyjeygggda.vbs")) or (event\_type = FILE and (event\_sub\_type = ENUM.FILE\_WRITE or event\_sub\_type = ENUM.FILE\_CREATE\_NEW) and (action\_file\_name = "nmddfrqqrbyjeygggda.vbs")) |dedup agent\_id, actor\_process\_image\_command\_line, actor\_process\_image\_sha256, action\_file\_path, action\_file\_sha256, action\_process\_image\_sha256, action\_process\_image\_command\_line |fields \_time, agent\_id,agent\_hostname, actor\_effective\_username, action\_file\_name, action\_file\_path, action\_file\_sha256, actor\_process\_image\_path, actor\_process\_image\_command\_line, actor\_process\_image\_sha256, action\_process\_image\_path, action\_process\_image\_command\_line, action\_process\_image\_sha256 |

## Conclusion

The Unit 42 Threat Intelligence team remains vigilant in monitoring this evolving situation, is actively hunting for known indicators from recent events and is ready to put protections in place to thwart attacks against our customers.

Product-specific protections have been implemented as a result of research performed in recent days, and those protections will be augmented as needed as more details come to light. Palo Alto Networks will update this Threat Brief with new information and recommendations as they become available.

## Additional Resources

### **CVE-2021-32648 Information**

* [CVE-2021-32648](https://nvd.nist.gov/vuln/detail/CVE-2021-32648) - NIST
* [CVE-2021-32648](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32648) - MITRE
* [OctoberCMS library](https://github.com/OctoberCMS/library/commit/016a297b1bec55d2e53bc889458ed2cb5c3e9374)
* [CVE-2021-32648](https://cyber.vumetric.com/vulns/CVE-2021-32648/improper-authentication-vulnerability-in-octobercms-october/) - Vumetric Cyber Portal
* [Account Takeover in OctoberCMS](https://github.com/advisories/GHSA-mxr5-mc97-63rc) - GitHub Advisory
* [OctoberCMS as you know it is Dead](https://wintercms.com/blog/post/october-cms-you-know-it-dead) - Winter CMS

### **WhisperGate Information**

* [Destructive malware targeting Ukrainian organizations](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/)
* [What We Know and Don't Know About the Cyberattacks Against Ukraine](https://zetter.substack.com/p/what-we-know-and-dont-know-about)

*Updated March 4, 2022, at 6:15 a.m. PT.*
Back to top

### Tags

* [CVE-2021-32648](https://unit42.paloaltonetworks.com/tag/cve-2021-32648/ "CVE-2021-32648")
* [OctoberCMS](https://unit42.paloaltonetworks.com/tag/octobercms/ "OctoberCMS")
* [Russia](https://unit42.paloaltonetworks.com/tag/russia/ "Russia")
* [Ukraine](https://unit42.paloaltonetworks.com/tag/ukraine/ "Ukraine")
* [WhisperGate](https://unit42.paloaltonetworks.com/tag/whispergate/ "WhisperGate")
* [Windows](https://unit42.paloaltonetworks.com/tag/windows/ "Windows")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Operation Falcon II: Unit 42 Helps INTERPOL Identify Nigerian Business Email Compromise Ring Members](https://unit42.paloaltonetworks.com/operation-falcon-ii-silverterrier-nigerian-bec/ "Operation Falcon II: Unit 42 Helps INTERPOL Identify Nigerian Business Email Compromise Ring Members")

### Table of Contents

* 

### Related Articles

* [Understanding the Russian Cyberthreat to the 2026 Winter Olympics](https://unit42.paloaltonetworks.com/russian-cyberthreat-2026-winter-olympics/ "article - table of contents")
* [01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "article - table of contents")
* [You Thought It Was Over? Authentication Coercion Keeps Evolving](https://unit42.paloaltonetworks.com/authentication-coercion/ "article - table of contents")

## Related Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
